CVE

Id
4970  
CVE No.
CVE-2002-0579  
Status
Candidate  
Description
WorkforceROI Xpede 4.1 allows remote attackers to gain privileges as an Xpede administrator via a direct HTTP request to the /admin/adminproc.asp script, which does not prompt for a password.  
Phase
Proposed (20020611)  
Votes
ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  
Comments