Vulnerabilities > CVE-2005-2286 - Unspecified vulnerability in ESI products Webeoc

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
esi-products
critical

Summary

WebEOC before 6.0.2 does not properly check user authorization, which allows remote attackers to gain privileges via a direct request to a resource.

Vulnerable Configurations

Part Description Count
Application
Esi_Products
1