|
|
|
|
|
|
|
| |
WebGais webgais CGI Arbitrary Command Execution |
|
| This script is Copyright (C) 1999-2010 Tenable Network Security, Inc. |
|
|
| Family | CGI abuses |
| Nessus Plugin ID | 10300 (webgais.nasl) |
| Bugtraq ID | 2058
|
| CVE ID | CVE-1999-0176
|
|
| Description: |
Synopsis :
The remote web server contains a CGI script that is prone to arbitrary
code execution.
Description :
The 'webgais' CGI is installed. This CGI may let an attacker execute
arbitrary commands with the privileges of the http daemon (usually root
or nobody).
See also :
http://archives.neohapsis.com/archives/bugtraq/1997_3/0057.html
Solution :
Remove this CGI.
Risk factor :
High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
|
|
|
|
|
|