VYPR
Unrated severityNVD Advisory· Published Feb 14, 2005· Updated Jun 16, 2026

CVE-2005-0409

CVE-2005-0409

Description

CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Citrusdb/Citrusdb2 versions
    cpe:2.3:a:citrusdb:citrusdb:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:citrusdb:citrusdb:*:*:*:*:*:*:*:*range: <=0.3.6
    • (no CPE)range: <=0.3.6

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.