Vignette VALID_PATHS Command TCL Code Injection Vulnerability
BID:7692
Info
Vignette VALID_PATHS Command TCL Code Injection Vulnerability
| Bugtraq ID: | 7692 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0405 |
| Remote: | Yes |
| Local: | No |
| Published: | May 26 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery of this vulnerability has been credited to Ramon Pinuaga Cascales <[email protected]>. |
| Vulnerable: |
Vignette Vignette V/5 Vignette V6 Content Suite 6.0.3 Vignette V6 Content Suite 6.0.2 Vignette V6 Content Suite 6.0.1 Vignette V6 Content Suite Vignette StoryServer 5.0 Vignette StoryServer 4.1 Vignette StoryServer 4.0 Vignette Content Suite V7 Vignette Content Suite V5 |
| Not Vulnerable: |
Vignette V6 Content Suite 6.0.4 |
Solution / Fix
Vignette VALID_PATHS Command TCL Code Injection Vulnerability
Solution:
This vulnerability does not affect Vignette Platform releases 6.0.4 and later. The vendor has stated that there are EFIXes available for vulnerable versions of the Vignette CMS. Affected users are advised to open a VOLSS ticket for further details or to request an EFIX.
Solution:
This vulnerability does not affect Vignette Platform releases 6.0.4 and later. The vendor has stated that there are EFIXes available for vulnerable versions of the Vignette CMS. Affected users are advised to open a VOLSS ticket for further details or to request an EFIX.