XSS vulnerability in the Office Powerpoint macro (Office Connector)

XMLWordPrintable

    • 6.5

      To reproduce:
      1. Attach a ".ppt" file to the page. (any file with that extension - doesn't need to be a powerpoint file)
      2. Add "Office Powerpoint" macro with Slide Number as:

      "><script>alert(document.domain)</script>
      

      3. View page.

      See officeconnector, PptConverter.java, line 97.

              Assignee:
              PatrickA
              Reporter:
              Dougall Johnson
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: