CVE-2004-0917

The default installation of Vignette Application Portal installs the diagnostic utility without authentication requirements, which allows remote attackers to gain sensitive information, such as server and OS version, and conduct unauthorized activities via an HTTP request to /diag.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vignette:application_portal:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2005-01-27 05:00

Updated : 2024-02-28 10:42


NVD link : CVE-2004-0917

Mitre link : CVE-2004-0917

CVE.ORG link : CVE-2004-0917


JSON object : View

Products Affected

vignette

  • application_portal