Vulnerabilities > CVE-2003-0398 - Unspecified vulnerability in Vignette Content Suite, Storyserver and Vignette
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN vignette
nessus
Summary
Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, with the SSI EXEC feature enabled, allows remote attackers to execute arbitrary code via a text variable to a Vignette Application that is later displayed.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
Nessus
NASL family | CGI abuses |
NASL id | VIGNETTE_TCL_CODE_INJECTION.NASL |
description | The remote host is running Vignette StoryServer v6, a web interface to Vignette |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11749 |
published | 2003-06-17 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11749 |
title | Vignette StoryServer < 6.0.4 Arbitrary TCL Code Execution |
code |
|
References
- http://marc.info/?l=bugtraq&m=105405734223874&w=2
- http://marc.info/?l=bugtraq&m=105405734223874&w=2
- http://www.iss.net/security_center/static/12077.php
- http://www.iss.net/security_center/static/12077.php
- http://www.s21sec.com/es/avisos/s21sec-016-en.txt
- http://www.s21sec.com/es/avisos/s21sec-016-en.txt
- http://www.securityfocus.com/bid/7685
- http://www.securityfocus.com/bid/7685