Vulnerability Description
Qualcomm Eudora 5.1.1, 5.2, and possibly other versions stores email attachments in a predictable location, which allows remote attackers to read arbitrary files via a link that loads an attachment with malicious script into a frame, which then executes the script in the local browser context.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Eudora | 5.1.1 |
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0079.html
- http://www.idefense.com/advisory/11.19.02b.txtPatchVendor Advisory
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0079.html
- http://www.idefense.com/advisory/11.19.02b.txtPatchVendor Advisory
FAQ
What is CVE-2002-1210?
CVE-2002-1210 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Qualcomm Eudora 5.1.1, 5.2, and possibly other versions stores email attachments in a predictable location, which allows remote attackers to read arbitrary files via a link that loads an attachment wi...
How severe is CVE-2002-1210?
CVE-2002-1210 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1210?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Eudora.