Vulnerabilities
Vulnerable Software
Plunet:  >> Business Manager  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in pagesUTF8/auftrag_allgemeinauftrag.jsp in Plunet BusinessManager 4.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the (1) QUB and (2) Bez74 parameters.
CVSS Score
3.5
EPSS Score
0.002
Published
2009-02-23
Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sensitive Customer or Order data via a modified Pfad parameter to pagesUTF8/Sys_DirAnzeige.jsp, or (2) list sensitive Jobs via a direct request to pagesUTF8/auftrag_job.jsp.
CVSS Score
4.0
EPSS Score
0.057
Published
2009-02-23


Contact Us

Shodan ® - All rights reserved