Vulnerability Details CVE-2003-0399
Vignette StoryServer 4 and 5, Vignette V/5, and possibly other versions allows remote attackers to perform unauthorized SELECT queries by setting the vgn_creds cookie to an arbitrary value and directly accessing the save template.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.8%
CVSS Severity
CVSS v2 Score 6.4
Products affected by CVE-2003-0399
-
cpe:2.3:a:vignette:content_suite:6.0
-
cpe:2.3:a:vignette:content_suite:7.0
-
cpe:2.3:a:vignette:storyserver:4.0
-
cpe:2.3:a:vignette:storyserver:4.1
-
cpe:2.3:a:vignette:storyserver:5.0
-
cpe:2.3:a:vignette:vignette:5.0