CVE-2004-0374
N/A
N/A
Summary
Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensitive SQL information via an HTTP request ending with the "SQLUSER" string.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.icdevgroup.org/pipermail/interchange-announce/2004/000043.html
- http://www.securityfocus.com/bid/10005
- http://ftp.icdevgroup.org/interchange/5.0/WHATSNEW
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15670
- http://secunia.com/advisories/11234
- http://www.debian.org/security/2004/dsa-471
References
- http://www.icdevgroup.org/pipermail/interchange-announce/2004/000043.html
- http://www.securityfocus.com/bid/10005
- http://ftp.icdevgroup.org/interchange/5.0/WHATSNEW
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15670
- http://secunia.com/advisories/11234
- http://www.debian.org/security/2004/dsa-471
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.