CVE-2013-3596

AdvancePro Advanceware allows remote authenticated users to obtain sensitive information about arbitrary customers' orders via a modified id parameter.
References
Link Resource
http://osvdb.org/96801
http://www.kb.cert.org/vuls/id/704526 US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:advanceprotech:advanceware:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2013-09-08 16:55

Updated : 2024-02-28 12:00


NVD link : CVE-2013-3596

Mitre link : CVE-2013-3596

CVE.ORG link : CVE-2013-3596


JSON object : View

Products Affected

advanceprotech

  • advanceware
CWE
CWE-264

Permissions, Privileges, and Access Controls