Korean
<< Back
VID 21064
Severity 40
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The "nph-publish.cgi" is installed.
A vulnerability in the nph-publish script version 1.0 through 1.1 could allow remote attackers to write to files that would normally not be accessible. Under certain circumstances, this hole could be used to gain access to the vulnerable machine.
Recommendation Remove the vulnerable version of nph-publish from your CGI-BIN directory and upgrade to at least version 1.2, which fixes this problem.
Related URL CVE-1999-1177 (CVE)
Related URL (SecurityFocus)
Related URL 2055 (ISS)