|
|
|
|
|
|
|
| |
WWWBoard passwd.txt Authentication Credential Disclosure |
|
| This script is Copyright (C) 1999-2010 Jonathan Provencher |
|
|
| Family | CGI abuses |
| Nessus Plugin ID | 10321 (wwwboardpwd.nasl) |
| Bugtraq ID | 649 12453
|
| CVE ID | CVE-1999-0953
|
|
| Description: |
Synopsis :
The remote web server contains a CGI application that is prone to an
information disclosure attack.
Description :
The remote host is running WWWBoard, a bulletin board system written
by Matt Wright.
This board system comes with a password file (passwd.txt) installed
next to the file 'wwwboard.html'. An attacker may obtain the contents
of this file and decode the password to modify the remote www board.
See also :
http://archives.neohapsis.com/archives/bugtraq/1998_3/0746.html
http://archives.neohapsis.com/archives/bugtraq/1999-q3/0993.html
Solution :
Configure the wwwadmin.pl script to change the name and location of
'passwd.txt'.
Risk factor :
Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
|
|
|
|
|
|