|
|
|
|
|
|
|
| |
HylaFAX faxsurvey Arbitrary Command Execution |
|
| This script is Copyright (C) 1999-2010 Tenable Network Security, Inc. |
|
|
| Family | CGI abuses |
| Nessus Plugin ID | 10067 (faxsurvey.nasl) |
| Bugtraq ID | 2056
|
| CVE ID | CVE-1999-0262
|
|
| Description: |
Synopsis :
A web application on the remote host has an arbitrary command
execution vulnerability.
Description :
The 'faxsurvey' CGI does not sanitize input to the query string. A
remote attacker could exploit this to execute arbitrary commands.
See also :
http://archives.neohapsis.com/archives/bugtraq/1998_3/0385.html
Solution :
Remove this CGI from the server.
Risk factor :
High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
|
|
|
|
|
|