CVE-2004-2748 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 4.8% (pctl 92)
Patch early
A public exploit exists.
Description
viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid profileid parameter, which leaks the pathname in an error message.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
| EPSS | 4.81% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| webtrends | reporting center |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WebTrends Reporting Center 6.1 Management Interface - Full Path Disclosure | 2004-01-20 |
References
- http://secunia.com/advisories/10689
- http://securityreason.com/securityalert/3354
- http://www.osvdb.org/3680
- http://www.securityfocus.com/archive/1/350419/30/21610/threaded
- http://www.securityfocus.com/bid/9460
- http://www.securitytracker.com/id?1008799
- http://secunia.com/advisories/10689
- http://securityreason.com/securityalert/3354
- http://www.osvdb.org/3680
- http://www.securityfocus.com/archive/1/350419/30/21610/threaded
- http://www.securityfocus.com/bid/9460
- http://www.securitytracker.com/id?1008799
→ the Explorer · watch your stack · NVD