CVE-2004-1893: Medium severity Macromedia Dreamweaver Ultradev vulnerability
Dreamweaver MX, when "Using Driver On Testing Server" or "Using DSN on Testing Server" is selected, uploads the mmhttpdb.asp script to the web site but does not require authentication, which allows remote attackers to obtain sensitive information and possibly execute arbitrary SQL commands via a direct request to mmhttpdb.asp.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1893?
CVE-2004-1893 has a high severity rating due to potential exposure of sensitive information and execution of arbitrary SQL commands.
How do I fix CVE-2004-1893?
To fix CVE-2004-1893, ensure that the mmhttpdb.asp script is not uploaded to the web server or implement proper authentication measures.
What systems are affected by CVE-2004-1893?
CVE-2004-1893 affects Macromedia Dreamweaver UltraDev 4.0 and multiple versions of Macromedia Dreamweaver including 6.0 and 2004.
Can CVE-2004-1893 lead to SQL injection attacks?
Yes, CVE-2004-1893 can enable remote attackers to perform SQL injection attacks due to lack of authentication.
Is there a patch available for CVE-2004-1893?
There is no official patch for CVE-2004-1893, and users are advised to upgrade to the latest version of the affected software.