{"api_version":"1","generated_at":"2026-04-23T10:17:47+00:00","cve":"CVE-2004-1893","urls":{"html":"https://cve.report/CVE-2004-1893","api":"https://cve.report/api/cve/CVE-2004-1893.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1893","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1893"},"summary":{"title":"CVE-2004-1893","description":"Dreamweaver MX, when \"Using Driver On Testing Server\" or \"Using DSN on Testing Server\" is selected, uploads the mmhttpdb.asp script to the web site but does not require authentication, which allows remote attackers to obtain sensitive information and possibly execute arbitrary SQL commands via a direct request to mmhttpdb.asp.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.macromedia.com/devnet/security/security_zone/mpsb04-05.html","name":"http://www.macromedia.com/devnet/security/security_zone/mpsb04-05.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Macromedia - MPSB 04-05 Potential Risk in Dreamweaver Remote Database Connectivity","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/11284","name":"http://secunia.com/advisories/11284","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Secunia - Advisories - Dreamweaver Database Connection Script Security Issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=108102481929451&w=2","name":"http://marc.info/?l=bugtraq&m=108102481929451&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'[securityzone@macromedia.com: New Macromedia Security Zone Bulletin Posted]' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15721","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15721","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.nextgenss.com/advisories/dreamweaver.txt","name":"http://www.nextgenss.com/advisories/dreamweaver.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"nextgenss.com -&nbspThis website is for sale! -&nbspnextgenss Resources and Information.","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/10036","name":"http://www.securityfocus.com/bid/10036","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Macromedia Dreamweaver Remote User Database Access Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1893","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1893","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1893","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macromedia","cpe5":"dreamweaver","cpe6":"2004","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1893","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macromedia","cpe5":"dreamweaver","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1893","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macromedia","cpe5":"dreamweaver","cpe6":"6.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1893","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macromedia","cpe5":"dreamweaver_ultradev","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:07:49.051Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20040403 [securityzone@macromedia.com: New Macromedia Security Zone Bulletin Posted]","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=108102481929451&w=2"},{"name":"11284","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/11284"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.macromedia.com/devnet/security/security_zone/mpsb04-05.html"},{"name":"10036","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/10036"},{"name":"dreamweaver-test-script-sql-injection(15721)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15721"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.nextgenss.com/advisories/dreamweaver.txt"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-04-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"Dreamweaver MX, when \"Using Driver On Testing Server\" or \"Using DSN on Testing Server\" is selected, uploads the mmhttpdb.asp script to the web site but does not require authentication, which allows remote attackers to obtain sensitive information and possibly execute arbitrary SQL commands via a direct request to mmhttpdb.asp."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20040403 [securityzone@macromedia.com: New Macromedia Security Zone Bulletin Posted]","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=108102481929451&w=2"},{"name":"11284","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/11284"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.macromedia.com/devnet/security/security_zone/mpsb04-05.html"},{"name":"10036","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/10036"},{"name":"dreamweaver-test-script-sql-injection(15721)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15721"},{"tags":["x_refsource_MISC"],"url":"http://www.nextgenss.com/advisories/dreamweaver.txt"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1893","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Dreamweaver MX, when \"Using Driver On Testing Server\" or \"Using DSN on Testing Server\" is selected, uploads the mmhttpdb.asp script to the web site but does not require authentication, which allows remote attackers to obtain sensitive information and possibly execute arbitrary SQL commands via a direct request to mmhttpdb.asp."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20040403 [securityzone@macromedia.com: New Macromedia Security Zone Bulletin Posted]","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=108102481929451&w=2"},{"name":"11284","refsource":"SECUNIA","url":"http://secunia.com/advisories/11284"},{"name":"http://www.macromedia.com/devnet/security/security_zone/mpsb04-05.html","refsource":"CONFIRM","url":"http://www.macromedia.com/devnet/security/security_zone/mpsb04-05.html"},{"name":"10036","refsource":"BID","url":"http://www.securityfocus.com/bid/10036"},{"name":"dreamweaver-test-script-sql-injection(15721)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15721"},{"name":"http://www.nextgenss.com/advisories/dreamweaver.txt","refsource":"MISC","url":"http://www.nextgenss.com/advisories/dreamweaver.txt"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1893","datePublished":"2005-05-10T04:00:00.000Z","dateReserved":"2005-05-04T00:00:00.000Z","dateUpdated":"2024-08-08T01:07:49.051Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:macromedia:dreamweaver:6.0:*:*:*:*:*:*:*","matchCriteriaId":"9E8C9E95-ACFC-49CD-BD6E-5D5D269F257F"},{"vulnerable":false,"criteria":"cpe:2.3:a:macromedia:dreamweaver:6.1:*:*:*:*:*:*:*","matchCriteriaId":"29664269-770C-4E39-95B8-E754A5E7C17E"},{"vulnerable":false,"criteria":"cpe:2.3:a:macromedia:dreamweaver:2004:*:*:*:*:*:*:*","matchCriteriaId":"F7E6E1EA-1A14-4B64-9E8C-BCC629F98346"},{"vulnerable":false,"criteria":"cpe:2.3:a:macromedia:dreamweaver_ultradev:4.0:*:*:*:*:*:*:*","matchCriteriaId":"D966A980-57F2-4FBB-A86C-EB93C8AE4A85"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1893","Ordinal":"1","Title":"CVE-2004-1893","CVE":"CVE-2004-1893","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1893","Ordinal":"1","NoteData":"Dreamweaver MX, when \"Using Driver On Testing Server\" or \"Using DSN on Testing Server\" is selected, uploads the mmhttpdb.asp script to the web site but does not require authentication, which allows remote attackers to obtain sensitive information and possibly execute arbitrary SQL commands via a direct request to mmhttpdb.asp.","Type":"Description","Title":"CVE-2004-1893"},{"CveYear":"2004","CveId":"1893","Ordinal":"2","NoteData":"2005-05-10","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1893","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}