PT-2004-3637 · Netiq · Netiq Webtrends Reporting Center Enterprise Edition
Oliver Karow
·
Publicado
2004-12-31
·
Atualizado
2018-10-19
·
CVE-2004-2748
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NetIQ WebTrends Reporting Center Enterprise Edition version 6.1a
Description
The issue allows remote attackers to determine the installation path of the software. This is achieved by providing an invalid
profileid parameter, which results in an error message that leaks the pathname.Recommendations
For version 6.1a, avoid using the
profileid parameter in the viewreport.pl script until a fix is available. As a temporary workaround, consider restricting access to the viewreport.pl script to minimize the risk of exploitation.Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Netiq Webtrends Reporting Center Enterprise Edition