{ "id": "CVE-2002-0385", "sourceIdentifier": "cve@mitre.org", "published": "2004-06-01T04:00:00.000", "lastModified": "2017-07-11T01:29:11.993", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Vignette Story Server 4.1 and 6.0 allows remote attackers to obtain sensitive information via a request that contains a large number of '\"' (double quote) and and '>' characters, which causes the TCL interpreter to crash and include stack data in the output." }, { "lang": "es", "value": "Vignette Story Server 4.1 and 6.0 permite a atacantes remotos obtener informaci\u00f3n sensible mediante una petici\u00f3n conteniendo un n\u00famero grande de caract\u00e9res \"comillas dobles\" y s\u00edmbolos \"mayor que\", lo que hace que el int\u00e9rprete se caiga y muestre datos de la pila en la salida." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 5.0 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:vignette:storyserver:4.1:*:*:*:*:*:*:*", "matchCriteriaId": "A69859D5-F4AF-4239-ADB2-5AB3F6A3F25F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:vignette:storyserver:6.0:*:*:*:*:*:*:*", "matchCriteriaId": "EC0BDA9F-F594-43E3-8514-A5D5FA6CBF41" }, { "vulnerable": true, "criteria": "cpe:2.3:a:vignette:vignette:5.0:*:*:*:*:*:*:*", "matchCriteriaId": "8D1E15D6-2CA5-419C-80AD-9E8FE6A054C3" } ] } ] } ], "references": [ { "url": "http://www.atstake.com/research/advisories/2003/a040703-1.txt", "source": "cve@mitre.org", "tags": [ "Patch", "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/bid/7296", "source": "cve@mitre.org", "tags": [ "Exploit", "Patch", "Vendor Advisory" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/11725", "source": "cve@mitre.org" } ] }