Skip to main content

Microsoft Outlook Express 6 Plain Text Message Script Execution
Vulnerability

posted onSeptember 14, 2001
by hitbsecnews

Microsoft Outlook Express 6 contains a vulnerability which allows an email message of
content-type 'text/plain' to execute specifically crafted scripting components.

It is important to note that Outlook Express 6 does not allow any scripting to be executed
by default. This security feature must be turned off in order to exploit this vulnerability.

Solution:A workaround is to disable scripting in Outlook Express.

bugtraq id
3334
class
Unknown
cve
CVE-MAP-NOMATCH
remote
Yes
local
No
published
September 12, 2001
updated
September 12, 2001
vulnerable
Microsoft Outlook Express 6.0
- Microsoft Windows ME
- Microsoft Windows 98se
- Microsoft Windows 98
- Microsoft Windows 95
- Microsoft Windows NT 4.0SP6a
+ Microsoft Windows NT 4.0
- Microsoft Windows NT 4.0SP5
+ Microsoft Windows NT 4.0
- Microsoft Windows NT 4.0SP4
+ Microsoft Windows NT 4.0
- Microsoft Windows 2000 SP2
+ Microsoft Windows 2000
- Microsoft Windows 2000 SP1
+ Microsoft Windows 2000
- Microsoft Windows 2000

Source

Tags

Networking

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th