Vulnerabilities > CVE-2003-0404 - Cross-Site Scripting vulnerability in Vignette Content Suite, Storyserver and Vignette

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
vignette
exploit available

Summary

Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login template.

Exploit-Db

descriptionVignette 4/5 Cross-Site Scripting Vulnerabilities. CVE-2003-0404. Remote exploit for unix platform
idEDB-ID:22648
last seen2016-02-02
modified2003-05-26
published2003-05-26
reporterRamon Pinuaga Cascales
sourcehttps://www.exploit-db.com/download/22648/
titleVignette 4/5 - Cross-Site Scripting Vulnerabilities