Vulnerabilities > CVE-2007-6198 - Unspecified vulnerability in BEA Aqualogic Interaction
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
portal/server.pt in the Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows wildcards in advanced searches for usernames, which allows remote attackers to enumerate valid usernames via the in_tx_fulltext parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
Exploit-Db
description | BEA AquaLogic Interaction 6.0/6.1 Plumtree Portal Multiple Information Disclosure Vulnerabilities. CVE-2007-6198. Webapps exploit for php platform |
id | EDB-ID:30822 |
last seen | 2016-02-03 |
modified | 2007-11-28 |
published | 2007-11-28 |
reporter | Adrian Pastor |
source | https://www.exploit-db.com/download/30822/ |
title | BEA AquaLogic Interaction 6.0/6.1 Plumtree Portal Multiple Information Disclosure Vulnerabilities |
Nessus
NASL family | CGI abuses |
NASL id | PLUMTREE_PORTAL_USER_INFO_DISCLOSURE.NASL |
description | The version of the Plumtree portal included with BEA AquaLogic Interaction / Plumtree Foundation and installed on the remote host allows an attacker to obtain a list of users defined to the portal through its search facility. This may aide in further attacks against the affected application. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 29187 |
published | 2007-12-04 |
reporter | This script is Copyright (C) 2007-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/29187 |
title | Plumtree Portal User Object User Enumeration |
code |
|
References
- http://procheckup.com/Vulnerability_PR06-11.php
- http://procheckup.com/Vulnerability_PR06-11.php
- http://secunia.com/advisories/27840
- http://secunia.com/advisories/27840
- http://www.securityfocus.com/archive/1/484469/100/0/threaded
- http://www.securityfocus.com/archive/1/484469/100/0/threaded
- http://www.securityfocus.com/bid/26620
- http://www.securityfocus.com/bid/26620
- http://www.securitytracker.com/id?1019004
- http://www.securitytracker.com/id?1019004
- http://www.vupen.com/english/advisories/2007/4040
- http://www.vupen.com/english/advisories/2007/4040