workforceroi records
8 published records for vendor workforceroi.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2002-0580No exploit | WorkforceROI Xpede 4.1 allows remote attackers to obtain the database username via a request to datasource.asp, which leaks the username in workforceroi · xpede | High7.5 | — | 1.6% | Jun 18, 2002 |
30Monitor | CVE-2002-0581No exploit | WorkforceROI Xpede 4.1 allows remote attackers to execute arbitrary SQL commands and read, modify, or steal credentials from the database viworkforceroi · xpede | High7.5 | — | 1.6% | Jun 18, 2002 |
30Monitor | CVE-2002-0579No exploit | WorkforceROI Xpede 4.1 allows remote attackers to gain privileges as an Xpede administrator via a direct HTTP request to the /admin/adminproworkforceroi · xpede | High7.5 | — | 1.6% | Jun 18, 2002 |
28Monitor | CVE-2002-0486Proof of concept | Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the cworkforceroi · xpede | High7.2 | — | 0.8% | Aug 12, 2002 |
21Monitor | CVE-2002-0584No exploit | WorkforceROI Xpede 4.1 allows remote attackers to read user timesheets by modifying the TSN ID parameter to the ts_app_process.asp script, wworkforceroi · xpede | Medium5.0 | — | 1.8% | Jun 18, 2002 |
20Monitor | CVE-2002-0582No exploit | WorkforceROI Xpede 4.1 stores temporary expense claim reports in a world-readable and indexable /reports/temp directory, which allows remoteworkforceroi · xpede | Medium5.0 | — | 1.6% | Jun 18, 2002 |
20Monitor | CVE-2002-0583No exploit | WorkforceROI Xpede 4.1 uses a small random namespace (5 alphanumeric characters) for temporary expense claim reports in the /reports/temp diworkforceroi · xpede | Medium5.0 | — | 1.6% | Jun 18, 2002 |
18Monitor | CVE-2002-0487No exploit | Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local uworkforceroi · xpede | Medium4.6 | — | 0.4% | Aug 12, 2002 |
- CVE-2002-058030Monitor
WorkforceROI Xpede 4.1 allows remote attackers to obtain the database username via a request to datasource.asp, which leaks the username in
HighCVSS 7.5No exploitEPSS 2%workforceroi · xpedeJun 18, 2002
- CVE-2002-058130Monitor
WorkforceROI Xpede 4.1 allows remote attackers to execute arbitrary SQL commands and read, modify, or steal credentials from the database vi
HighCVSS 7.5No exploitEPSS 2%workforceroi · xpedeJun 18, 2002
- CVE-2002-057930Monitor
WorkforceROI Xpede 4.1 allows remote attackers to gain privileges as an Xpede administrator via a direct HTTP request to the /admin/adminpro
HighCVSS 7.5No exploitEPSS 2%workforceroi · xpedeJun 18, 2002
- CVE-2002-048628Monitor
Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the c
HighCVSS 7.2Proof of conceptEPSS 1%workforceroi · xpedeAug 12, 2002
- CVE-2002-058421Monitor
WorkforceROI Xpede 4.1 allows remote attackers to read user timesheets by modifying the TSN ID parameter to the ts_app_process.asp script, w
MediumCVSS 5.0No exploitEPSS 2%workforceroi · xpedeJun 18, 2002
- CVE-2002-058220Monitor
WorkforceROI Xpede 4.1 stores temporary expense claim reports in a world-readable and indexable /reports/temp directory, which allows remote
MediumCVSS 5.0No exploitEPSS 2%workforceroi · xpedeJun 18, 2002
- CVE-2002-058320Monitor
WorkforceROI Xpede 4.1 uses a small random namespace (5 alphanumeric characters) for temporary expense claim reports in the /reports/temp di
MediumCVSS 5.0No exploitEPSS 2%workforceroi · xpedeJun 18, 2002
- CVE-2002-048718Monitor
Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local u
MediumCVSS 4.6No exploitEPSS 0%workforceroi · xpedeAug 12, 2002