Description
The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.
References (5)
Core 5
Core References
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-044
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/3006
Patch, Vendor Advisory vdb-entry
x_refsource_xf
http://www.iss.net/security_center/static/8777.php
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=101829645415486&w=2
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/4449
Scores
EPSS
0.1885
EPSS Percentile
97.0%
Details
Status
published
Products (3)
microsoft/office_web_components
2000
microsoft/office_web_components
2002
microsoft/project
2002
Published
Sep 24, 2002
Tracked Since
Feb 18, 2026