This script is Copyright (C) 2007-2012 Tenable Network Security, Inc.
Synopsis :
The remote web server contains a CGI script that allows arbitrary
command execution.
Description :
The remote host is running ServerView, a web-based suite of asset
management tools.
The version of ServerView installed on the remote host fails to
sanitize user-supplied input to the 'Servername' parameter of the
'SnmpView/SnmpListMibValues' script before using it to execute a shell
command. An unauthenticated attacker can leverage this issue to
execute arbitrary code on the remote host subject to the privileges of
the web server user id.
Note that the same result can be achieved via input to the
'ServerName' subparameter of the 'Parameterlist' parameter of the
'DBAsciiAccess' script.
See also :
http://www.securityfocus.com/archive/1/472800/30/0/threaded
Solution :
Upgrade to ServerView version 4.50.09 as that reportedly fixes the
issue.
Risk factor :
High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 5.9
(CVSS2#E:POC/RL:OF/RC:C)
Public Exploit Available : true