vendor:
actiTIME
by:
Gjoko 'LiquidWorm' Krstic
8,8
CVSS
HIGH
Open Redirection, HTTP Response Splitting and Unquoted Service Path Elevation Of Privilege
601, 113, 462
CWE
Product Name: actiTIME
Affected Version From: 2015.2 (Small Team Edition)
Affected Version To: 2015.2 (Small Team Edition)
Patch Exists: YES
Related CWE: N/A
CPE: a:actimind:actitime
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 6.1 for x86
2015
actiTIME 2015.2 Multiple Vulnerabilities
actiTIME is a web timesheet software. It suffers from multiple security vulnerabilities including: Open Redirection, HTTP Response Splitting and Unquoted Service Path Elevation Of Privilege.
Mitigation:
Ensure that the application is properly configured and that all security patches are up to date.