VID |
21714 |
Severity |
40 |
Port |
80, ... |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
A version of phpMyFAQ software which is older than 1.5.2 is detected as installed on the host. phpMyFAQ is a freely available FAQ-system that uses a MySQL database for Microsoft Windows operating systems. phpMyFAQ versions prior to 1.5.2 are vulnerable to multiple vulnerabilities, which can be exploited by a remote attacker to conduct information disclosure, arbitrary code execution, SQL injection and cross-site scripting attacks.
* Note: This check solely relied on the version number of the phpMyFaq installed on the remote Web server to assess this vulnerability, so this might be a false positive.
* References: http://rgod.altervista.org/phpmyfuck151.html
* Platforms Affected: Thorsten Rinne, PhpMyFAQ versions prior to 1.5.2 Microsoft Windows Any version |
Recommendation |
Upgrade to the latest version of phpMyFaq (1.5.2 or later), available from the phpMyFaq Download Web page at http://www.phpmyfaq.de/download.php |
Related URL |
CVE-2005-3046,CVE-2005-3047,CVE-2005-3048,CVE-2005-3049,CVE-2005-3050 (CVE) |
Related URL |
14927,14928,14929,14930 (SecurityFocus) |
Related URL |
(ISS) |
|