Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> CGI abuses >> Ashnews Code Injection


Vulnerability Assessment Details

Ashnews Code Injection

Vulnerability Assessment Summary
Searches for the existence of ashnews.php

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote web server contains a PHP application that is affected by
multiple vulnerabilities.

Description :

It is possible to make the remote host include php files hosted on a
third party server using Ashnews.

A possible hacker may use this flaw to inject arbitrary code in the remote
host and gain a shell with the rights of the web server.

In addition, the application reportedly fails to sanitize the 'id'
parameter before using it in dynamically-generated output, subjecting
users to cross-site scripting attacks.

See also :

http://www.securityfocus.com/archive/1/329910
http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041844.html

Solution :

Remove the software as it is no longer supported.

Network Security Threat Level:

Low / CVSS Base Score : 2.3
(AV:R/AC:L/Au:NR/C:N/I:P/A:N/B:N)

Networks Security ID: 8241, 16426

Vulnerability Assessment Copyright: This script is Copyright (C) 2003 Tenable Network Security

Cables, Connectors


Juniper EX4300-48T-AFI 48x 1GB RJ-45 4x 40GB QSFP+ Switch - Same Day Shipping picture

Juniper EX4300-48T-AFI 48x 1GB RJ-45 4x 40GB QSFP+ Switch - Same Day Shipping

$189.99



Juniper EX2300-C-12P, 12 Port FANLESS POE Ethernet Switch EX2300-C picture

Juniper EX2300-C-12P, 12 Port FANLESS POE Ethernet Switch EX2300-C

$375.00



Juniper Networks SRX340 SRX300 Series 8-Port Security Firewall Tested picture

Juniper Networks SRX340 SRX300 Series 8-Port Security Firewall Tested

$129.00



Juniper Networks EX2200-C Gigabit Ethernet Managed Switch | EX2200-C-12T-2G picture

Juniper Networks EX2200-C Gigabit Ethernet Managed Switch | EX2200-C-12T-2G

$49.99



Juniper EX3400-48P 48-Ports PoE+ 4x SFP+ and 2x QSFP+ Managed Switch Tested picture

Juniper EX3400-48P 48-Ports PoE+ 4x SFP+ and 2x QSFP+ Managed Switch Tested

$170.00



Juniper Networks EX4400-48MP 48 port 5GbE + 12 port 10 Gigabit PoE++ Switch -NEW picture

Juniper Networks EX4400-48MP 48 port 5GbE + 12 port 10 Gigabit PoE++ Switch -NEW

$1100.00



Juniper EX3400-48P PoE+ 48x Gb 4x SFP+ Network Ethernet Switch Single PSU picture

Juniper EX3400-48P PoE+ 48x Gb 4x SFP+ Network Ethernet Switch Single PSU

$124.99



Juniper Networks EX3300 EX3300-48T 48-Port Gigabit Switch picture

Juniper Networks EX3300 EX3300-48T 48-Port Gigabit Switch

$59.95



Juniper Networks EX4300-48T 48 Port Gigabit 4 QSFP 40G 2xPSU AFO Network Switch picture

Juniper Networks EX4300-48T 48 Port Gigabit 4 QSFP 40G 2xPSU AFO Network Switch

$89.00



Juniper QFX5200-32C-AFO 32P QSFP28 Switch picture

Juniper QFX5200-32C-AFO 32P QSFP28 Switch

$1199.00



Discussions

No Discussions have been posted on this vulnerability.