CVE-2003-0400

Vignette StoryServer & V/5 - Memory Corruption

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2003-0400. PoCs published by S21Sec, @stake.

AI-analyzed exploit summary The exploit describes an information leakage vulnerability in Vignette StoryServer due to improper handling of URI variables, potentially exposing memory contents. The provided URL demonstrates the issue but lacks executable code.

Description

Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of memory, as demonstrated using the "-->" string in a CookieName argument to the login template, referred to as a "memory leak" in some reports.

Exploits (2)

exploitdb WRITEUP VERIFIED
by S21Sec · textremoteunix
https://www.exploit-db.com/exploits/22646

The exploit describes an information leakage vulnerability in Vignette StoryServer due to improper handling of URI variables, potentially exposing memory contents. The provided URL demonstrates the issue but lacks executable code.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: Vignette StoryServer (version unspecified)
No auth needed
Prerequisites: Access to a vulnerable Vignette StoryServer instance
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by @stake · textremotemultiple
https://www.exploit-db.com/exploits/22472

This writeup describes an information leakage vulnerability in Vignette StoryServer where a crafted request triggers an error state, exposing stack memory content. The attack involves a malformed URL parameter to provoke an error message containing sensitive data.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Vignette StoryServer
No auth needed
Prerequisites: Access to the target Vignette StoryServer instance
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Vendor Advisory x_refsource_misc
http://www.s21sec.com/es/avisos/s21sec-018-en.txt
Patch, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/12075.php
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/7684
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105405985126857&w=2

Scores

EPSS 0.0350
EPSS Percentile 88.0%

Details

Status published
Products (6)
vignette/content_suite 6.0
vignette/storyserver 4.0
vignette/storyserver 4.1
vignette/storyserver 4.2
vignette/storyserver 5.0
vignette/vignette 5.0
Published Jun 30, 2003
Tracked Since Feb 18, 2026