CVE-2006-3014
Microsoft Excel - Arbitrary JavaScript Execution via Embedded Shockwave Flash Object
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3014. PoCs published by Debasis Mohanty.
AI-analyzed exploit summary The provided text describes a vulnerability in Microsoft Office (CVE-2006-3014) where arbitrary script code in Shockwave Flash Objects can execute without user confirmation. It lacks actual exploit code, serving only as a vulnerability summary.
Description
Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the spreadsheet.
Exploits (1)
The provided text describes a vulnerability in Microsoft Office (CVE-2006-3014) where arbitrary script code in Shockwave Flash Objects can execute without user confirmation. It lacks actual exploit code, serving only as a vulnerability summary.