Emurl Scripting Vulnerability
BID:544
Info
Emurl Scripting Vulnerability
| Bugtraq ID: | 544 |
| Class: | Design Error |
| CVE: |
CVE-1999-1017 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 27 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | Posted to NTBugtraq July 28, 1999 by Oisin Grehan <[email protected]>. |
| Vulnerable: |
Seattle Lab Software Emurl 2.0 |
| Not Vulnerable: | |
Discussion
Emurl Scripting Vulnerability
Emurl places attachments received via email into a folder that is accessible via http and marked 'scriptable'. Because of this it can be possible for an attacker send attachments containing hostile asp or similar scripting code to an email address on the target server. This code will then be executed by the webserver when the recipient reads their email.
Emurl places attachments received via email into a folder that is accessible via http and marked 'scriptable'. Because of this it can be possible for an attacker send attachments containing hostile asp or similar scripting code to an email address on the target server. This code will then be executed by the webserver when the recipient reads their email.
Exploit / POC
Emurl Scripting Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Emurl Scripting Vulnerability
References:
References: