| VID |
21064 |
| Severity |
40 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The "nph-publish.cgi" is installed. A vulnerability in the nph-publish script version 1.0 through 1.1 could allow remote attackers to write to files that would normally not be accessible. Under certain circumstances, this hole could be used to gain access to the vulnerable machine. |
| Recommendation |
Remove the vulnerable version of nph-publish from your CGI-BIN directory and upgrade to at least version 1.2, which fixes this problem. |
| Related URL |
CVE-1999-1177 (CVE) |
| Related URL |
(SecurityFocus) |
| Related URL |
2055 (ISS) |
|