|
|
|
|
|
|
|
| |
OmniHTTPd visadmin.exe Malformed URL DoS |
|
| This script is Copyright (C) 1999-2010 Tenable Network Security, Inc. |
|
|
| Family | CGI abuses |
| Nessus Plugin ID | 10295 (visadmin.nasl) |
| Bugtraq ID | 1808
|
| CVE ID | CVE-1999-0970
|
|
| Description: |
Synopsis :
The remote host has an application that is affected by a
denial of service vulnerability.
Description :
It is possible to fill the hard disk of a server running
OmniHTTPd by issuing the request :
http://omni.server/cgi-bin/visadmin.exe?user=guest
This allows an attacker to crash your web server. This
script checks for the presence of the faulty CGI, but
does not execute it.
Solution :
Remove visadmin.exe from /cgi-bin.
Risk factor :
Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
|
|
|
|
|
|