Vignette Style Template Information Leakage Vulnerability
BID:7688
Info
Vignette Style Template Information Leakage Vulnerability
| Bugtraq ID: | 7688 |
| Class: | Configuration Error |
| CVE: |
CVE-2003-0401 |
| Remote: | Yes |
| Local: | No |
| Published: | May 26 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery credited to S21SEC <[email protected]>. |
| Vulnerable: |
Vignette Vignette V/5 Vignette V6 Content Suite Vignette StoryServer 5.0 Vignette StoryServer 4.1 Vignette StoryServer 4.0 Vignette Content Suite V7 Vignette Content Suite V5 |
| Not Vulnerable: | |
Discussion
Vignette Style Template Information Leakage Vulnerability
It has been reported that some Vignette products install several templates, including the style template, in the /vgn directory. Because of this, it may be possible for a remote attacker to gain access to potentially sensitive information.
** The vendor has stated that on a live CDS, the affected template will not dump any information. Rather, the template will return a HTTP error 404 or show a blank page.
It has been reported that some Vignette products install several templates, including the style template, in the /vgn directory. Because of this, it may be possible for a remote attacker to gain access to potentially sensitive information.
** The vendor has stated that on a live CDS, the affected template will not dump any information. Rather, the template will return a HTTP error 404 or show a blank page.
Exploit / POC
Vignette Style Template Information Leakage Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
Vignette Style Template Information Leakage Vulnerability
Solution:
The vendor has posted a response to this issue at the following location:
http://support.vignette.com/VOLSS/KB/View/1,,5557,00.html
It should be noted that only existing Vignette customers and partners are able to access the above link.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor has posted a response to this issue at the following location:
http://support.vignette.com/VOLSS/KB/View/1,,5557,00.html
It should be noted that only existing Vignette customers and partners are able to access the above link.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Vignette Style Template Information Leakage Vulnerability
References:
References:
- Vignette Homepage (VIGNETTE)
- S21SEC-019 - Vignette /vgn/style internal information leak (S21SEC
)