CVE-2000-0397
Published May 15, 2000The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's email account.
Vendor/product archive
2 CVEs tagged to seattle_lab_software / emurl — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's email account.
Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to ex…