Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/544 | vdb entry patch vendor advisory |
http://marc.info/?l=ntbugtraq&m=93316253431588&w=2 | mailing list |