Vulnerabilities > CVE-2004-0374 - Remote Information Disclosure vulnerability in Interchange
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
NONE Summary
Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensitive SQL information via an HTTP request ending with the "__SQLUSER__" string.
Vulnerable Configurations
Exploit-Db
description | Interchange 4.8.x/5.0 Remote Information Disclosure Vulnerability. CVE-2004-0374. Webapps exploit for asp platform |
id | EDB-ID:23895 |
last seen | 2016-02-02 |
modified | 2004-03-30 |
published | 2004-03-30 |
reporter | anonymous |
source | https://www.exploit-db.com/download/23895/ |
title | Interchange 4.8.x/5.0 - Remote Information Disclosure Vulnerability |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-471.NASL |
description | A vulnerability was discovered recently in Interchange, an e-commerce and general HTTP database display system. This vulnerability can be exploited by an attacker to expose the content of arbitrary variables. An attacker may learn SQL access information for your Interchange application and use this information to read and manipulate sensitive data. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15308 |
published | 2004-09-29 |
reporter | This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15308 |
title | Debian DSA-471-1 : interchange - missing input sanitising |
code |
|
References
- http://ftp.icdevgroup.org/interchange/5.0/WHATSNEW
- http://secunia.com/advisories/11234
- http://www.debian.org/security/2004/dsa-471
- http://www.icdevgroup.org/pipermail/interchange-announce/2004/000043.html
- http://www.securityfocus.com/bid/10005
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15670