mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-11 08:27:12 +02:00
770 B
770 B
CVE-2015-4626
Description
B.A.S C2Box before 4.0.0 (r19171) relies on client-side validation, which allows remote attackers to "corrupt the business logic" via a negative value in an overdraft.
POC
Reference
- https://packetstormsecurity.com/files/136450/C2Box-4.0.0-r19171-Validation-Bypass.html
- https://packetstormsecurity.com/files/136450/C2Box-4.0.0-r19171-Validation-Bypass.html