Vulnerabilities > CVE-2003-0405 - Unspecified vulnerability in Vignette Content Suite, Storyserver and Vignette
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN vignette
nessus
Summary
Vignette StoryServer 5 and Vignette V/6 allows remote attackers to execute arbitrary TCL code via (1) an HTTP query or cookie which is processed in the NEEDS command, or (2) an HTTP Referrer that is processed in the VALID_PATHS command.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 7 |
Nessus
NASL family | CGI abuses |
NASL id | VIGNETTE_TCL_CODE_INJECTION.NASL |
description | The remote host is running Vignette StoryServer v6, a web interface to Vignette |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11749 |
published | 2003-06-17 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11749 |
title | Vignette StoryServer < 6.0.4 Arbitrary TCL Code Execution |
code |
|
References
- http://marc.info/?l=bugtraq&m=105405922826197&w=2
- http://marc.info/?l=bugtraq&m=105405922826197&w=2
- http://www.iss.net/security_center/static/12070.php
- http://www.iss.net/security_center/static/12070.php
- http://www.s21sec.com/es/avisos/s21sec-024-en.txt
- http://www.s21sec.com/es/avisos/s21sec-024-en.txt
- http://www.securityfocus.com/bid/7690
- http://www.securityfocus.com/bid/7690
- http://www.securityfocus.com/bid/7692
- http://www.securityfocus.com/bid/7692