PT-2006-5444 · Panda · Panda Platinum Internet Security

3Apa3A

·

Published

2006-09-09

·

Updated

2018-10-17

·

CVE-2006-4659

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Panda Platinum Internet Security versions 10.02.01 through 11.00.00
Description The issue allows remote attackers to cause arbitrary messages to be classified as spam via a web page that contains IMG tags with predictable URLs. This could also be regarded as a cross-site request forgery (CSRF) vulnerability, where an attacker can trick the system into performing unintended actions.
Recommendations For versions 10.02.01 through 11.00.00, consider restricting access to the spam classification feature until a patch is available. As a temporary workaround, avoid using the predictable URLs in IMG tags to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4659

Affected Products

Panda Platinum Internet Security