积极预防 及时发现
快速响应 力保恢复
当‘Use Microsoft Viewer’ 和‘allow executables in HTM...
发布时间:2001-06-27 信息来源:管理员

CNCVE编号:CNCVE-20010365 CVE编号:CAN-2001-0365 安全级别:高 漏洞中文描述: 当‘Use Microsoft Viewer’ 和‘allow executables in HTML content’选项被激活时,Eudora 5.1早期版本允许远程攻击者通过一个包含具有ActiveX控件和带有IMG标签的恶意代码的Javascript的HTML邮件消息来执行任意代码。 漏洞英文描述: Eudora before 5.1 allows a remote attacker to execute arbitrary code, when the 'Use Microsoft Viewer' and 'allow executables in HTML content' options are enabled, via an HTML email message containing Javascript, with ActiveX controls and malicious code with IMG tag. 漏洞参考: Reference: BUGTRAQ:20010318 feeble.you!dora.exploit Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98503741910995&w=2 Reference: XF:eudora-html-execute-code Reference: URL:http://xforce.iss.net/static/6262.php Reference: BID:2490 Referenc 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:配置错误