NaviCOPA < 3.01 6th February 2009 Multiple Vulnerabilities

This script is Copyright (C) 2009-2011 Tenable Network Security, Inc.


Synopsis :

The remote web server is affected by multiple vulnerabilities.

Description :

According to its banner, the version of the NaviCOPA web server
software running on the remote host is either earlier than 3.01 or
3.01 from before the 6th of February 2009. Such versions are affected
by two vulnerabilities :

- There is a heap-based buffer overflow that can be
triggered when handling an overly long GET request.

- The server returns the source of scripts hosted on it if
the URL ends in a dot ('.').

See also :

http://www.securityfocus.com/archive/1/500626/30/0/threaded

Solution :

Upgrade to NaviCOPA 3.01 from 6th February 2009 or later as that
reportedly resolves the issues.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.3
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Web Servers

Nessus Plugin ID: 35619 ()

Bugtraq ID: 33585

CVE ID: