Microsoft Outlook IFrame Embedded Media Player File Vulnerability
BID:4340
Info
Microsoft Outlook IFrame Embedded Media Player File Vulnerability
| Bugtraq ID: | 4340 |
| Class: | Design Error |
| CVE: |
CVE-2002-0481 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 21 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovered by Richard M. Smith <[email protected]>. |
| Vulnerable: |
Microsoft Outlook 2002 0 |
| Not Vulnerable: | |
Discussion
Microsoft Outlook IFrame Embedded Media Player File Vulnerability
An issue has been reported with Microsoft Outlook which may result in the automatic execution of JavaScript in HTML formatted email.
If a Windows Media Player file is referenced within an IFRAME tag, JavaScript commands included in the file may automatically execute when the email is viewed.
Additional versions of Outlook may share this vulnerability. This has not, however, been confirmed.
An issue has been reported with Microsoft Outlook which may result in the automatic execution of JavaScript in HTML formatted email.
If a Windows Media Player file is referenced within an IFRAME tag, JavaScript commands included in the file may automatically execute when the email is viewed.
Additional versions of Outlook may share this vulnerability. This has not, however, been confirmed.
Exploit / POC
Microsoft Outlook IFrame Embedded Media Player File Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Outlook IFrame Embedded Media Player File Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Outlook IFrame Embedded Media Player File Vulnerability
References:
References: