VID |
21807 |
Severity |
30 |
Port |
80, ... |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
A version of TUTOS which is older than version 1.2 is detected as installed on the host. TUTOS (The Ultimate Team Organization Software) is a freely available, open-source team organization software package written in PHP. TUTOS versions prior to 1.2 are vulnerable to multiple input validation vulnerabilities, which can be exploited by a remote, authenticated attacker to perform various attacks such as cross-site scripting, and possibly SQL injection.
* Note: This check solely relied on the version number of the TUTOS installed on the remote web server to assess this vulnerability, so this might be a false positive.
* References: http://secunia.com/advisories/12606/
* Platforms Affected: gokohnert, TUTOS version 1.1 and earlier versions Any operating system Any version |
Recommendation |
Upgrade to the latest version of TUTOS (1.2 or later), available from the TUTOS Download Web site at http://www.tutos.org/homepage/download.html |
Related URL |
CVE-2004-2161,CVE-2004-2162 (CVE) |
Related URL |
8011,8012,11221 (SecurityFocus) |
Related URL |
17444,17445 (ISS) |
|