Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the spreadsheet.
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A538
https://exchange.xforce.ibmcloud.com/vulnerabilities/27312
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-069
http://www.vupen.com/english/advisories/2006/4507
http://www.vupen.com/english/advisories/2006/3577
http://www.vupen.com/english/advisories/2006/3573
http://www.us-cert.gov/cas/techalerts/TA06-318A.html
http://www.securityfocus.com/bid/19980
http://www.securiteam.com/windowsntfocus/5TP0M0KIUA.html
http://www.adobe.com/support/security/bulletins/apsb06-11.html
http://securitytracker.com/id?1016344