PT-2002-1634 · Workforceroi · Workforceroi Xpede
Published
2002-06-11
·
Updated
2008-09-05
·
CVE-2002-0584
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WorkforceROI Xpede version 4.1
Description
The issue allows remote attackers to read user timesheets by modifying the
TSN ID parameter to the "ts app process.asp" script. This parameter is easily guessable because it is incremented by 1 for each new timesheet.Recommendations
For version 4.1, consider restricting access to the "ts app process.asp" script until a patch is available. As a temporary workaround, avoid using the
TSN ID parameter in the affected script to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Workforceroi Xpede