Vulnerabilities > CVE-2015-4626 - Numeric Errors vulnerability in Treasuryxpress C2Box
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
B.A.S C2Box before 4.0.0 (r19171) relies on client-side validation, which allows remote attackers to "corrupt the business logic" via a negative value in an overdraft.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Packetstorm
data source | https://packetstormsecurity.com/files/download/136450/c2box-bypass.txt |
id | PACKETSTORM:136450 |
last seen | 2016-12-05 |
published | 2016-03-28 |
reporter | Harish Ramadoss |
source | https://packetstormsecurity.com/files/136450/C2Box-4.0.0-r19171-Validation-Bypass.html |
title | C2Box 4.0.0(r19171) Validation Bypass |