CWE-425
Direct Request ('Forced Browsing')
Description
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-127 · CAPEC-143 · CAPEC-144 · CAPEC-668 · CAPEC-87
CVEs mapped to this weakness (244)
page 13 of 13| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2005-1697 | 0.00 | — | 0.01 | May 24, 2005 | The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simple_smarty.php, which reveals the path in an error message. | |||
| CVE-2005-1685 | 0.00 | — | 0.02 | May 20, 2005 | episodex guestbook allows remote attackers to bypass authentication and edit scripts via a direct request to admin.asp. | |||
| CVE-2005-1668 | 0.00 | — | 0.02 | May 18, 2005 | YusASP Web Asset Manager 1.0 allows remote attackers to gain privileges via a direct request to assetmanager.asp. | |||
| CVE-2004-2144 | 0.00 | — | 0.03 | Dec 31, 2004 | Baal Smart Forms before 3.2 allows remote attackers to bypass authentication and obtain system access via a direct request to regadmin.php. |
- CVE-2005-1697May 24, 2005risk 0.00cvss —epss 0.01
The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simple_smarty.php, which reveals the path in an error message.
- CVE-2005-1685May 20, 2005risk 0.00cvss —epss 0.02
episodex guestbook allows remote attackers to bypass authentication and edit scripts via a direct request to admin.asp.
- CVE-2005-1668May 18, 2005risk 0.00cvss —epss 0.02
YusASP Web Asset Manager 1.0 allows remote attackers to gain privileges via a direct request to assetmanager.asp.
- CVE-2004-2144Dec 31, 2004risk 0.00cvss —epss 0.03
Baal Smart Forms before 3.2 allows remote attackers to bypass authentication and obtain system access via a direct request to regadmin.php.