PT-2005-2304 · Inprotect · Nprotect Netizen

Keigo Yamazaki

·

Published

2005-04-13

·

Updated

2016-10-18

·

CVE-2005-1301

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: nProtect:Netizen version 2005.3.17.1
Description: The issue arises from the software's failure to properly verify the authenticity of its update module, allowing remote malicious websites to write arbitrary files.
Recommendations: For version 2005.3.17.1, consider restricting access to update modules to only authorized sites as a temporary workaround until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1301

Affected Products

Nprotect Netizen