CVE-1999-1017: High severity Seattle Lab Software Emurl vulnerability

Published Jul 28, 1999
·
Updated

Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message.

Affected Software

1 affected component
Seattle Lab Software Emurl<=2.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable server-side scripting/execution for the directory where Emurl stores e-mail attachments so that uploaded ASP (and other executable script) files cannot be executed when a message is opened.

    Seattle Lab Software Emurl attachment storage directory script execution = disabled
  2. Compensating control

    Block or filter e-mail attachments with server-side script extensions (for example .asp) at the mail gateway/antivirus/secure mail appliance to prevent delivery of potentially executable attachments to recipients.

  3. Operational

    Scan the attachment storage location and mailboxes for existing .asp or other executable script attachments and remove any malicious files; notify affected users and quarantine suspicious items for analysis.

Event History

Jul 28, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1017?

CVE-1999-1017 is considered a high severity vulnerability due to the risk of executing malicious scripts through email attachments.

2

How do I fix CVE-1999-1017?

To fix CVE-1999-1017, you should upgrade to a version of Seattle Labs Emurl that is later than 2.0 or disable scripting in the directory that stores email attachments.

3

What types of software are affected by CVE-1999-1017?

CVE-1999-1017 affects Seattle Labs Emurl version 2.0 and possibly earlier versions.

4

What kind of attack is enabled by CVE-1999-1017?

CVE-1999-1017 potentially allows attackers to execute malicious ASP files when users open email messages containing these attachments.

5

Who is impacted by CVE-1999-1017?

Users of Seattle Labs Emurl version 2.0 and below are impacted by CVE-1999-1017, particularly those who receive email attachments.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203