CVE-2004-0917

The default installation of Vignette Application Portal installs the diagnostic utility without authentication requirements, which allows remote attackers to gain sensitive information, such as server and OS version, and conduct unauthorized activities via an HTTP request to /diag.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vignette:application_portal:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:49

Type Values Removed Values Added
References () http://securitytracker.com/id?1011447 - () http://securitytracker.com/id?1011447 -
References () http://www.atstake.com/research/advisories/2004/a092804-1.txt - Exploit, Vendor Advisory () http://www.atstake.com/research/advisories/2004/a092804-1.txt - Exploit, Vendor Advisory
References () http://www.securityfocus.com/bid/11267 - Vendor Advisory () http://www.securityfocus.com/bid/11267 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/17530 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/17530 -

Information

Published : 2005-01-27 05:00

Updated : 2024-11-20 23:49


NVD link : CVE-2004-0917

Mitre link : CVE-2004-0917

CVE.ORG link : CVE-2004-0917


JSON object : View

Products Affected

vignette

  • application_portal