mod_survey For Apache ENV Tags SQL Injection

This script is Copyright (C) 2003-2011 Tenable Network Security, Inc.


Synopsis :

The web server module on the remote host has a SQL injection
vulnerability.

Description :

According to the banner, the remote host is using a vulnerable
version of mod_survey, a Perl module for managing online surveys.
This version has a flaw that could result in a SQL injection attack
when the module is being used with a database backend. A remote
attacker could exploit this to take control of the database.

Solution :

Upgrade to mod_survey 3.0.14e / 3.0.15pre6 or later.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 6.5
(CVSS2#E:H/RL:OF/RC:C)
Public Exploit Available : true

Family: Web Servers

Nessus Plugin ID: 11609 ()

Bugtraq ID: 7192

CVE ID: