MEDIUM🇵🇱 Wersja polska

CVE-2005-0409

CVSS 6.4v2.0pub. 2005-02-14upd. 2026-04-16

CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.

CVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:N
  • Citrusdb

    APP
    Citrusdb
    ≤ 0.3.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2005-0408CRITICAL9.8PL ✓same product

CitrusDB: pominięcie uwierzytelnienia przez przewidywalny hash MD5 cookie

CVE-2005-0411HIGH7.5same product

Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and loca...

CVE-2005-0410MEDIUM5.0same product

SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject d...

CVE-2005-0229MEDIUM5.0same vendor

CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote ...