Outlook Express BCC: Recipient Disclosure
Medium Nessus Network Monitor Plugin ID 2150
SynopsisThe remote email client is vulnerable to a flaw where the 'BCC' address is not hidden.
DescriptionThe remote host is using Outlook Express version 6.00 or 6.00 SP1. It is reported that the effectiveness of the BCC: field in these versions cannot be trusted. People receiving the mail through the To: and CC: fields can find the invisible receipients by opening the mail in a text editor.
SolutionUpgrade or patch according to vendor recommendations.