Nessus Plugin #14283

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

CVSTrac CVSROOT/passwd arbitrary account deletion

Family:
CGI abuses
Category:
infos
Copyright:
This script is Copyright (C) 2004 David Maciejak
Summary:
Checks for CVSTrac version
Version:
$Revision: 1.4 $
Cve_id:
-
Bugtraq_id:
-
Xrefs:
OSVDB:8642
Description:

The remote host seems to be running cvstrac,
a web-based bug and patch-set tracking system for CVS.

This version of CVSTRAC is vulnerable to a flaw wherein
a remote attacker can overwrite a critical file, thereby
giving them elevated access and potentially control
over other user accounts.

***** Nessus has determined the vulnerability exists on the target
***** simply by looking at the version number(s) of CVSTrac
***** installed there.


Solution : Update to version 1.1.4 or disable this CGI suite
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.