Skip to content
Noroxi

workforceroi records

8 published records for vendor workforceroi.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

      The weakness classes this vendor ships most often: where to look.

      CWE

      All records

      8 records
      • CVE-2002-0580
        30Monitor

        WorkforceROI Xpede 4.1 allows remote attackers to obtain the database username via a request to datasource.asp, which leaks the username in

        HighCVSS 7.5No exploitEPSS 2%

        workforceroi · xpedeJun 18, 2002

      • CVE-2002-0581
        30Monitor

        WorkforceROI Xpede 4.1 allows remote attackers to execute arbitrary SQL commands and read, modify, or steal credentials from the database vi

        HighCVSS 7.5No exploitEPSS 2%

        workforceroi · xpedeJun 18, 2002

      • CVE-2002-0579
        30Monitor

        WorkforceROI Xpede 4.1 allows remote attackers to gain privileges as an Xpede administrator via a direct HTTP request to the /admin/adminpro

        HighCVSS 7.5No exploitEPSS 2%

        workforceroi · xpedeJun 18, 2002

      • CVE-2002-0486
        28Monitor

        Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the c

        HighCVSS 7.2Proof of conceptEPSS 1%

        workforceroi · xpedeAug 12, 2002

      • CVE-2002-0584
        21Monitor

        WorkforceROI Xpede 4.1 allows remote attackers to read user timesheets by modifying the TSN ID parameter to the ts_app_process.asp script, w

        MediumCVSS 5.0No exploitEPSS 2%

        workforceroi · xpedeJun 18, 2002

      • CVE-2002-0582
        20Monitor

        WorkforceROI Xpede 4.1 stores temporary expense claim reports in a world-readable and indexable /reports/temp directory, which allows remote

        MediumCVSS 5.0No exploitEPSS 2%

        workforceroi · xpedeJun 18, 2002

      • CVE-2002-0583
        20Monitor

        WorkforceROI Xpede 4.1 uses a small random namespace (5 alphanumeric characters) for temporary expense claim reports in the /reports/temp di

        MediumCVSS 5.0No exploitEPSS 2%

        workforceroi · xpedeJun 18, 2002

      • CVE-2002-0487
        18Monitor

        Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local u

        MediumCVSS 4.6No exploitEPSS 0%

        workforceroi · xpedeAug 12, 2002