PT-2002-1634 · Workforceroi · Workforceroi Xpede
Publicado
2002-06-11
·
Atualizado
2008-09-05
·
CVE-2002-0584
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WorkforceROI Xpede version 4.1
Description
The issue allows remote attackers to read user timesheets by modifying the
TSN ID parameter to the "ts app process.asp" script. This parameter is easily guessable because it is incremented by 1 for each new timesheet.Recommendations
For version 4.1, consider restricting access to the "ts app process.asp" script until a patch is available. As a temporary workaround, avoid using the
TSN ID parameter in the affected script to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Workforceroi Xpede