Vulnerability Name: | CVE-2005-3560 (CCN-22971) | ||||||||
Assigned: | 2005-11-07 | ||||||||
Published: | 2005-11-07 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1, and (5) ZoneAlarm 6.0 allow remote attackers to bypass the "Advanced Program Control and OS Firewall filters" setting via URLs in "HTML Modal Dialogs" (window.location.href) contained within JavaScript tags. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Nov 07 2005 - 12:46:04 CST Zone Labs Products Advance Program Control and OS Firewall (Behavioral Based) Technology Bypass Vulnerability Source: MITRE Type: CNA CVE-2005-3560 Source: CCN Type: SA17450 ZoneAlarm Personal Firewall Program Control Feature Bypass Source: SECUNIA Type: Vendor Advisory 17450 Source: SREASON Type: UNKNOWN 155 Source: OSVDB Type: UNKNOWN 20677 Source: CCN Type: OSVDB ID: 20677 ZoneAlarm ShowHTMLDialog() Outbound Filter Bypass Source: BUGTRAQ Type: UNKNOWN 20051107 Zone Labs Products Advance Program Control and OS Firewall (Behavioral Based) Technology Bypass Vulnerability Source: BID Type: Exploit 15347 Source: CCN Type: BID-15347 Zone Labs Zone Alarm Advance Program Control Bypass Weakness Source: CCN Type: Zone Labs Web site Zone Labs: Zone Labs, Internet security products, online safety, software, protection Source: XF Type: UNKNOWN zonealarm-showhtmldialog-obtain-information(22971) Source: XF Type: UNKNOWN zonealarm-showhtmldialog-obtain-information(22971) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |