Netscape Email Client Message Deletion Weakness
BID:6499
Info
Netscape Email Client Message Deletion Weakness
| Bugtraq ID: | 6499 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 01 2003 12:00AM |
| Updated: | Jan 01 2003 12:00AM |
| Credit: | The discovery of this weakness is credited to "Michael Puchol" <[email protected]>. |
| Vulnerable: |
Netscape Netscape 7.0 |
| Not Vulnerable: | |
Discussion
Netscape Email Client Message Deletion Weakness
A weakness has been discovered in the Netscape 7.0 Email Client. When a user deletes an email message the file is moved to the Trash folder. By clicking the 'Empty Trash' option a user may be under the impression that the messages will be deleted when they actually are not.
A malicious local user may take advantage of this weakness to view messages believed to be deleted by the legitmate Netscape user.
A weakness has been discovered in the Netscape 7.0 Email Client. When a user deletes an email message the file is moved to the Trash folder. By clicking the 'Empty Trash' option a user may be under the impression that the messages will be deleted when they actually are not.
A malicious local user may take advantage of this weakness to view messages believed to be deleted by the legitmate Netscape user.
Exploit / POC
Netscape Email Client Message Deletion Weakness
No exploit is required for this weakness.
No exploit is required for this weakness.
References
Netscape Email Client Message Deletion Weakness
References:
References:
- Potential disclosure of sensitive information in Netscape 7.0 ("Michael Puchol"
)