Nessus Plugin #11074

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

OfficeScan configuration file disclosure

Family:
CGI abuses
Category:
infos
Copyright:
This script is Copyright (C) 2002 Michel Arboi
Summary:
Checks for the presence of /officescan/hotdownload/ofscan.ini
Version:
$Revision: 1.8 $
Cve_id:
-
Bugtraq_id:
3438
Xrefs:
-
Description:

Trend Micro OfficeScan Corporate Edition (Japanese version: Virus
Buster Corporate Edition) web-based management console let anybody
access /officescan/hotdownload without authentication.

Reading the configuration file /officescan/hotdownload/ofcscan.ini
will reveal information on your system. More, it contains passwords
that are encrypted by a weak specific algorithm
so they might be
decrypted

Solution : upgrade OfficeScan
Risk factor : Low
Generiert am 27.04.2005 um 18:49:54 Uhr.