How to Buy
This script is Copyright (C) 2009-2011 Tenable Network Security, Inc.
The remote web server is affected by multiple vulnerabilities.
According to its banner, the version of the NaviCOPA web server
software running on the remote host is either earlier than 3.01 or
3.01 from before the 6th of February 2009. Such versions are affected
by two vulnerabilities :
- There is a heap-based buffer overflow that can be
triggered when handling an overly long GET request.
- The server returns the source of scripts hosted on it if
the URL ends in a dot ('.').
See also :
Upgrade to NaviCOPA 3.01 from 6th February 2009 or later as that
reportedly resolves the issues.
Risk factor :
Critical / CVSS Base Score : 10.0
CVSS Temporal Score : 8.3
Public Exploit Available : true
Family: Web Servers
Nessus Plugin ID: 35619 ()
Bugtraq ID: 33585
Get Nessus Professional to scan unlimited IPs, run compliance checks & more
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.