Qualcomm Eudora 5.1 allows remote attackers to execute arbitrary code via an HTML e-mail message that uses a file:// URL in a t:video tag to reference an attached Windows Media Player file containing JavaScript code, which is launched and executed in the My Computer zone by Internet Explorer.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/8609 | vdb entry |
http://marc.info/?l=ntbugtraq&m=101680201823534&w=2 | mailing list |
http://marc.info/?l=bugtraq&m=101680576827641&w=2 | mailing list |
http://security.greymagic.com/adv/gm002-ie/ | exploit vendor advisory |
http://www.securityfocus.com/bid/4343 | vdb entry |