vendor:
Eudora
by:
flynn
7.5
CVSS
HIGH
Spoofing
20
CWE
Product Name: Eudora
Affected Version From: 6.0.1
Affected Version To: 6.1.2001
Patch Exists: YES
Related CWE: N/A
CPE: a:qualcomm:eudora:6.1.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2004
Eudora 6.0.1 on Windows spoof, LaunchProtect
A problem has been identified in the implementation of LaunchProtect within Eudora. Because of this, it may be possible to trick users into performing dangerous actions by sending a plain README attachment and a README.bat attachment, which contains a malicious script that can be executed without warning.
Mitigation:
Upgrade to the latest version of Eudora, which includes a fix for this vulnerability.