Microsoft Office InfoPath 2003 SP1 includes sensitive information in the Manifest.xsf file in a custom .xsn form, which allows attackers to obtain printer and network information, obtain the database name, username, and password, or obtain the internal web server name.
References
Configurations
Information
Published : 2005-05-01 21:00
Updated : 2008-09-05 13:47
NVD link : CVE-2005-0820
Mitre link : CVE-2005-0820
JSON object : View
CWE
Products Affected
microsoft
- office_infopath