Vulnerabilities > CVE-2002-1143 - Unspecified vulnerability in Microsoft Excel and Word

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
microsoft
exploit available

Summary

Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."

Exploit-Db

  • descriptionMS Word 95/97/98/2000/2002 Excel 2002 INCLUDETEXT Document Sharing File Disclosure. CVE-2002-1143. Remote exploit for windows platform
    idEDB-ID:21764
    last seen2016-02-02
    modified2002-08-26
    published2002-08-26
    reporterAlex Gantman
    sourcehttps://www.exploit-db.com/download/21764/
    titleMicrosoft Word 95/97/98/2000/2002 Excel 2002 INCLUDETEXT Document Sharing File Disclosure
  • descriptionMS Word 95/97/98/2000/2002 INCLUDEPICTURE Document Sharing File Disclosure. CVE-2002-1143. Remote exploit for windows platform
    idEDB-ID:21812
    last seen2016-02-02
    modified2002-09-20
    published2002-09-20
    reporterRichard Edwards
    sourcehttps://www.exploit-db.com/download/21812/
    titleMicrosoft Word 95/97/98/2000/2002 INCLUDEPICTURE Document Sharing File Disclosure

Oval

accepted2012-05-28T04:01:27.174-04:00
classvulnerability
contributors
  • nameIngrid Skoog
    organizationThe MITRE Corporation
  • nameIngrid Skoog
    organizationThe MITRE Corporation
  • nameJohn Hoyland
    organizationCentennial Software
  • nameShane Shaffer
    organizationG2, Inc.
descriptionMicrosoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."
familywindows
idoval:org.mitre.oval:def:202
statusaccepted
submitted2004-08-24T12:00:00.000-04:00
titleFlaw in Word Fields and Excel External Updates Could Lead to Information Disclosure
version6