CVE-2003-0405
Summary
| CVE | CVE-2003-0405 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-06-30 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Vignette StoryServer 5 and Vignette V/6 allows remote attackers to execute arbitrary TCL code via (1) an HTTP query or cookie which is processed in the NEEDS command, or (2) an HTTP Referrer that is processed in the VALID_PATHS command. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vignette | Content Suite | 5.0 | All | All | All |
| Application | Vignette | Content Suite | 6.0 | All | All | All |
| Application | Vignette | Content Suite | 6.0.1 | All | All | All |
| Application | Vignette | Content Suite | 6.0.2 | All | All | All |
| Application | Vignette | Content Suite | 6.0.3 | All | All | All |
| Application | Vignette | Storyserver | 5.0 | All | All | All |
| Application | Vignette | Vignette | 5.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Página no encontrada – S21Sec | af854a3a-2127-422b-91ae-364da2661108 | www.s21sec.com | Patch, Vendor Advisory |
| ISS X-Force Database: vignette-tcl-code-execution (12070): Vignette and StoryServer could allow an attacker to execute TCL code | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Vendor Advisory |
| 'S21SEC-024 - Vignette TCL Injection' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Vignette VALID_PATHS Command TCL Code Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| Vignette NEEDS Command TCL Code Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.