First published: Wed Apr 27 2005(Updated: )
owOfflineCC.asp in OneWorldStore allows remote attackers to obtain sensitive information by modifying the idOrder parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JD Edwards OneWorld | =basic | |
Oracle JD Edwards OneWorld | =business | |
Oracle JD Edwards OneWorld | =enterprise | |
Oracle JD Edwards OneWorld | =free | |
Oracle JD Edwards OneWorld | =soho |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1329 is classified as a medium severity vulnerability.
CVE-2005-1329 can be exploited by modifying the idOrder parameter to retrieve sensitive information from the server.
CVE-2005-1329 affects various versions of OneWorldStore, including basic, business, enterprise, free, and soho editions.
To fix CVE-2005-1329, validate and sanitize user input for the idOrder parameter in the application.
CVE-2005-1329 may allow remote attackers to access sensitive user information, including order details.