Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> CGI abuses >> p-news Admin Access


Vulnerability Assessment Details

p-news Admin Access

Vulnerability Assessment Summary
Searches for the existence of p-news.php

Detailed Explanation for this Vulnerability Assessment

The remote host is running the p-news bulletin board.

There is a flaw in the version in use which may permit a possible hacker
who has a 'Member' account to upgrade its rights to administrator
by supplying a malformed username.

Solution : Delete this CGI
Network Security Threat Level: Medium

Networks Security ID:

Vulnerability Assessment Copyright: This script is Copyright (C) 2003 Tenable Network Security

Cables, Connectors

Dell T310 Server
$80.0
Dell T310 Server pictureHP ProLiant DL20 Gen9 2U Rack Server - Xeon E3-1220v5 3.0GHz (PID 823556-B21)
$300.0
HP ProLiant DL20 Gen9 2U Rack Server - Xeon E3-1220v5 3.0GHz (PID 823556-B21) pictureUsed Supermicro X8DTI-LN4F Motherboard - EATX LGA1366 + 2x Xeon X5650 CPUs
$109.49
Used Supermicro X8DTI-LN4F Motherboard - EATX LGA1366 + 2x Xeon X5650 CPUs pictureDell T310 Intel Xeon 8gb 2 1TB RAID Ubuntu Installed. Boots perfect
$100.0
Dell T310 Intel Xeon 8gb 2 1TB RAID Ubuntu Installed. Boots perfect picture


Discussions

No Discussions have been posted on this vulnerability.