Interchange before 5.0.1 allows remote attackers to "expose the content...
Vulnerability Description
Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensitive SQL information via an HTTP request ending with the "__SQLUSER__" string.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-0374
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.icdevgroup.org/pipermail/interchange-announce/2004/000043.html
- http://www.securityfocus.com/bid/10005
- http://ftp.icdevgroup.org/interchange/5.0/WHATSNEW
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15670
- http://secunia.com/advisories/11234
- http://www.debian.org/security/2004/dsa-471
More from interchange development group
View All →Affected Vendor
interchange development group
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.