vendor:
StoryServer
by:
Not specified
5.5
CVSS
MEDIUM
Stack memory content disclosure
200
CWE
Product Name: StoryServer
Affected Version From: Not specified
Affected Version To: Not specified
Patch Exists: NO
Related CWE: Not specified
CPE: Not specified
Platforms Tested: Not specified
Unknown
Vulnerability in Vignette StoryServer
Under certain circumstances, Vignette StoryServer may reveal stack memory content. A specially crafted request for a page that accepts user-supplied data can trigger an error state, which will result in a dump of the current stack contents being returned to the attacker's browser within an error message. This information can be used to mount further attacks against the system.
Mitigation:
It is recommended to apply patches or updates provided by the vendor to address this vulnerability. Additionally, input validation should be implemented to prevent the exploitation of user-supplied data.