Vulnerabilities > CVE-2006-6960 - Security Bypass vulnerability in Spy Sweeper
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL network
webroot-software
Summary
The Compression Sweep feature in WebRoot Spy Sweeper 4.5.9 and earlier does not handle non-ZIP archives, which allows remote attackers to bypass the malware detection via files with (1) RAR, (2) GZ, (3) TAR, (4) CAB, or (5) ACE compression.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |