peter bassill · operator
$ cve CVE-2004-2748 JSON

CVE-2004-2748 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 4.8% (pctl 92)

Patch early

A public exploit exists.

Description

viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid profileid parameter, which leaks the pathname in an error message.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS4.81% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
webtrendsreporting center

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD