Description
Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the spreadsheet.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Debasis Mohanty · textdoswindows
https://www.exploit-db.com/exploits/28087
References (16)
Core 16
Core References
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3573
US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-318A.html
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4507
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/19980
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22882
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21865
Exploit mailing-list
x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2006-06/0414.html
Various Sources x_refsource_misc
http://www.securiteam.com/windowsntfocus/5TP0M0KIUA.html
Exploit x_refsource_misc
http://hackingspirits.com/vuln-rnd/vuln-rnd.html
Various Sources x_refsource_confirm
http://www.adobe.com/support/security/bulletins/apsb06-11.html
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A538
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3577
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/18583
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27312
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-069
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1016344
Scores
EPSS
0.5832
EPSS Percentile
98.2%
Details
CWE
CWE-20
Status
published
Products (1)
microsoft/excel
Published
Jun 22, 2006
Tracked Since
Feb 18, 2026