This script is Copyright (C) 2012-2014 Tenable Network Security, Inc.
The remote web server may be affected by multiple vulnerabilities.
According to its banner, the version of Apache 2.2 installed on the
remote host is earlier than 2.2.23. It is, therefore, potentially
affected by the following vulnerabilities:
- The utility 'apachectl' can receive a zero-length
directory name in the LD_LIBRARY_PATH via the 'envvars'
file. A local attacker with access to that utility
could exploit this to load a malicious Dynamic Shared
Object (DSO), leading to arbitrary code execution.
- An input validation error exists related to
'mod_negotiation', 'Multiviews' and untrusted uploads
that can allow cross-site scripting attacks.
Note that Nessus has not tested for these flaws but has instead relied
on the version in the server's banner.
See also :
Upgrade to Apache version 2.2.23 or later.
Risk factor :
Medium / CVSS Base Score : 6.9
CVSS Temporal Score : 6.0
Public Exploit Available : true