Predictable Location Vulnerability in Outlook 2003 Allows Remote Code Execution

Predictable Location Vulnerability in Outlook 2003 Allows Remote Code Execution

CVE-2004-0502 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on predictable locations, as demonstrated using a shell: URI.

Learn more about our Web Application Penetration Testing UK.