Flaw in eMule 0.49

2008.07.15
Credit: carl hardwick
Risk: Low
Local: No
Remote: No
CVE: N/A
CWE: N/A

eMule 0.49 and previous versions could expose the OS user account name when it sends the shared files list. When an user asks for the shared files list of another user, the full path of folders are sent and they're fully visible into the emule log. example: Requesting shared files from 'yohan' User yohan (1507...) shares directory 'C:Documents and SettingsJean-DenisMy documents...' OS user account name Jean-Denis is visible and could be used in further attacks.

References:

http://seclists.org/fulldisclosure/2008/Jul/0207.html


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top