CVE-2006-4659
Last modified
CVE-2006-4659 is a vulnerability of currently unknown severity. The Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 uses predictable URLs for the spam classification of each message, which allows remote attackers to cause Panda to classify arbitrary messages as spam via a web page that contains IMG tags with the predictable URLs. NOTE: this issue could also be regarded as a cross-site request forgery (CSRF) vulnerability.. EPSS estimates a 2.00% chance of exploitation in the next 30 days.
Description
The Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 uses predictable URLs for the spam classification of each message, which allows remote attackers to cause Panda to classify arbitrary messages as spam via a web page that contains IMG tags with the predictable URLs. NOTE: this issue could also be regarded as a cross-site request forgery (CSRF) vulnerability.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Panda | Panda Platinum Internet Security | 2006_10.02.01 |
| Panda | Panda Platinum Internet Security | 2007_11.00.00 |
References
- http://www.security.nnov.ru/advisories/pandais.aspVendor Advisory
- http://www.security.nnov.ru/advisories/pandais.aspVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-4659?
How severe is CVE-2006-4659?
How do I fix CVE-2006-4659?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-4653(1) Amazing Little Poll and (2) Amazing Little Picture Poll …
- CVE-2006-4654Format string vulnerability in Easy Address Book Web Server …
- CVE-2006-4655Buffer overflow in the Strcmp function in the XKEYBOARD exte…
- CVE-2006-4656PHP remote file inclusion vulnerability in admin/editeur/spa…
- CVE-2006-4657Panda Platinum Internet Security 2006 10.02.01 and 2007 11.0…
- CVE-2006-4658Panda Platinum Internet Security 2006 10.02.01 and 2007 11.0…
- CVE-2006-4660Multiple cross-site scripting (XSS) vulnerabilities in the R…
- CVE-2006-4661AOL ICQ Toolbar 1.3 for Internet Explorer (toolbaru.dll) doe…
- CVE-2006-4662Heap-based buffer overflow in the MCRegEx__Search function i…
- CVE-2006-4663The source code tar archive of the Linux kernel 2.6.16, 2.6.…7.8
- CVE-2006-4664PHP remote file inclusion vulnerability in includes/function…
- CVE-2006-4665Cross-site scripting (XSS) vulnerability in index.php in MKP…
Are you affected by CVE-2006-4659?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
