CVE Vulnerabilities

CVE-2005-0229

Published: Apr 27, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card information via a direct request to newfile.txt.

Affected Software

NameVendorStart VersionEnd Version
Citrusdb_customer_databaseCitrusdb0.1.2 (including)0.1.2 (including)
Citrusdb_customer_databaseCitrusdb0.2 (including)0.2 (including)
Citrusdb_customer_databaseCitrusdb0.2.1 (including)0.2.1 (including)
Citrusdb_customer_databaseCitrusdb0.3 (including)0.3 (including)
Citrusdb_customer_databaseCitrusdb0.3.1 (including)0.3.1 (including)
Citrusdb_customer_databaseCitrusdb0.3.5 (including)0.3.5 (including)

References