5

CVE-2007-6198

Exploit

portal/server.pt in the Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows wildcards in advanced searches for usernames, which allows remote attackers to enumerate valid usernames via the in_tx_fulltext parameter.

Data is provided by the National Vulnerability Database (NVD)
BeaAqualogic Interaction Version5.0.2
BeaAqualogic Interaction Version5.0.3
BeaAqualogic Interaction Version5.0.4
BeaAqualogic Interaction Version6.0.1.218452
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.92% 0.902
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N