VulnerabilityModified
CVE-2004-2748
viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid profileid parameter, which leaks the pathname in an error message.
MEDIUM 4.3EPSS 4.81%
Does this matter?
Lower severity and a low EPSS score (4.81%). Track it; it rarely justifies an emergency change on its own.
Description
viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid profileid parameter, which leaks the pathname in an error message.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 4.81% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- webtrends/reporting center
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/10689Vendor Advisory
- http://securityreason.com/securityalert/3354
- http://www.osvdb.org/3680
- http://www.securityfocus.com/archive/1/350419/30/21610/threaded
- http://www.securityfocus.com/bid/9460
- http://www.securitytracker.com/id?1008799
- http://secunia.com/advisories/10689Vendor Advisory
- http://securityreason.com/securityalert/3354
- http://www.osvdb.org/3680
- http://www.securityfocus.com/archive/1/350419/30/21610/threaded
- http://www.securityfocus.com/bid/9460
- http://www.securitytracker.com/id?1008799
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.