WorkforceROI XPede Unprotected Administrative Facilities Vulnerability
BID:4552
Info
WorkforceROI XPede Unprotected Administrative Facilities Vulnerability
| Bugtraq ID: | 4552 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-0579 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 19 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Discovered by Cerberus Vulgaris <[email protected]>. |
| Vulnerable: |
WorkforceROI Xpede 4.1 |
| Not Vulnerable: | |
Discussion
WorkforceROI XPede Unprotected Administrative Facilities Vulnerability
XPede is web-based project accounting software. It is available for Microsoft Windows operating systems.
XPede does not prompt non-administrative users for administrative authentication credentials if they attempt to access an administrative script. This may enable a malicious XPede user to gain unauthorized access to the administrative facilities of the software.
This issue was reported for XPede 4.1. Other versions may also be affected.
XPede is web-based project accounting software. It is available for Microsoft Windows operating systems.
XPede does not prompt non-administrative users for administrative authentication credentials if they attempt to access an administrative script. This may enable a malicious XPede user to gain unauthorized access to the administrative facilities of the software.
This issue was reported for XPede 4.1. Other versions may also be affected.
Solution / Fix
WorkforceROI XPede Unprotected Administrative Facilities Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.