Unrated severityNVD Advisory· Published Jun 30, 2003· Updated Apr 16, 2026
CVE-2003-0402
CVE-2003-0402
Description
The default login template (/vgn/login) in Vignette StoryServer 5 and Vignette V/5 generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks.
Affected products
7cpe:2.3:a:vignette:content_suite:5.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:vignette:content_suite:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:vignette:content_suite:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:vignette:content_suite:7.0:*:*:*:*:*:*:*
cpe:2.3:a:vignette:storyserver:4.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:vignette:storyserver:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:vignette:storyserver:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:vignette:storyserver:5.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.s21sec.com/en/avisos/s21sec-020-en.txtnvdPatchVendor Advisory
- www.iss.net/security_center/static/12073.phpnvdVendor Advisory
- www.securityfocus.com/bid/7691nvdVendor Advisory
- marc.infonvd
News mentions
0No linked articles in our index yet.