CVE-2004-1893
Summary
| CVE | CVE-2004-1893 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Dreamweaver MX, when "Using Driver On Testing Server" or "Using DSN on Testing Server" is selected, uploads the mmhttpdb.asp script to the web site but does not require authentication, which allows remote attackers to obtain sensitive information and possibly execute arbitrary SQL commands via a direct request to mmhttpdb.asp. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Macromedia | Dreamweaver | 2004 | All | All | All |
| Application | Macromedia | Dreamweaver | 6.0 | All | All | All |
| Application | Macromedia | Dreamweaver | 6.1 | All | All | All |
| Application | Macromedia | Dreamweaver Ultradev | 4.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Macromedia - MPSB 04-05 Potential Risk in Dreamweaver Remote Database Connectivity | af854a3a-2127-422b-91ae-364da2661108 | www.macromedia.com | Vendor Advisory |
| Secunia - Advisories - Dreamweaver Database Connection Script Security Issue | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch |
| '[[email protected]: New Macromedia Security Zone Bulletin Posted]' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| nextgenss.com - This website is for sale! - nextgenss Resources and Information. | af854a3a-2127-422b-91ae-364da2661108 | www.nextgenss.com | |
| Macromedia Dreamweaver Remote User Database Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.