7.5
CVSSv2

CVE-2005-4197

Published: 13/12/2005 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

tunnelform.yaws in Nortel SSL VPN 4.2.1.6 allows remote malicious users to execute arbitrary commands via a link in the a parameter, which is executed with extra privileges in a cryptographically signed Java Applet.

Vulnerable Product Search on Vulmon Subscribe to Product

nortel ssl vpn 4.1.2.11

nortel ssl vpn 4.1.2.12

nortel ssl vpn

Exploits

source: wwwsecurityfocuscom/bid/15798/info Nortel SSL VPN is prone to an input validation vulnerability This issue could be exploited to cause arbitrary commands to be executed on a user's computer Cross-site scripting attacks are also possible Nortel SSL VPN 4216 is vulnerable to this issue; other versions may also be affected ...