VulnerabilityModified
CVE-2003-0405
Vignette StoryServer 5 and Vignette V/6 allows remote attackers to execute arbitrary TCL code via (1) an HTTP query or cookie which is processed in the NEEDS command, or (2) an HTTP Referrer that is processed in the VALID_PATHS command.
MEDIUM 5.0EPSS 1.57%
Does this matter?
Lower severity and a low EPSS score (1.57%). Track it; it rarely justifies an emergency change on its own.
Description
Vignette StoryServer 5 and Vignette V/6 allows remote attackers to execute arbitrary TCL code via (1) an HTTP query or cookie which is processed in the NEEDS command, or (2) an HTTP Referrer that is processed in the VALID_PATHS command.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- vignette/content suite · vignette/storyserver · vignette/vignette
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=105405922826197&w=2
- http://www.iss.net/security_center/static/12070.phpVendor Advisory
- http://www.s21sec.com/es/avisos/s21sec-024-en.txtPatch, Vendor Advisory
- http://www.securityfocus.com/bid/7690Patch, Vendor Advisory
- http://www.securityfocus.com/bid/7692Patch, Vendor Advisory
- http://marc.info/?l=bugtraq&m=105405922826197&w=2
- http://www.iss.net/security_center/static/12070.phpVendor Advisory
- http://www.s21sec.com/es/avisos/s21sec-024-en.txtPatch, Vendor Advisory
- http://www.securityfocus.com/bid/7690Patch, Vendor Advisory
- http://www.securityfocus.com/bid/7692Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.