First published: Mon May 15 2000(Updated: )
The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's email account.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Seattle Lab Software Emurl | =2.0 | |
=2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0397 is categorized as a moderate severity vulnerability due to its impact on user account privacy.
To address CVE-2000-0397, update the EMURL application to a version that corrects the improper encoding of session identifiers in URLs.
Users of EMURL version 2.0 are potentially affected by CVE-2000-0397, as it allows unauthorized access to email accounts.
CVE-2000-0397 exploits predictable identifiers in user session URLs to allow attackers unauthorized access to email accounts.
CVE-2000-0397 was disclosed in May 2000.