Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

WorkforceROI XPede Unprotected Administrative Facilities Vulnerability

XPede is web-based project accounting software. It is available for Microsoft Windows operating systems.

XPede does not prompt non-administrative users for administrative authentication credentials if they attempt to access an administrative script. This may enable a malicious XPede user to gain unauthorized access to the administrative facilities of the software.

This issue was reported for XPede 4.1. Other versions may also be affected.







 

Privacy Statement
Copyright 2008, SecurityFocus