Vulnerabilities > CVE-2015-4626 - Numeric Errors vulnerability in Treasuryxpress C2Box

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
treasuryxpress
CWE-189

Summary

B.A.S C2Box before 4.0.0 (r19171) relies on client-side validation, which allows remote attackers to "corrupt the business logic" via a negative value in an overdraft.

Vulnerable Configurations

Part Description Count
Application
Treasuryxpress
1

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/136450/c2box-bypass.txt
idPACKETSTORM:136450
last seen2016-12-05
published2016-03-28
reporterHarish Ramadoss
sourcehttps://packetstormsecurity.com/files/136450/C2Box-4.0.0-r19171-Validation-Bypass.html
titleC2Box 4.0.0(r19171) Validation Bypass