Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
WorkforceROI Xpede 4.1 allows remote attackers to obtain the database username via a request to datasource.asp, which leaks the username in a form and allows the attacker to more easily conduct brute force password guessing attacks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WorkforceROI XPede DataSource.ASP信息泄露漏洞
Vulnerability Description
XPede是一款基于WEB的项目审核软件,可运行在Microsoft Windows操作系统下。 XPede中的datasource.asp脚本存在漏洞,可以导致攻击者获得数据库其他用户信息,如用户名。 任何匿名用户(无需cookie或者帐户)请求/admin/datasource.asp就可以获得数据库用户名信息。另外,脚本提供可以改变用户密码的接口,利用这个接口攻击者可以采用暴力猜测密码的方法进行攻击。 此问题存在于XPede 4.1版本中,其他版本也可能存在此漏洞。
CVSS Information
N/A
Vulnerability Type
N/A