Synopsis
A web application running on the remote host has an information disclosure vulnerability.
Description
The remote host is hosting eLDAPo, a PHP-based CGI suite designed to perform LDAP queries.
This application stores the passwords to the LDAP server in plaintext in its source file. An attacker can read the source code of index.php and use the information contained to gain credentials on a third-party server.
Solution
Upgade to eLDAPo 1.18 or later.
Plugin Details
File Name: eldapo_plaintext_passwords.nasl
Supported Sensors: Nessus
Vulnerability Information
Required KB Items: www/PHP
Excluded KB Items: Settings/disable_cgi_scanning
Exploit Ease: No exploit is required
Reference Information
BID: 7535