Vulnerability Description
Zone Labs IMsecure and IMsecure Pro before 1.5 allow remote attackers to bypass Active Link Filtering via an instant message containing a URL with hex encoded file extensions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zonelabs | Imsecure | 1.0.0.0 |
References
- http://download.zonelabs.com/bin/free/securityAlert/16.htmlPatchVendor Advisory
- http://marc.info/?l=bugtraq&m=110020607924001&w=2
- http://secunia.com/advisories/13169Vendor Advisory
- http://www.securityfocus.com/bid/11662Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18042
- http://download.zonelabs.com/bin/free/securityAlert/16.htmlPatchVendor Advisory
- http://marc.info/?l=bugtraq&m=110020607924001&w=2
- http://secunia.com/advisories/13169Vendor Advisory
- http://www.securityfocus.com/bid/11662Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18042
FAQ
What is CVE-2004-1517?
CVE-2004-1517 is a vulnerability with a CVSS score of 7.5 (HIGH). Zone Labs IMsecure and IMsecure Pro before 1.5 allow remote attackers to bypass Active Link Filtering via an instant message containing a URL with hex encoded file extensions.
How severe is CVE-2004-1517?
CVE-2004-1517 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1517?
Check the references section above for vendor advisories and patch information. Affected products include: Zonelabs Imsecure.