Synopsis
The remote host has a CGI installed which allow arbitrary code execution on the remote system.
Description
The 'vpasswd.cgi' CGI is installed. Some versions do not properly check for special characters and allow an attacker to execute any command on your system.
Warning : Nessus solely relied on the presence of this CGI, it did not determine if you specific version is vulnerable to that problem
Solution
remove it from /cgi-bin.
Plugin Details
File Name: vpasswd_cgi.nasl
Configuration: Enable paranoid mode
Supported Sensors: Nessus
Vulnerability Information
Required KB Items: Settings/ParanoidReport
Exploit Ease: No known exploits are available
Vulnerability Publication Date: 10/24/2002
Reference Information
BID: 6038