VulnerabilityModified
CVE-2006-4658
Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 uses sequential message numbers in generated URLs that are not filtered if the user replies to a message, which might allow remote attackers to determine mail usage patterns.
MEDIUM 5.0EPSS 2.07%
Does this matter?
Lower severity and a low EPSS score (2.07%). Track it; it rarely justifies an emergency change on its own.
Description
Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 uses sequential message numbers in generated URLs that are not filtered if the user replies to a message, which might allow remote attackers to determine mail usage patterns.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.07% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- panda/panda platinum internet security
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/21769Vendor Advisory
- http://securityreason.com/securityalert/1524
- http://www.security.nnov.ru/advisories/pandais.aspVendor Advisory
- http://www.securityfocus.com/archive/1/445479/100/0/threaded
- http://www.securityfocus.com/bid/19891
- http://secunia.com/advisories/21769Vendor Advisory
- http://securityreason.com/securityalert/1524
- http://www.security.nnov.ru/advisories/pandais.aspVendor Advisory
- http://www.securityfocus.com/archive/1/445479/100/0/threaded
- http://www.securityfocus.com/bid/19891
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.