CVE-2005-0409
Last modified
CVE-2005-0409 is a vulnerability of currently unknown severity. CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.. EPSS estimates a 5.66% chance of exploitation in the next 30 days.
Description
CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Citrusdb | Citrusdb | <= 0.3.6 |
References
- http://www.redteam-pentesting.de/advisories/rt-sa-2005-003.txtExploit, Vendor Advisory
- http://www.redteam-pentesting.de/advisories/rt-sa-2005-003.txtExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-0409?
How severe is CVE-2005-0409?
How do I fix CVE-2005-0409?
Are you affected by CVE-2005-0409?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
