PT-2004-3637 · Netiq · Netiq Webtrends Reporting Center Enterprise Edition

Oliver Karow

·

Publicado

2004-12-31

·

Atualizado

2018-10-19

·

CVE-2004-2748

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions NetIQ WebTrends Reporting Center Enterprise Edition version 6.1a
Description The issue allows remote attackers to determine the installation path of the software. This is achieved by providing an invalid profileid parameter, which results in an error message that leaks the pathname.
Recommendations For version 6.1a, avoid using the profileid parameter in the viewreport.pl script until a fix is available. As a temporary workaround, consider restricting access to the viewreport.pl script to minimize the risk of exploitation.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2004-2748

Produtos afetados

Netiq Webtrends Reporting Center Enterprise Edition