PT-2002-1634 · Workforceroi · Workforceroi Xpede

Published

2002-06-11

·

Updated

2008-09-05

·

CVE-2002-0584

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions WorkforceROI Xpede version 4.1
Description The issue allows remote attackers to read user timesheets by modifying the TSN ID parameter to the "ts app process.asp" script. This parameter is easily guessable because it is incremented by 1 for each new timesheet.
Recommendations For version 4.1, consider restricting access to the "ts app process.asp" script until a patch is available. As a temporary workaround, avoid using the TSN ID parameter in the affected script to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0584

Affected Products

Workforceroi Xpede