Search

published date: April 27, 2005

CVE-2005-0229 : CitrusDB 0.3.5 and earlier...

Description

CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card information via a direct request to newfile.txt.

Product(s):

  • CitrusDB Customer Database 0.1.2
  • CitrusDB Customer Database 0.2.1
  • CitrusDB Customer Database 0.2
  • CitrusDB Customer Database 0.3.1
  • CitrusDB Customer Database 0.3.5
  • CitrusDB Customer Database 0.3

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2005-0229, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2005-0229 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?