Synopsis
Information managed by the remote service can be modified or erased.
Description
The remote host is using the PT News management system.
There is a flaw in this version which allows anyone to execute arbitrary admnistrative PTnews command on this host (such as deleting news or editing a news) without having to know the administrator password.
An attacker may use this flaw to edit the content of this website or even to delete it completely.
Solution
Upgrade to PT News 1.7.8 or newer.
Plugin Details
File Name: ptnews_admin.nasl
Supported Sensors: Nessus
Vulnerability Information
Required KB Items: www/PHP
Excluded KB Items: Settings/disable_cgi_scanning
Exploit Ease: No exploit is required
Reference Information
BID: 7394