Korean
<< Back
VID 21807
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description A version of TUTOS which is older than version 1.2 is detected as installed on the host. TUTOS (The Ultimate Team Organization Software) is a freely available, open-source team organization software package written in PHP. TUTOS versions prior to 1.2 are vulnerable to multiple input validation vulnerabilities, which can be exploited by a remote, authenticated attacker to perform various attacks such as cross-site scripting, and possibly SQL injection.

* Note: This check solely relied on the version number of the TUTOS installed on the remote web server to assess this vulnerability, so this might be a false positive.

* References:
http://secunia.com/advisories/12606/

* Platforms Affected:
gokohnert, TUTOS version 1.1 and earlier versions
Any operating system Any version
Recommendation Upgrade to the latest version of TUTOS (1.2 or later), available from the TUTOS Download Web site at http://www.tutos.org/homepage/download.html
Related URL CVE-2004-2161,CVE-2004-2162 (CVE)
Related URL 8011,8012,11221 (SecurityFocus)
Related URL 17444,17445 (ISS)