CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.
oryginał ENCVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:NCitrusdb
APPCitrusdb≤ 0.3.6
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2005-0408CRITICAL9.8PL ✓ten sam produkt
CitrusDB: pominięcie uwierzytelnienia przez przewidywalny hash MD5 cookie
CVE-2005-0411HIGH7.5ten sam produkt
Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and loca...
CVE-2005-0410MEDIUM5.0ten sam produkt
SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject d...
CVE-2005-0229MEDIUM5.0ten sam vendor
CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote ...