CVE-2004-2563
Last modified
CVE-2004-2563 is a vulnerability of currently unknown severity. Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and database information, and conduct cross-site scripting (XSS) attacks, via a direct request to tmtrack.dll with modified LoginPage and Template parameters.. EPSS estimates a 2.22% chance of exploitation in the next 30 days.
Description
Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and database information, and conduct cross-site scripting (XSS) attacks, via a direct request to tmtrack.dll with modified LoginPage and Template parameters.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Serena Software | Serena Teamtrack | 6.1.1 |
References
- http://secunia.com/advisories/12122Vendor Advisory
- http://www.osvdb.org/8182Exploit
- http://www.osvdb.org/8183Exploit
- http://www.osvdb.org/8185Exploit
- http://secunia.com/advisories/12122Vendor Advisory
- http://www.osvdb.org/8182Exploit
- http://www.osvdb.org/8183Exploit
- http://www.osvdb.org/8185Exploit
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-2563?
How severe is CVE-2004-2563?
How do I fix CVE-2004-2563?
Are you affected by CVE-2004-2563?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
