VendorsComersus Open Technologiescomersus_backoffice_liteall versions
Vulnerabilities

Comersus Open Technologies Comersus Backoffice Lite

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2005-0301
comersus_backoffice_install10.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to bypass authentication and gain privileges via a direct request to the program.
Published 2005-02-10 · Modified
7.5EPSS 0.016
CVE-2005-0302
SQL injection vulnerability in default.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to execute arbitrary SQL commands via the referer field in the HTTP header.
Published 2005-02-10 · Modified
7.5EPSS 0.013
CVE-2005-3397
Cross-site scripting (XSS) vulnerability in Comersus BackOffice allows remote attackers to inject arbitrary web script or HTML via the error parameter to comersus_backoffice_supportError.asp. NOTE: the comersus_backoffice_message.asp/message vector is already covered by CVE-2005-2191 item 2.
Published 2005-11-01 · Modified
4.31 PoCEPSS 0.014
CVE-2005-0303
Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_supportError.asp or (2) comersus_backofficelite_supportError.asp in BackOffice Lite 6.0 and 6.01 allow remote attackers to inject arbitrary web script or HTML via the error parameter.
Published 2005-02-10 · Modified
4.3EPSS 0.012