Unrated severityNVD Advisory· Published Jun 1, 2004· Updated Apr 16, 2026
CVE-2002-0385
CVE-2002-0385
Description
Vignette Story Server 4.1 and 6.0 allows remote attackers to obtain sensitive information via a request that contains a large number of '"' (double quote) and and '>' characters, which causes the TCL interpreter to crash and include stack data in the output.
Affected products
3cpe:2.3:a:vignette:storyserver:4.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:vignette:storyserver:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:vignette:storyserver:6.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.atstake.com/research/advisories/2003/a040703-1.txtnvdPatchVendor Advisory
- www.securityfocus.com/bid/7296nvdExploitPatchVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/11725nvd
News mentions
0No linked articles in our index yet.