{"api_version":"1","generated_at":"2026-07-23T07:32:02+00:00","cve":"CVE-2005-0409","urls":{"html":"https://cve.report/CVE-2005-0409","api":"https://cve.report/api/cve/CVE-2005-0409.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-0409","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-0409"},"summary":{"title":"CVE-2005-0409","description":"CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-02-14 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.4","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031707.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031707.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[Full-Disclosure] Advisory: Authentication bypass in CitrusDB","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.redteam-pentesting.de/advisories/rt-sa-2005-003.txt","name":"http://www.redteam-pentesting.de/advisories/rt-sa-2005-003.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-0409","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-0409","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"409","vulnerable":"1","versionEndIncluding":"0.3.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"citrusdb","cpe5":"citrusdb","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:13:54.144Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20050214 Advisory: Upload Authorization bypass in CitrusDB","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031707.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.redteam-pentesting.de/advisories/rt-sa-2005-003.txt"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-02-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-06-04T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20050214 Advisory: Upload Authorization bypass in CitrusDB","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031707.html"},{"tags":["x_refsource_MISC"],"url":"http://www.redteam-pentesting.de/advisories/rt-sa-2005-003.txt"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-0409","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20050214 Advisory: Upload Authorization bypass in CitrusDB","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031707.html"},{"name":"http://www.redteam-pentesting.de/advisories/rt-sa-2005-003.txt","refsource":"MISC","url":"http://www.redteam-pentesting.de/advisories/rt-sa-2005-003.txt"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-0409","datePublished":"2005-02-16T05:00:00.000Z","dateReserved":"2005-02-14T00:00:00.000Z","dateUpdated":"2024-08-07T21:13:54.144Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-02-14 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:citrusdb:citrusdb:*:*:*:*:*:*:*:*","versionEndIncluding":"0.3.6","matchCriteriaId":"AA1F1B4D-3FA6-4A54-A671-9B403DE5EC33"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"409","Ordinal":"1","Title":"CVE-2005-0409","CVE":"CVE-2005-0409","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"409","Ordinal":"1","NoteData":"CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.","Type":"Description","Title":"CVE-2005-0409"},{"CveYear":"2005","CveId":"409","Ordinal":"2","NoteData":"2005-02-16","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"409","Ordinal":"3","NoteData":"2005-06-04","Type":"Other","Title":"Modified"}]}}}