Логотип exploitDog
bind:CVE-2005-0409
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2005-0409

Количество 2

Количество 2

nvd логотип

CVE-2005-0409

почти 21 год назад

CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.

CVSS2: 6.4
EPSS: Низкий
github логотип

GHSA-6gw3-9jpp-7crr

почти 4 года назад

CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-0409

CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.

CVSS2: 6.4
4%
Низкий
почти 21 год назад
github логотип
GHSA-6gw3-9jpp-7crr

CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.

4%
Низкий
почти 4 года назад

Уязвимостей на страницу