VYPR

CWE-425

Direct Request ('Forced Browsing')

BaseIncomplete

Description

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-143 · CAPEC-144 · CAPEC-668 · CAPEC-87

CVEs mapped to this weakness (244)

page 13 of 13
  • CVE-2005-1697May 24, 2005
    risk 0.00cvss —epss 0.01

    The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simple_smarty.php, which reveals the path in an error message.

  • CVE-2005-1685May 20, 2005
    risk 0.00cvss —epss 0.02

    episodex guestbook allows remote attackers to bypass authentication and edit scripts via a direct request to admin.asp.

  • CVE-2005-1668May 18, 2005
    risk 0.00cvss —epss 0.02

    YusASP Web Asset Manager 1.0 allows remote attackers to gain privileges via a direct request to assetmanager.asp.

  • CVE-2004-2144Dec 31, 2004
    risk 0.00cvss —epss 0.03

    Baal Smart Forms before 3.2 allows remote attackers to bypass authentication and obtain system access via a direct request to regadmin.php.