Vulnerabilities > CVE-2003-0399 - Unspecified vulnerability in Vignette Content Suite, Storyserver and Vignette
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN vignette
nessus
Summary
Vignette StoryServer 4 and 5, Vignette V/5, and possibly other versions allows remote attackers to perform unauthorized SELECT queries by setting the vgn_creds cookie to an arbitrary value and directly accessing the save template.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
Nessus
NASL family | CGI abuses |
NASL id | VIGNETTE_TCL_CODE_INJECTION.NASL |
description | The remote host is running Vignette StoryServer v6, a web interface to Vignette |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11749 |
published | 2003-06-17 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11749 |
title | Vignette StoryServer < 6.0.4 Arbitrary TCL Code Execution |
code |
|
References
- http://marc.info/?l=bugtraq&m=105405874325673&w=2
- http://marc.info/?l=bugtraq&m=105405874325673&w=2
- http://www.iss.net/security_center/static/12076.php
- http://www.iss.net/security_center/static/12076.php
- http://www.s21sec.com/es/avisos/s21sec-017-en.txt
- http://www.s21sec.com/es/avisos/s21sec-017-en.txt
- http://www.securityfocus.com/bid/7683
- http://www.securityfocus.com/bid/7683