Vulnerabilities > CVE-2003-0400 - Unspecified vulnerability in Vignette Content Suite, Storyserver and Vignette

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
vignette
exploit available

Summary

Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of memory, as demonstrated using the "-->" string in a CookieName argument to the login template, referred to as a "memory leak" in some reports.

Exploit-Db

  • descriptionVignette StoryServer 4.1 Sensitive Stack Memory Information Disclosure Vulnerability. CVE-2003-0400. Remote exploits for multiple platform
    idEDB-ID:22472
    last seen2016-02-02
    modified2003-04-07
    published2003-04-07
    reporter@stake
    sourcehttps://www.exploit-db.com/download/22472/
    titleVignette StoryServer 4.1 Sensitive Stack Memory Information Disclosure Vulnerability
  • descriptionVignette 4.x/5.0 Memory Disclosure Vulnerability. CVE-2003-0400. Remote exploit for unix platform
    idEDB-ID:22646
    last seen2016-02-02
    modified2003-05-26
    published2003-05-26
    reporterS21Sec
    sourcehttps://www.exploit-db.com/download/22646/
    titleVignette 4.x/5.0 Memory Disclosure Vulnerability