WebEOC before 6.0.2 does not properly check user authorization, which allows remote attackers to gain privileges via a direct request to a resource.Referenceshttp://www.kb.cert.org/vuls/id/JGEI-6BWLWGhttp://www.kb.cert.org/vuls/id/258834