WorkforceROI XPede Arbitrary Time Sheet Disclosure Vulnerabiltiy
BID:4556
Info
WorkforceROI XPede Arbitrary Time Sheet Disclosure Vulnerabiltiy
| Bugtraq ID: | 4556 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-0584 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 19 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Discovered by Cerberus Vulgaris <[email protected]>. |
| Vulnerable: |
WorkforceROI Xpede 4.1 |
| Not Vulnerable: | |
Discussion
WorkforceROI XPede Arbitrary Time Sheet Disclosure Vulnerabiltiy
XPede is web-based project accounting software. It is available for Microsoft Windows operating systems.
An issue has been reported in Xpede, which could allow a remote user to access the time sheets of other users. The vulnerability is in the 'ets_app_process.asp' script and is due to a lack of adequate authorization checks.
This issue was reported for XPede 4.1. Other versions may also be affected.
XPede is web-based project accounting software. It is available for Microsoft Windows operating systems.
An issue has been reported in Xpede, which could allow a remote user to access the time sheets of other users. The vulnerability is in the 'ets_app_process.asp' script and is due to a lack of adequate authorization checks.
This issue was reported for XPede 4.1. Other versions may also be affected.
Exploit / POC
WorkforceROI XPede Arbitrary Time Sheet Disclosure Vulnerabiltiy
No exploit code is required.
No exploit code is required.