Remote Help Default Credentials

critical Nessus Plugin ID 45138

Synopsis

The remote access service uses a default set of credentials.

Description

It was possible to log in to the Remote Help server on the remote host using a default set of credentials.

An attacker could exploit this flaw in order to gain complete control of the affected system.

Solution

Change the password for the default user.

See Also

http://remotehelp.sourceforge.net/en/index.html

Plugin Details

Severity: Critical

ID: 45138

File Name: remotehelp_default_credentials.nasl

Version: 1.10

Type: remote

Family: CGI abuses

Published: 3/24/2010

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

Required KB Items: www/remote_help

Excluded KB Items: global_settings/supplied_logins_only