Vulnerability Description
WebEOC before 6.0.2 does not properly check user authorization, which allows remote attackers to gain privileges via a direct request to a resource.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Esi Products | Webeoc | <= 6.0.1 |
References
- http://www.kb.cert.org/vuls/id/258834PatchUS Government Resource
- http://www.kb.cert.org/vuls/id/JGEI-6BWLWG
- http://www.kb.cert.org/vuls/id/258834PatchUS Government Resource
- http://www.kb.cert.org/vuls/id/JGEI-6BWLWG
FAQ
What is CVE-2005-2286?
CVE-2005-2286 is a vulnerability with a CVSS score of 10.0 (HIGH). WebEOC before 6.0.2 does not properly check user authorization, which allows remote attackers to gain privileges via a direct request to a resource.
How severe is CVE-2005-2286?
CVE-2005-2286 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-2286?
Check the references section above for vendor advisories and patch information. Affected products include: Esi Products Webeoc.