Vulnerabilities > CVE-2015-2858 - Unspecified vulnerability in Datalex Airline Booking Software
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Datalex airline booking software before 2015-09-03 allows remote attackers to read or write to arbitrary user data via a modified profileId parameter to (1) ValidateFormAction.do or (2) ProfileConfirmEditAddressAction.do.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |