|
|
|
|
|
|
|
| |
Windmail.exe Shell Metacharacter Arbitrary Command Execution |
|
| This script is Copyright (C) 2000-2010 Tenable Network Security, Inc. |
|
|
| Family | CGI abuses |
| Nessus Plugin ID | 10365 (windmail.nasl) |
| Bugtraq ID | 1073
|
| CVE ID | CVE-2000-0242
|
|
| Description: |
Synopsis :
The remote web server contains a CGI script that is prone to arbitrary
command execution.
Description :
The remote host may be running WindMail as a CGI application. In this
mode, some versions of the 'windmail.exe' script allow an attacker to
execute arbitrary commands on the remote server.
See also :
http://seclists.org/lists/bugtraq/2000/Mar/0322.html
Solution :
Remove the CGI script.
Risk factor :
High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
|
|
|
|
|
|