Synopsis
The remote web server has a PHP script that is affected by multiple vulnerabilities.
Description
The remote host is VideoDB, a web-based video dabatase manager written in PHP.
The remote version of this software is vulnerable to a SQL injection attack due to a lack of filtering on user-supplied input. An attacker may exploit this flaw to modify the remote database.
This software may be vulnerable to an unauthorized access attack in the file 'edit.php' that may allow an attacker to edit database entries, as well as an unspecified cross-site scripting issue.
Solution
Upgrade to VideoDB 2.0.2 or later.
Plugin Details
File Name: videodb_multiple_vulnerabilites.nasl
Supported Sensors: Nessus
Vulnerability Information
CPE: cpe:/a:videodb:videodb
Required KB Items: www/PHP
Excluded KB Items: Settings/disable_cgi_scanning
Exploit Ease: No exploit is required
Patch Publication Date: 1/5/2005
Vulnerability Publication Date: 1/5/2005