5
CVSSv2

CVE-2007-6198

Published: 01/12/2007 Updated: 15/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

portal/server.pt in the Plumtree portal in BEA AquaLogic Interaction 5.0.2 up to and including 5.0.4 and 6.0.1.218452 allows wildcards in advanced searches for usernames, which allows remote malicious users to enumerate valid usernames via the in_tx_fulltext parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

bea aqualogic interaction 5.0.4

bea aqualogic interaction 6.0.1.218452

bea aqualogic interaction 5.0.2

bea aqualogic interaction 5.0.3

Exploits

source: wwwsecurityfocuscom/bid/26620/info BEA AquaLogic Interaction is prone to multiple information-disclosure vulnerabilities Attackers can exploit these issues to access valid usernames in the Plumtree portal as well as the server hostname, build date, and server version Information harvested can aid in further attacks The follow ...