漏洞信息详情
ZoneLabs IMsecure的URI过滤绕过漏洞
- CNNVD编号:CNNVD-200412-1144
- 危害等级: 高危
- CVE编号:
CVE-2004-1517
- 漏洞类型:
输入验证
- 发布时间:
2004-12-31
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
zonelabs - 漏洞来源:
Paul Kurczaba of K… -
漏洞简介
Zone Labs Imsecure和IMsecure Pro 1.5之前的版本存在漏洞。远程攻击者借助包含一个十六进制编码的文件extenstions网址的即时消息绕过Active Link Filtering。
漏洞公告
The vendor has released version 1.5.0.39 of the affected package to resolve this issue, as well as a security alert documenting the vulnerability. Please see the referenced advisory for further information on obtaining fixes.
参考网址
来源: XF
名称: imsecure-active-link-bypass(18042)
链接:http://xforce.iss.net/xforce/xfdb/18042
来源: BID
名称: 11662
链接:http://www.securityfocus.com/bid/11662
来源: download.zonelabs.com
链接:http://download.zonelabs.com/bin/free/securityAlert/16.html
来源: SECUNIA
名称: 13169
链接:http://secunia.com/advisories/13169
来源: BUGTRAQ
名称: 20041111 Zone Labs IMsecure Active Link Filter Bypass
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=110020607924001&w=2