Vignette Unauthorized Legacy Tool Access Vulnerability
BID:7683
Info
Vignette Unauthorized Legacy Tool Access Vulnerability
| Bugtraq ID: | 7683 |
| Class: | Access Validation Error |
| CVE: |
CVE-2003-0399 |
| Remote: | Yes |
| Local: | No |
| Published: | May 26 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery of this issue is credited to S21SEC <[email protected]>. |
| Vulnerable: |
Vignette Vignette V/5 Vignette V6 Content Suite Vignette StoryServer 5.0 Vignette StoryServer 4.1 Vignette StoryServer 4.0 Vignette Content Suite V7 |
| Not Vulnerable: | |
Discussion
Vignette Unauthorized Legacy Tool Access Vulnerability
Vignette does not sufficiently restrict access to the Legacy Tool application. Unauthorized remote users may use this tool to execute database queries.
** The vendor has stated that the "Legacy records save" template is a sample template that cannot be launched to a live CDS unless explicitly specified.
Vignette does not sufficiently restrict access to the Legacy Tool application. Unauthorized remote users may use this tool to execute database queries.
** The vendor has stated that the "Legacy records save" template is a sample template that cannot be launched to a live CDS unless explicitly specified.
Exploit / POC
Vignette Unauthorized Legacy Tool Access Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Vignette Unauthorized Legacy Tool Access Vulnerability
Solution:
The vendor has posted a response to this issue at the following location:
http://support.vignette.com/VOLSS/KB/View/1,,5557,00.html
It should be noted that only existing Vignette customers and partners are able to access the above link.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor has posted a response to this issue at the following location:
http://support.vignette.com/VOLSS/KB/View/1,,5557,00.html
It should be noted that only existing Vignette customers and partners are able to access the above link.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Vignette Unauthorized Legacy Tool Access Vulnerability
References:
References:
- Vignette Homepage (VIGNETTE)
- Vignette Response to S21SEC Security Advisories [05/29/03] (VIGNETTE)
- S21SEC-017 - Vignette /vgn/legacy/save SQL access (S21SEC
)