Vignette Application Portal Remote Information Disclosure Vulnerability
BID:11267
Info
Vignette Application Portal Remote Information Disclosure Vulnerability
| Bugtraq ID: | 11267 |
| Class: | Design Error |
| CVE: |
CVE-2004-0917 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 28 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | Discovery of this issue is credited to Cory Scott <[email protected]> of @stake, Inc. |
| Vulnerable: |
Vignette Application Portal |
| Not Vulnerable: | |
Discussion
Vignette Application Portal Remote Information Disclosure Vulnerability
Vignette Application Portal is affected by a remote information disclosure vulnerability. This issue is due to a design error that facilitates unauthorized access to sensitive information.
An attacker can leverage this issue to reveal sensitive information such as operating system version, application version, database connection parameters, and various other application portal related setting details.
Vignette Application Portal is affected by a remote information disclosure vulnerability. This issue is due to a design error that facilitates unauthorized access to sensitive information.
An attacker can leverage this issue to reveal sensitive information such as operating system version, application version, database connection parameters, and various other application portal related setting details.
Exploit / POC
Vignette Application Portal Remote Information Disclosure Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Vignette Application Portal Remote Information Disclosure Vulnerability
Solution:
The vendor has made a knowledge base article (KB 6947) available with remediation advice. This article has been made available to registered customers only. Please contact the vendor for information on obtaining the article.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor has made a knowledge base article (KB 6947) available with remediation advice. This article has been made available to registered customers only. Please contact the vendor for information on obtaining the article.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Vignette Application Portal Remote Information Disclosure Vulnerability
References:
References:
- Vignette Application Portal Homepage (VIGNETTE)
- Vignette Homepage (VIGNETTE)