CVE-2005-3560: High severity Zonelabs Zonealarm Anti-spyware vulnerability
Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1, and (5) ZoneAlarm 6.0 allow remote attackers to bypass the "Advanced Program Control and OS Firewall filters" setting via URLs in "HTML Modal Dialogs" (window.location.href) contained within JavaScript tags.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3560?
CVE-2005-3560 is classified as a medium severity vulnerability.
How do I fix CVE-2005-3560?
To fix CVE-2005-3560, users should update their ZoneAlarm software to the latest version that addresses the vulnerability.
What types of ZoneAlarm products are affected by CVE-2005-3560?
CVE-2005-3560 affects ZoneAlarm Pro 6.0, ZoneAlarm Internet Security Suite 6.0, ZoneAlarm Anti-Virus 6.0, ZoneAlarm Anti-Spyware 6.0 through 6.1, and ZoneAlarm 6.0.
What exploitation method is used for CVE-2005-3560?
CVE-2005-3560 can be exploited by remote attackers through URLs in HTML Modal Dialogs.
Is there any user impact associated with CVE-2005-3560?
Yes, successful exploitation of CVE-2005-3560 allows attackers to bypass critical security features of ZoneAlarm.