vendor:
Eudora
by:
me
7,5
CVSS
HIGH
Spoofing
20
CWE
Product Name: Eudora
Affected Version From: 6.0.3
Affected Version To: 6.0.3
Patch Exists: YES
Related CWE: N/A
CPE: a:qualcomm:eudora:6.0.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2002
Eudora 6.0.3 on Windows spoof, LaunchProtect
This exploit allows an attacker to spoof attachments in Eudora 6.0.3 on Windows. The attacker can embed CR=x0d characters which get converted internally into a NUL=x00 and ignored, allowing them to spoof "attachment converted" lines. The attacker can also guess the full path to the attach directory and change the name shown to anything they like, but this will result in a broken icon. They can also include HTML inclusions to do file, http, and javascript links.
Mitigation:
Upgrade to a version of Eudora that is not vulnerable to this exploit.