Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Curious vulnerability in Excel 2007

Curious vulnerability in Excel 2007

From: <jplopezy_at_gmail.com>
Date: 26 Apr 2008 15:00:26 -0000
('binary' encoding is not supported, stored as-is) Product: Microsoft Excel 2007
OS: Windows XP

Hello

inform them that, I found a vulnerability in curiosity rather excel, it is that you can run Javascript code (XSS), it seems certain there html tags that excel those injected with these and other code can execute javascript, so this curious flaw is that following the execution of the xss excel breaks, discussing this with a debugger the result is as follows ..

Access violation when reading [00000034]

Well the procedure for conducting the test is fairly basic concept down here leave an address where the xss only have to select it and copy it to an Excel spreadsheet and may see vulnerability.

(will have to see the source code of the page because txt files in geocities interpret tags ...)

http://es.geocities.com/jplopezy/excelxss.txt

greetings!

Juan Pablo Lopez Yacubian
Received on Apr 26 2008

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]