|
|
|
|
|
|
|
| |
CDomain whois_raw.cgi fqdn Parameter Arbitrary Command Execution |
|
| This script is Copyright (C) 1999-2010 Tenable Network Security, Inc. |
|
|
| Family | CGI abuses |
| Nessus Plugin ID | 10306 (whois_raw.nasl) |
| Bugtraq ID | 304
|
| CVE ID | CVE-1999-1063
|
|
| Description: |
Synopsis :
The remote web server contains a CGI script that is prone to arbitrary
command execution attacks.
Description :
The remote host appears to be using the CdomainFree 'whois_raw.cgi'
script.
This CGI script allows an attacker to view any file on the target
computer, as well as to execute arbitrary commands.
See also :
http://www.nessus.org/u?9160cb71
Solution :
Upgrade to CdomainFree 2.5 or to one of the commercial versions.
Risk factor :
High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
|
|
|
|
|
|