Vulnerabilities > CVE-2004-2563 - Remote Authentication Bypass vulnerability in Serena Software Serena Teamtrack 6.1.1

047910
CVSS 5.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
serena-software
exploit available

Summary

Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and database information, and conduct cross-site scripting (XSS) attacks, via a direct request to tmtrack.dll with modified LoginPage and Template parameters.

Vulnerable Configurations

Part Description Count
Application
Serena_Software
1

Exploit-Db

descriptionSerena TeamTrack 6.1.1 Remote Authentication Bypass Vulnerability. CVE-2004-2563. Remote exploit for windows platform
idEDB-ID:24297
last seen2016-02-02
modified2004-07-21
published2004-07-21
reporterNoam Rathaus
sourcehttps://www.exploit-db.com/download/24297/
titleSerena TeamTrack 6.1.1 - Remote Authentication Bypass Vulnerability