CVE-2002-0861
Summary
| CVE | CVE-2002-0861 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-09-24 04:00:00 UTC |
| Updated | 2018-10-12 21:31:00 UTC |
| Description | Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the "Allow paste operations via script" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Office Web Components | 2000 | All | All | All |
| Application | Microsoft | Office Web Components | 2002 | All | All | All |
| Application | Microsoft | Office Web Components | 2000 | All | All | All |
| Application | Microsoft | Office Web Components | 2002 | All | All | All |
| Application | Microsoft | Project | 2000 | All | All | All |
| Application | Microsoft | Project | 2002 | All | All | All |
| Application | Microsoft | Project | 2000 | All | All | All |
| Application | Microsoft | Project | 2002 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Office Web Components Clipboard Information Disclosure Vulnerability | BID | www.securityfocus.com | |
| Microsoft Security Bulletin MS02-044 - Critical | Microsoft Docs | MS | docs.microsoft.com | |
| ISS X-Force Database: owc-spreadsheet-clipboard-access (8779): Microsoft OWC Spreadsheet component "Paste" and "Copy" method could allow unauthorized clipboard access through Internet Explorer | XF | www.iss.net | Patch, Vendor Advisory |
| 20020408 Controlling the clipboard with OWC in IE (GM#007-IE) | BUGTRAQ | marc.info | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.