CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.
References
Configurations
History
20 Nov 2024, 23:55
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031707.html - | |
References | () http://www.redteam-pentesting.de/advisories/rt-sa-2005-003.txt - Exploit, Vendor Advisory |
Information
Published : 2005-02-14 05:00
Updated : 2024-11-20 23:55
NVD link : CVE-2005-0409
Mitre link : CVE-2005-0409
CVE.ORG link : CVE-2005-0409
JSON object : View
Products Affected
citrusdb
- citrusdb
CWE