Xedus Web Server Traversal Arbitrary File Access

medium Nessus Plugin ID 14645

Synopsis

The remote host is running a web server with a directory traversal vulnerability.

Description

The remote host runs Xedus Peer-to-Peer web server. This version is vulnerable to directory traversal. An attacker could send a specially crafted URL to view arbitrary files on the system.

Solution

Upgrade to the latest version.

See Also

http://www.nessus.org/u?7d859f3a

Plugin Details

Severity: Medium

ID: 14645

File Name: xedus_dir_traversal.nasl

Version: 1.23

Type: remote

Published: 9/3/2004

Updated: 6/12/2020

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Exploited by Nessus: true

Vulnerability Publication Date: 8/30/2004

Reference Information

CVE: CVE-2004-1646

BID: 11071

Secunia: 12418