Stalkerlab Mailers CGIMail.exe Arbitrary File Retrieval

low Nessus Plugin ID 11721

Language:

Synopsis

The remote web server is hosting a CGI application that is affected by an information disclosure vulnerability.

Description

The CGI 'CgiMail.exe' exists on this web server. Some versions of this file are vulnerable to remote exploit.

An attacker can use this flaw to gain access to confidential data or further escalate their privileges.

Solution

There is no known solution at this time.

See Also

https://seclists.org/bugtraq/2000/Aug/418

Plugin Details

Severity: Low

ID: 11721

File Name: cgimail.nasl

Version: 1.23

Type: remote

Family: CGI abuses

Published: 6/11/2003

Updated: 1/19/2021

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: Low

Base Score: 2.6

Temporal Score: 2.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Information

Required KB Items: Settings/ParanoidReport

Excluded KB Items: Settings/disable_cgi_scanning

Vulnerability Publication Date: 8/29/2000

Reference Information

CVE: CVE-2000-0726

BID: 1623