mod_survey For Apache ENV Tags SQL Injection

This script is Copyright (C) 2003-2011 Tenable Network Security, Inc.

Synopsis :

The web server module on the remote host has a SQL injection

Description :

According to the banner, the remote host is using a vulnerable
version of mod_survey, a Perl module for managing online surveys.
This version has a flaw that could result in a SQL injection attack
when the module is being used with a database backend. A remote
attacker could exploit this to take control of the database.

Solution :

Upgrade to mod_survey 3.0.14e / 3.0.15pre6 or later.

Risk factor :

High / CVSS Base Score : 7.5
CVSS Temporal Score : 6.5
Public Exploit Available : true

Family: Web Servers

Nessus Plugin ID: 11609 ()

Bugtraq ID: 7192