CVE-2005-0685
Description
Multiple access validation errors in OutStart Participate Enterprise (PE) allow remote attackers to (1) browse arbitrary directory trees by modifying the rootFolder parameter to displaynavigator.jsp, (2) rename arbitrary directory objects by modifying the selectedObject parameter to renamepopup.jsp, (3) delete arbitrary directory objects by modifying the selectedObjectsCSV parameter to displaydeletenavigator.jsp, and conduct other unauthorized activities via the (4) showDeleteView, (5) showWebFolderView, (6) showLibraryView, (7) showMyLibraryView, (8) singleSelectObject, (9) processRadioSelection, (10) processCheckboxSelection, (11) singleSelectObject, (12) addToSelectedObjects, or (13) removeFromSelectedObjects commands.
Affected products
1- cpe:2.3:a:outstart:participate_enterprise:3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- secunia.com/advisories/14542nvdPatchVendor Advisory
- security.honour.ca/outstartpsi.txtnvdPatchVendor Advisory
- www.securityfocus.com/bid/12752nvdPatchVendor Advisory
- www.securityfocus.com/archive/1/392623nvdVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/19632nvd
News mentions
0No linked articles in our index yet.