4.3
CVSSv2

CVE-2004-2748

Published: 31/12/2004 Updated: 19/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote malicious users to determine the installation path via an invalid profileid parameter, which leaks the pathname in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

webtrends reporting center 6.1a

Exploits

source: wwwsecurityfocuscom/bid/9460/info The WebTrends Reporting Center management interface discloses installation path information when an invalid argument for an interface URI parameter is requested This information may permit an attacker to enumerate the layout of the underlying file system of the host This issue was reported for ...