Description
Eudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable encoded attachments, which makes it easier for remote attackers to read arbitrary files via spoofed "Converted" headers.
Affected products
- qualcomm / eudora6.2.0.14 – 6.2.0.14
Exploits & proofs of concept
- exploit-dbEudora 6.0.3 (Windows) - Attachment Spoofingby anonymous
Updated 14m ago · 8 sources