VulnerabilityModified
CVE-2005-0285
Webseries Payment Application does not properly restrict privileged operations, which allows remote authenticated users to gain privileges by directly accessing certain URLs.
MEDIUM 4.6EPSS 1.43%
Does this matter?
Lower severity and a low EPSS score (1.43%). Track it; it rarely justifies an emergency change on its own.
Description
Webseries Payment Application does not properly restrict privileged operations, which allows remote authenticated users to gain privileges by directly accessing certain URLs.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.43% probability · 72th percentile
- CISA KEV
- Not listed
- Affected
- bottomline/webseries payment application
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=110547396124885&w=2
- http://secunia.com/advisories/13821
- http://securitytracker.com/id?1012854
- http://www.securityfocus.com/bid/12216Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18848
- http://marc.info/?l=bugtraq&m=110547396124885&w=2
- http://secunia.com/advisories/13821
- http://securitytracker.com/id?1012854
- http://www.securityfocus.com/bid/12216Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18848
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.