Vignette Login Template User Information Leakage Vulnerability
BID:7691
Info
Vignette Login Template User Information Leakage Vulnerability
| Bugtraq ID: | 7691 |
| Class: | Design Error |
| CVE: |
CVE-2003-0402 |
| Remote: | Yes |
| Local: | No |
| Published: | May 26 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery credited to S21SEC <[email protected]>. |
| Vulnerable: |
Vignette Vignette V/5 Vignette V6 Content Suite Vignette StoryServer 5.0 Vignette StoryServer 4.1 Vignette StoryServer 4.0 Vignette Content Suite V7 Vignette Content Suite V5 |
| Not Vulnerable: | |
Discussion
Vignette Login Template User Information Leakage Vulnerability
It has been reported that some Vignette products install several templates, including the login template, in the /vgn directory. Because of this, it may be possible for a remote attacker to gain access to potentially sensitive information.
It has been reported that some Vignette products install several templates, including the login template, in the /vgn directory. Because of this, it may be possible for a remote attacker to gain access to potentially sensitive information.
Exploit / POC
Vignette Login Template User Information Leakage Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
Vignette Login Template User Information Leakage Vulnerability
Solution:
The vendor has posted a response to this issue at the following location:
http://support.vignette.com/VOLSS/KB/View/1,,5557,00.html
It should be noted that only existing Vignette customers and partners are able to access the above link.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor has posted a response to this issue at the following location:
http://support.vignette.com/VOLSS/KB/View/1,,5557,00.html
It should be noted that only existing Vignette customers and partners are able to access the above link.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.