VendorsMicrosoftoffice_infopath2003
Vulnerabilities

Microsoft Office Infopath 2003

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2005-0820
Microsoft Office InfoPath 2003 SP1 includes sensitive information in the Manifest.xsf file in a custom .xsn form, which allows attackers to obtain printer and network information, obtain the database name, username, and password, or obtain the internal web server name.
Published 2005-03-20 · Modified
5.0EPSS 0.012
CVE-2010-1257
Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in Microsoft Office InfoPath 2003 SP3, 2007 SP1, and 2007 SP2; Office SharePoint Server 2007 SP1 and SP2; SharePoint Services 3.0 SP1 and SP2; and Internet Explorer 8 allows remote attackers to inject arbitrary web script or HTML via vectors related to sanitization.
Published 2010-06-08 · Modified
4.3EPSS 0.222