CVE-2002-0727

high

Description

The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.

References

https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-044

http://www.securityfocus.com/bid/4449

http://www.osvdb.org/3006

http://www.iss.net/security_center/static/8777.php

http://marc.info/?l=bugtraq&m=101829645415486&w=2

Details

Source: Mitre, NVD

Published: 2002-09-24

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.1013