VYPR
Unrated severityNVD Advisory· Published Jun 30, 2003· Updated Apr 16, 2026

CVE-2003-0405

CVE-2003-0405

Description

Vignette StoryServer 5 and Vignette V/6 allows remote attackers to execute arbitrary TCL code via (1) an HTTP query or cookie which is processed in the NEEDS command, or (2) an HTTP Referrer that is processed in the VALID_PATHS command.

Affected products

7
  • cpe:2.3:a:vignette:content_suite:5.0:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:vignette:content_suite:5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:vignette:content_suite:6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:vignette:content_suite:6.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:vignette:content_suite:6.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:vignette:content_suite:6.0.3:*:*:*:*:*:*:*
  • cpe:2.3:a:vignette:storyserver:5.0:*:*:*:*:*:*:*
  • cpe:2.3:a:vignette:vignette:5.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.