CVE

CVE-2006-3014

Severity:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
22/06/2006
Last modified:
12/10/2018

Description

Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the spreadsheet.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:excel:*:*:*:*:*:*:*:*