Record summary

CVE-2009-0700 has a selected CVSS score of 4.0; EIP currently links 2 catalogued exploits.

Description

Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sensitive Customer or Order data via a modified Pfad parameter to pagesUTF8/Sys_DirAnzeige.jsp, or (2) list sensitive Jobs via a direct request to pagesUTF8/auftrag_job.jsp.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBPlunet BusinessManager 4.1 - 'pagesUTF8/Sys_DirAnzeige.jsp?Pfad' Direct Request Information DisclosureExploitDB exploitby Matteo IgnaccoloNot analyzed1 file
ExploitDB

PoC details
ExploitDBPlunet BusinessManager 4.1 - 'pagesUTF8/auftrag_job.jsp?Pfad' Direct Request Information DisclosureExploitDB exploitby Matteo IgnaccoloNot analyzed1 file
ExploitDB

PoC details

References

6