积极预防 及时发现
快速响应 力保恢复
Eudora 5.0.2 允许远程攻击者通过一个带有“Attachment Converted”MI...
发布时间:2001-09-20 信息来源:管理员

CNCVE编号:CNCVE-20010677 CVE编号:CAN-2001-0677 安全级别:高 漏洞中文描述: Eudora 5.0.2 允许远程攻击者通过一个带有“Attachment Converted”MIME报头中目标文件路径的邮件来阅读任意文件,当此邮件被用户转发到攻击者时,这就发送了此目标文件。 漏洞英文描述: Eudora 5.0.2 allows a remote attacker to read arbitrary files via an email with the path of the target file in the "Attachment Converted" MIME header, which sends the file when the email is forwarded to the attacker by the user. 漏洞参考: Reference: BUGTRAQ:20010418 Eudora file leakage problem (still) Reference: URL:http://www.securityfocus.com/archive/1/177369 Reference: XF:eudora-plain-text-attachment(6431) Reference: URL:http://xforce.iss.net/static/6431.php 系统类型: Unix/Linux Win95/98/ME Win2000/NT 其他 漏洞类型:设计错误