« Volver al listado

CVE-2003-0402

Estado: ModificadaMedia (5)—

The default login template (/vgn/login) in Vignette StoryServer 5 and Vignette V/5 generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2003-0402",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2003-06-30T04:00:00.000",
  "references": [
    {
      "url": "http://marc.info/?l=bugtraq&m=105405880325755&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.iss.net/security_center/static/12073.php",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.s21sec.com/en/avisos/s21sec-020-en.txt",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/7691",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=105405880325755&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.iss.net/security_center/static/12073.php",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.s21sec.com/en/avisos/s21sec-020-en.txt",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/7691",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The default login template (/vgn/login) in Vignette StoryServer 5 and Vignette V/5 generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks."
    },
    {
      "lang": "es",
      "value": "La plantilla de inicio de sesíón por defecto (/vgn/login) en Vignette StoryServer 5 y Vignette V/5 genera diferentes respuestas si un usuario existe o no, lo que permite a atacantes remotos identificar nombres de usuario válidos mediante ataques de fuerza bruta."
    }
  ],
  "lastModified": "2026-06-16T22:02:08.243",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vignette:content_suite:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "240B7293-825A-4224-B767-D79FF7D90AA1"
            },
            {
              "criteria": "cpe:2.3:a:vignette:content_suite:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "460D6CDD-85AF-4E27-ABFB-3BF603B0EDCD"
            },
            {
              "criteria": "cpe:2.3:a:vignette:content_suite:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F28F678-7536-484A-A970-068392362B55"
            },
            {
              "criteria": "cpe:2.3:a:vignette:storyserver:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "331AD9B5-7E79-45CA-AFE1-84B1545FE74A"
            },
            {
              "criteria": "cpe:2.3:a:vignette:storyserver:4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A69859D5-F4AF-4239-ADB2-5AB3F6A3F25F"
            },
            {
              "criteria": "cpe:2.3:a:vignette:storyserver:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1113CE36-9F16-443E-B4B6-C9EA21DEF362"
            },
            {
              "criteria": "cpe:2.3:a:vignette:vignette:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D1E15D6-2CA5-419C-80AD-9E8FE6A054C3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}