CVE

Id
7232  
CVE No.
CVE-2003-0405  
Status
Candidate  
Description
Vignette StoryServer 5 and Vignette V/6 allows remote attackers to execute arbitrary TCL code via (1) an HTTP query or cookie which is processed in the NEEDS command, or (2) an HTTP Referrer that is processed in the VALID_PATHS command.  
Phase
Assigned (20030610)  
Votes
None (candidate not yet proposed)  
Comments