Back to Database
Status published
High
CVE-2005-0301
comersus_backoffice_install10.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers...
Vulnerability Description
comersus_backoffice_install10.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to bypass authentication and gain privileges via a direct request to the program.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2005-0301
Credits & Attribution
No credits recorded in the NVD database.
References
More from comersus open technologies
View All →CVE-2007-3324
Multiple cross-site scripting (XSS) vulnerabilities in Comersus Cart 7.07 allow...
Medium
4.3
CVE-2007-3323
SQL injection vulnerability in comersus_optReviewReadExec.asp in Comersus Shop Cart 7.07...
High
7.5
CVE-2005-3397
Cross-site scripting (XSS) vulnerability in Comersus BackOffice allows remote attackers...
Medium
4.3
CVE-2005-3285
Cross-site scripting (XSS) vulnerability in comersus_backoffice_searchItemForm.asp in Comersus BackOffice Plus...
Medium
4.3
CVE-2005-2191
Multiple cross-site scripting (XSS) vulnerabilities in Comersus shopping cart allow...
Medium
4.3
Affected Vendor
comersus open technologies
View all reports →Affected Software
comersus backoffice lite
Vulnerable Versions:
6.0, 6.1
Timeline
Official Publish:
February 10th, 2005
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.