Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:INFO-LEAK:VIGNETTE-LEAK

Severity

Medium

Recommended

No

Category

HTTP

Keywords

Vignette Story Server Sensitive Information Disclosure

Release Date

2003/06/18

Update Number

1213

Supported Platforms

di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Vignette Story Server Sensitive Information Disclosure


This signature detects attempts to exploit a known vulnerability in Vignette Story Server. Vignette Story Server versions 4.1 and 6 are vulnerable. Attackers can expose information about user sessions, server side code, and other sensitive information.

Extended Description

It has been reported that Vignette StoryServer, under some circumstances may reveal stack memory content. If a specially crafted request is made for a page that accepts user-supplied data an error state may be triggered. If the attack is successful a dump of the current stack contents will be returned to the attackers browser within an error message. The information gathered in this way may be used to mount further attacks against the system.

Affected Products

  • Vignette StoryServer 4.1.0
  • Vignette V/5

References

  • BugTraq: 7296
  • CVE: CVE-2002-0385
  • URL: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2002-0385
  • URL: http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=8297

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out