Microsoft Office InfoPath 2003 SP1 includes sensitive information in the Manifest.xsf file in a custom .xsn form, which allows attackers to obtain printer and network information, obtain the database name, username, and password, or obtain the internal web server name.
Link | Tags |
---|---|
http://securitytracker.com/id?1013454 | vdb entry |
http://www.osvdb.org/14882 | vdb entry |
http://www.securityfocus.com/bid/12824 | vdb entry |
http://support.microsoft.com/kb/867443 | vendor advisory |