20041113 Eudora 6.2 attachment spoofmailing list
http://marc.info/?l=bugtraq&m=110037078519691&w=2 CVE-2004-1521
Eudora 6.0.3 (Windows) - Attachment Spoofing
Record summary
CVE-2004-1521 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Eudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable encoded attachments, which makes it easier for remote attackers to read arbitrary files via spoofed "Converted" headers.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBEudora 6.0.3 (Windows) - Attachment SpoofingExploitDB exploitby anonymousNot analyzed1 file
References
520041113 Eudora 6.2 attachment spoofmailing list
http://marc.info/?l=ntbugtraq&m=110053102601655&w=2 packetstormsecurity.nl
http://packetstormsecurity.nl/0411-exploits/eudora62014.txt eudora-base64-attach-spoof-variant(18064)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/18064 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1521