Vulnerability Description
Multiple access validation errors in OutStart Participate Enterprise (PE) allow remote attackers to (1) browse arbitrary directory trees by modifying the rootFolder parameter to displaynavigator.jsp, (2) rename arbitrary directory objects by modifying the selectedObject parameter to renamepopup.jsp, (3) delete arbitrary directory objects by modifying the selectedObjectsCSV parameter to displaydeletenavigator.jsp, and conduct other unauthorized activities via the (4) showDeleteView, (5) showWebFolderView, (6) showLibraryView, (7) showMyLibraryView, (8) singleSelectObject, (9) processRadioSelection, (10) processCheckboxSelection, (11) singleSelectObject, (12) addToSelectedObjects, or (13) removeFromSelectedObjects commands.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Outstart | Participate Enterprise | 3 |
References
- http://secunia.com/advisories/14542PatchVendor Advisory
- http://security.honour.ca/outstartpsi.txtPatchVendor Advisory
- http://www.securityfocus.com/archive/1/392623Vendor Advisory
- http://www.securityfocus.com/bid/12752PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19632
- http://secunia.com/advisories/14542PatchVendor Advisory
- http://security.honour.ca/outstartpsi.txtPatchVendor Advisory
- http://www.securityfocus.com/archive/1/392623Vendor Advisory
- http://www.securityfocus.com/bid/12752PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19632
FAQ
What is CVE-2005-0685?
CVE-2005-0685 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple access validation errors in OutStart Participate Enterprise (PE) allow remote attackers to (1) browse arbitrary directory trees by modifying the rootFolder parameter to displaynavigator.jsp, ...
How severe is CVE-2005-0685?
CVE-2005-0685 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-0685?
Check the references section above for vendor advisories and patch information. Affected products include: Outstart Participate Enterprise.