|
|
|
|
|
|
|
| |
WebGais websendmail CGI Arbitrary Command Execution |
|
| This script is Copyright (C) 1999-2010 Tenable Network Security, Inc. |
|
|
| Family | CGI abuses |
| Nessus Plugin ID | 10301 (websendmail.nasl) |
| Bugtraq ID | 2077
|
| CVE ID | CVE-1999-0196
|
|
| Description: |
Synopsis :
The remote web server contains a CGI script that may suffer from an
arbitrary command execution flaw.
Description :
The 'websendmail' program, part of Webgais, appears to be installed on
the remote host. This CGI script has a well-known security flaw that
lets an attacker execute arbitrary commands with the privileges of the
http daemon (usually root or nobody).
See also :
http://archives.neohapsis.com/archives/bugtraq/1997_3/0018.html
Solution :
Remove the 'websendmail' program.
Risk factor :
High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
|
|
|
|
|
|