PT-2002-1634 · Workforceroi · Workforceroi Xpede

Publicado

2002-06-11

·

Atualizado

2008-09-05

·

CVE-2002-0584

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions WorkforceROI Xpede version 4.1
Description The issue allows remote attackers to read user timesheets by modifying the TSN ID parameter to the "ts app process.asp" script. This parameter is easily guessable because it is incremented by 1 for each new timesheet.
Recommendations For version 4.1, consider restricting access to the "ts app process.asp" script until a patch is available. As a temporary workaround, avoid using the TSN ID parameter in the affected script to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0584

Produtos afetados

Workforceroi Xpede