Remote Information Disclosure in Brightmail Spamfilter by Symantec
CVE-2004-0671
Currently unrated
Summary
The Brightmail Spamfilter, an email filtering product by Symantec, is susceptible to a remote information disclosure vulnerability. By manipulating the 'id' parameter in a specific request ('viewMsgDetails.do'), attackers can gain unauthorized access to the email messages of other users. This flaw in versions 6.0 and earlier beta releases compromises user confidentiality and allows potential exploitation by malicious actors.
References
Timeline
Vulnerability published
Vulnerability Reserved