[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2002-1056Date: (C)2002-05-16   (M)2023-12-22


Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
http://marc.info/?l=bugtraq&m=101760380418890&w=2
http://online.securityfocus.com/archive/1/265621
BID-4397
MS02-021
outlook-object-execute-script(8708)

CPE    6
cpe:/a:microsoft:outlook:2002
cpe:/a:microsoft:outlook:2000
cpe:/a:microsoft:word:2000:sr1
cpe:/a:microsoft:word:2000:sr1a
...
OVAL    2
oval:org.mitre.oval:def:429
oval:org.mitre.oval:def:205

© SecPod Technologies