Korean
<< Back
VID 21846
Severity 40
Port 8080
Protocol TCP
Class CGI
Detailed Description The ViRobot Linux Server is vulnerable to an authentication bypass vulnerability in the filescan script. ViRobot Linux Server is a commercial anti-virus product for Linux-based operating systems. ViRobot Linux Server version 2.0 and possibly earlier versions could allow a remote attacker by bypass authentication, caused by improper validation of the HTTP_COOKIE variable. A remote attacker could exploit this vulnerability to bypass authentication and gain administrative access to the system.

* References:
http://www.securityfocus.com/archive/1/425788/30/0/threaded
http://www.frsirt.com/english/advisories/2006/0691
http://secunia.com/advisories/18974/

* Platforms Affected:
HAURI Inc., ViRobot Linux Server version 2.0 and earlier versions
Linux Any version
Recommendation Apply the appropriate patch for your system, available from the HAURI Web site at http://www.hauri.net/download/download_linux_patch.php
Related URL CVE-2006-0864 (CVE)
Related URL 16768 (SecurityFocus)
Related URL 24850 (ISS)