Synopsis
The remote web server has an application that is affected by an information disclosure vulnerability.
Description
The remote server is running Ocean12 GuestBook, a set of scripts to manage an interactive guestbook.
An attacker may download the database 'o12guest.mdb' and use it to extract the password of the admninistrator of these CGIs.
Solution
Block the download of .mdb files from your web server.
Plugin Details
File Name: ocean12_db_download.nasl
Supported Sensors: Nessus
Vulnerability Information
Excluded KB Items: Settings/disable_cgi_scanning
Exploit Ease: No exploit is required
Reference Information
BID: 7328