Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6198 (AquaLogic Interaction)

BugsAlert Home > CVE-2007-6198 (AquaLogic Interaction)
 
 

portal/server.pt in the Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows wildcards in advanced searches for usernames, which allows remote attackers to enumerate valid usernames via the in_tx_fulltext parameter.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6198

Learn more about CVE-2007-6198 (AquaLogic Interaction)
 
Tags: cve-2007-6198 aqualogic interaction

Related Items

      mb_detect_encoding doesn´t detect

      Major blunder: virus mailed to Google Video blog subscribers

      CVE-2008-5424 (outlook_express)

      FrSIRT - IBM Tivoli Netcool/Webtop Multiple Security Bypass Vulnerabilities

      CVE-2008-1916 (Ubercart Module)

      Fedora update for postfix

      Vuln: New Earth Programming Team Image Upload Script Arbitrary File Upload Vulnerability

 

Pixel