7.5

CVE-2005-1668

YusASP Web Asset Manager 1.0 allows remote attackers to gain privileges via a direct request to assetmanager.asp.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
YusaspWeb Asset Manager Version1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.99% 0.781
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-425 Direct Request ('Forced Browsing')

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

http://www.osvdb.org/16198
Broken Link
http://www.securiteam.com/windowsntfocus/5OP0115FPQ.html
Patch
Broken Link
http://www.securityfocus.com/bid/13501
Third Party Advisory
Broken Link
VDB Entry