The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal hostnames by reading comments in the HTML source of any page.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:39
Type | Values Removed | Values Added |
---|---|---|
References | () http://procheckup.com/Vulnerability_PR06-08.php - Exploit | |
References | () http://procheckup.com/Vulnerability_PR06-09.php - Exploit | |
References | () http://secunia.com/advisories/27840 - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/484467/100/0/threaded - | |
References | () http://www.securitytracker.com/id?1019005 - | |
References | () http://www.vupen.com/english/advisories/2007/4040 - |
Information
Published : 2007-12-01 06:46
Updated : 2024-11-21 00:39
NVD link : CVE-2007-6197
Mitre link : CVE-2007-6197
CVE.ORG link : CVE-2007-6197
JSON object : View
Products Affected
bea
- aqualogic_interaction
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor