|
Family: CGI abuses --> Category: attack
Webmin / Usermin Null Filtering Vulnerabilities Vulnerability Scan
Vulnerability Scan Summary Checks if nulls in a URL are filtered by miniserv.pl
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server is affected by multiple issues.
Description :
The remote host is running Webmin or Usermin, web-based interfaces for
Unix / Linux system administrators and end-users.
Webmin and Usermin both come with the Perl script 'miniserv.pl' to
provide basic web services, and the version of 'miniserv.pl' installed
on the remote host fails to properly filter null characters from URLs.
A possible hacker may be able to exploit this to reveal the source code of CGI
scripts, obtain directory listings, or launch cross-site scripting
attacks against the affected application.
See also :
http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/89_e.html
http://www.webmin.com/security.html
Solution :
Upgrade to Webmin version 1.296 / Usermin 1.226 or later.
Threat Level:
High / CVSS Base Score : 7.0
(AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|