PT-2005-2304 · Inprotect · Nprotect Netizen
Keigo Yamazaki
·
Publicado
2005-04-13
·
Atualizado
2016-10-18
·
CVE-2005-1301
CVSS v2.0
2.6
Baixa
| Vetor | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
nProtect:Netizen version 2005.3.17.1
Description:
The issue arises from the software's failure to properly verify the authenticity of its update module, allowing remote malicious websites to write arbitrary files.
Recommendations:
For version 2005.3.17.1, consider restricting access to update modules to only authorized sites as a temporary workaround until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Nprotect Netizen