Atstake Security Advisory 03-04-07.1...

- AV AC AU C I A
发布: 2003-04-10
修订: 2025-04-13

Atstake Security Advisory A040703-1 - Vignette Story Server has a vulnerability that allows for sensitive information disclosure. It allows the publication of both static and dynamic content. The dynamic pages are created using a TCL[1] Interpreter. There exists a vulnerability within the TCL interpreter used that allows 'dumping' of the stack of the current running TCL process when generating dynamic pages. This vulnerability results in an attacker being able to extract information about other users sessions, server side code and other sensitive information.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息