VID |
21806 |
Severity |
30 |
Port |
80, ... |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
A version of TUTOS which is older than version 1.1.20040412 is detected as installed on the host. TUTOS (The Ultimate Team Organization Software) is a freely available, open-source team organization software package written in PHP. TUTOS versions prior to 1.1.20040412 are vulnerable to multiple input validation vulnerabilities, which can be exploited by a remote, authenticated attacker to perform various attacks such as path disclosure, cross-site scripting, and possibly SQL injection.
* Note: This check solely relied on the version number of the TUTOS installed on the remote web server to assess this vulnerability, so this might be a false positive.
* References: http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0079.html
* Platforms Affected: gokohnert, TUTOS versions prior to 1.1.20040412 Any operating system Any version |
Recommendation |
Upgrade to the latest version of TUTOS (1.1.20040412 or later), available from the TUTOS Download Web site at http://www.tutos.org/homepage/download.html |
Related URL |
(CVE) |
Related URL |
10129 (SecurityFocus) |
Related URL |
15852,15854 (ISS) |
|