PT-2004-3637 · Netiq · Netiq Webtrends Reporting Center Enterprise Edition
Oliver Karow
·
Published
2004-12-31
·
Updated
2018-10-19
·
CVE-2004-2748
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NetIQ WebTrends Reporting Center Enterprise Edition version 6.1a
Description
The issue allows remote attackers to determine the installation path of the software. This is achieved by providing an invalid
profileid parameter, which results in an error message that leaks the pathname.Recommendations
For version 6.1a, avoid using the
profileid parameter in the viewreport.pl script until a fix is available. As a temporary workaround, consider restricting access to the viewreport.pl script to minimize the risk of exploitation.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netiq Webtrends Reporting Center Enterprise Edition