180solutions Zango downloads "required Adware components" without checking integrity or authenticity, which might allow context-dependent attackers to execute arbitrary code by subverting the DNS resolution of static.zangocash.com.
References
Configurations
History
21 Nov 2024, 00:11
Type | Values Removed | Values Added |
---|---|---|
References | () http://secdev.zoller.lu/research/zango.htm - Exploit, Patch | |
References | () http://securityreason.com/securityalert/890 - | |
References | () http://www.securityfocus.com/archive/1/433566/100/0/threaded - |
Information
Published : 2006-05-12 00:02
Updated : 2025-04-03 01:03
NVD link : CVE-2006-2324
Mitre link : CVE-2006-2324
CVE.ORG link : CVE-2006-2324
JSON object : View
Products Affected
180solutions
- zango
CWE