İçeriğe atla
Noroxi

workforceroi kayıtları

workforceroi üreticisine ait 8 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Yıllara göre kayıt

    Çubuk: toplam · koyu kısım: CISA KEV.

    Tekrar eden sınıflar

      Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.

      CWE

      Tüm kayıtlar

      8 kayıt
      • CVE-2002-0580
        30İzleyin

        WorkforceROI Xpede 4.1 allows remote attackers to obtain the database username via a request to datasource.asp, which leaks the username in

        YüksekCVSS 7,5İstismar yokEPSS %2

        workforceroi · xpede18 Haz 2002

      • CVE-2002-0581
        30İzleyin

        WorkforceROI Xpede 4.1 allows remote attackers to execute arbitrary SQL commands and read, modify, or steal credentials from the database vi

        YüksekCVSS 7,5İstismar yokEPSS %2

        workforceroi · xpede18 Haz 2002

      • CVE-2002-0579
        30İzleyin

        WorkforceROI Xpede 4.1 allows remote attackers to gain privileges as an Xpede administrator via a direct HTTP request to the /admin/adminpro

        YüksekCVSS 7,5İstismar yokEPSS %2

        workforceroi · xpede18 Haz 2002

      • CVE-2002-0486
        28İzleyin

        Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the c

        YüksekCVSS 7,2Kavram kanıtıEPSS %1

        workforceroi · xpede12 Ağu 2002

      • CVE-2002-0584
        21İzleyin

        WorkforceROI Xpede 4.1 allows remote attackers to read user timesheets by modifying the TSN ID parameter to the ts_app_process.asp script, w

        OrtaCVSS 5,0İstismar yokEPSS %2

        workforceroi · xpede18 Haz 2002

      • CVE-2002-0582
        20İzleyin

        WorkforceROI Xpede 4.1 stores temporary expense claim reports in a world-readable and indexable /reports/temp directory, which allows remote

        OrtaCVSS 5,0İstismar yokEPSS %2

        workforceroi · xpede18 Haz 2002

      • CVE-2002-0583
        20İzleyin

        WorkforceROI Xpede 4.1 uses a small random namespace (5 alphanumeric characters) for temporary expense claim reports in the /reports/temp di

        OrtaCVSS 5,0İstismar yokEPSS %2

        workforceroi · xpede18 Haz 2002

      • CVE-2002-0487
        18İzleyin

        Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local u

        OrtaCVSS 4,6İstismar yokEPSS %0

        workforceroi · xpede12 Ağu 2002