VID |
21846 |
Severity |
40 |
Port |
8080 |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
The ViRobot Linux Server is vulnerable to an authentication bypass vulnerability in the filescan script. ViRobot Linux Server is a commercial anti-virus product for Linux-based operating systems. ViRobot Linux Server version 2.0 and possibly earlier versions could allow a remote attacker by bypass authentication, caused by improper validation of the HTTP_COOKIE variable. A remote attacker could exploit this vulnerability to bypass authentication and gain administrative access to the system.
* References: http://www.securityfocus.com/archive/1/425788/30/0/threaded http://www.frsirt.com/english/advisories/2006/0691 http://secunia.com/advisories/18974/
* Platforms Affected: HAURI Inc., ViRobot Linux Server version 2.0 and earlier versions Linux Any version |
Recommendation |
Apply the appropriate patch for your system, available from the HAURI Web site at http://www.hauri.net/download/download_linux_patch.php |
Related URL |
CVE-2006-0864 (CVE) |
Related URL |
16768 (SecurityFocus) |
Related URL |
24850 (ISS) |
|