The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.
References
Link | Resource |
---|---|
http://www.securityfocus.com/archive/1/212724 | Third Party Advisory VDB Entry Vendor Advisory |
http://www.securityfocus.com/archive/1/213762 | Third Party Advisory VDB Entry Vendor Advisory |
http://www.securityfocus.com/bid/3305 | Third Party Advisory VDB Entry Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7093 | VDB Entry |
http://www.securityfocus.com/archive/1/212724 | Third Party Advisory VDB Entry Vendor Advisory |
http://www.securityfocus.com/archive/1/213762 | Third Party Advisory VDB Entry Vendor Advisory |
http://www.securityfocus.com/bid/3305 | Third Party Advisory VDB Entry Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7093 | VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
History
20 Nov 2024, 23:36
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/archive/1/212724 - Third Party Advisory, VDB Entry, Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/213762 - Third Party Advisory, VDB Entry, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/3305 - Third Party Advisory, VDB Entry, Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/7093 - VDB Entry |
Information
Published : 2001-09-07 04:00
Updated : 2024-11-20 23:36
NVD link : CVE-2001-1099
Mitre link : CVE-2001-1099
CVE.ORG link : CVE-2001-1099
JSON object : View
Products Affected
microsoft
- exchange_server
symantec
- norton_antivirus
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type