Vulnerabilities > CVE-2003-0402 - Unspecified vulnerability in Vignette Content Suite, Storyserver and Vignette
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN vignette
nessus
Summary
The default login template (/vgn/login) in Vignette StoryServer 5 and Vignette V/5 generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 7 |
Nessus
NASL family | CGI abuses |
NASL id | VIGNETTE_TCL_CODE_INJECTION.NASL |
description | The remote host is running Vignette StoryServer v6, a web interface to Vignette |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11749 |
published | 2003-06-17 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11749 |
title | Vignette StoryServer < 6.0.4 Arbitrary TCL Code Execution |
code |
|
References
- http://marc.info/?l=bugtraq&m=105405880325755&w=2
- http://marc.info/?l=bugtraq&m=105405880325755&w=2
- http://www.iss.net/security_center/static/12073.php
- http://www.iss.net/security_center/static/12073.php
- http://www.s21sec.com/en/avisos/s21sec-020-en.txt
- http://www.s21sec.com/en/avisos/s21sec-020-en.txt
- http://www.securityfocus.com/bid/7691
- http://www.securityfocus.com/bid/7691