CVE-2004-2563

Serena TeamTrack 6.1.1 - Info Disclosure & XSS

Title source: llm
STIX 2.1

Description

Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and database information, and conduct cross-site scripting (XSS) attacks, via a direct request to tmtrack.dll with modified LoginPage and Template parameters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Noam Rathaus · perlremotewindows
https://www.exploit-db.com/exploits/24297

Scores

EPSS 0.0107
EPSS Percentile 77.8%

Details

Status published
Products (1)
serena_software/serena_teamtrack 6.1.1
Published Dec 31, 2004
Tracked Since Feb 18, 2026