CGI Generic XPath Injection (2nd pass)

medium Nessus Plugin ID 56245

Synopsis

A web application is potentially vulnerable to XPath injection.

Description

By providing specially crafted parameters to CGIs, Nessus was able to get an error from the underlying XPath engine. This error suggests that the CGI is affected by an XPath injection vulnerability.

An attacker may exploit this flaw to bypass authentication or read confidential data.

Solution

Modify the relevant CGIs so that they properly escape arguments.

Plugin Details

Severity: Medium

ID: 56245

File Name: torture_cgi_xpath_injection2.nasl

Version: 2.5

Type: remote

Family: CGI abuses

Published: 9/21/2011

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

Required KB Items: Settings/enable_web_app_tests

Reference Information

CWE: 20, 209, 643, 713, 722, 727, 751, 77, 801, 810, 928, 929, 933