exploits , vulnerabilities , articles , Microsoft Crypto API X.509 Certificate Validation Remote Information Disclosure Vulnerability
| Title |
Microsoft Crypto API X.509 Certificate Validation Remote Information Disclosure Vulnerability |
| Published |
2008-04-01-12:00AM |
| Updated |
2008-07-04-07:00PM |
| Class |
Design Error |
| CVE |
|
| Remote |
Yes |
| Local |
No |
| Credit |
Alexander Klink |
| Vulnerable |
Microsoft Windows Live Mail 2008 0 Microsoft Outlook 2007 0 Microsoft Office 2007 SP1 Microsoft Office 2007 0 Microsoft Access 2007 0 Microsoft Access 2007 0 Microsoft Excel 2003 Microsoft Excel 2007 0 Microsoft Excel 2007 0 Microsoft FrontPage 2003 Microsoft Groove 2007 0 Microsoft Groove 2007 0 Microsoft InfoPath 2003 Microsoft InfoPath 2007 0 Microsoft InfoPath 2007 0 Microsoft Office Communicator 2007 0 Microsoft Office Communicator 2007 0 Microsoft OneNote 2003 0 Microsoft Outlook 2003 0 Microsoft Outlook 2007 0 Microsoft Outlook 2007 0 Microsoft PowerPoint 2003 0 Microsoft PowerPoint 2007 0 Microsoft PowerPoint 2007 0 Microsoft Project Professional 2007 0 Microsoft Project Professional 2007 0 Microsoft Project Standard 2007 0 Microsoft Project Standard 2007 0 Microsoft Publisher 2003 Microsoft Publisher 2007 0 Microsoft Publisher 2007 0 Microsoft SharePoint Designer 2007 0 Microsoft SharePoint Designer 2007 0 Microsoft Visio Professional 2007 0 Microsoft Visio Professional 2007 0 Microsoft Visio Standard 2007 0 Microsoft Visio Standard 2007 0 Microsoft Crypto API 0
|
| Not Vulnerable |
|
| Code |
The following Office document will trigger HTTP requests to an external webserver.The referenced advisories also state that sending a blank email to <smime-http@klink.name> will result in a reply email that is S/MIME-encoded in a manner that also triggers the issue.Symantec has not validated the safety of the document or email, so users should take appropriate precautions for handling potentially malicious content. /data/vulnerabilities/exploits/HTTP_over_Office_2007_PoC.docx |
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Sat, 19 Dec 2009 03:38:48 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Girl pictu www.37cool Caress mambo Remo all photo SEX PRAZEL SEX WOMAN sexesy www.pkzx.c Crack Data video porn www.0596fk CMS is Fre maxcpm.inf candysex HUMILIATIO Album phot gayse Free xxx c Fucking go argosoft m ww.xnxx.co News Searc Windows Pl mambo Remo Ray j sex php 2007 storm worm club.banda openssh www.mig33. Phonerotic www.dldvb. el ladies WWW SAHILA free sex v EMANSEX Pooja nude Crack Data lo256l maxcpm.inf news for c maxcpm.inf www.338818 AFFIDAVIT www.zhibei news/explo Sanja news for c russain gi
|