Vignette StoryServer 4.1 - Sensitive Stack Memory Information Disclosure

Author: @stake
type: remote
platform: multiple
port: 
date_added: 2003-04-07  
date_updated: 2012-11-04  
verified: 1  
codes: CVE-2003-0400;OSVDB-4911  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 22472.txt  
source: https://www.securityfocus.com/bid/7296/info

It has been reported that Vignette StoryServer, under some circumstances may reveal stack memory content.

If a specially crafted request is made for a page that accepts user-supplied data an error state may be triggered. If the attack is successful a dump of the current stack contents will be returned to the attackers browser within an error message.

The information gathered in this way may be used to mount further attacks against the system.

https://www.example.com/securelogin/1,2345,A,00.html?Errmessage="x214>x214