|
|
|
|
|
|
|
| |
WebSpeed Messenger Administration Utility Unauthenticed Access |
|
| This script is Copyright (C) 2000-2010 Tenable Network Security, Inc. |
|
|
| Family | CGI abuses |
| Nessus Plugin ID | 10304 (webspeed.nasl) |
| Bugtraq ID | 969
|
| CVE ID | CVE-2000-0127
|
|
| Description: |
Synopsis :
The remote web server contains an application that is prone to privilege
escalation attacks.
Description :
The remote web server appears to be using Webspeed, a website creation
language used with database-driven websites.
The version of Webspeed installed on the remote host allows anonymous
access to the 'WSMadmin' utility, which is used configure Webspeed. An
attacker can exploit this issue to gain control of the affected
application.
See also :
http://archives.neohapsis.com/archives/bugtraq/2000-02/0013.html
Solution :
Edit the 'ubroker.properties' file and change 'AllowMsngrCmds=1' to
'AllowMsngrCmds=0'.
Risk factor :
High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
|
|
|
|
|
|