PT-2002-2492 · Qualcomm+1 · Qualcomm Eudora+2

Published

2002-12-31

·

Updated

2017-07-11

·

CVE-2002-1770

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Qualcomm Eudora version 5.1
Description The issue allows remote attackers to execute arbitrary code via an HTML e-mail message. This is achieved by using a file:// URL in a t:video tag to reference an attached Windows Media Player file containing JavaScript code. The code is launched and executed in the My Computer zone by Internet Explorer.
Recommendations For Qualcomm Eudora version 5.1, consider disabling the execution of JavaScript code in attached files as a temporary workaround until a patch is available. Restrict access to attached Windows Media Player files to minimize the risk of exploitation. Avoid using the t:video tag in HTML e-mail messages until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1770

Affected Products

Internet Explorer
Qualcomm Eudora
Windows Media Player