Nessus Plugin #16227

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

Comersus BackOffice Lite Administrative Bypass

Family:
CGI abuses
Category:
attack
Copyright:
This script is Copyright (C) 2005 Noam Rathaus
Summary:
Checks for the presence of a BackOffice Lite Administrative Bypass
Version:
$Revision: 1.2 $
Cve_id:
-
Bugtraq_id:
12362
Xrefs:
-
Description:

Comersus ASP shopping cart is a set of ASP scripts creating an online
shoppingcart. It works on a database of your own choosing, default is
msaccess, and includes online administration tools.

By accessing the /comersus_backoffice_install10.asp file it is possible
to bypass the need to authenticate as an administrative user.

Solution: Delete the file '/comersus_backoffice_install10.asp' from the
server as it is not needed after the installation process has been
completed.

Risk factor: High
Generiert am 27.04.2005 um 18:49:54 Uhr.