GreyMatter gm-upload.cgi Arbitrary File Upload

Medium Nessus Network Monitor Plugin ID 3489


The remote host is vulnerable to a Script Injection attack.


The remote host is running Greymatter, a log and journal application. This version of Greymatter is vulnerable to a flaw where an attacker can upload and execute arbitrary code with the rights of the web server. Successful exploitation would lead to the attacker executing arbitrary code that would impact confidentiality, integrity and availability.


Upgrade or patch according to vendor recommendations.

See Also

Plugin Details

Severity: Medium

ID: 3489

File Name: 3489.prm

Family: CGI

Published: 2006/03/28

Modified: 2016/01/21

Dependencies: 1442

Risk Information

Risk Factor: Medium


Base Score: 6.5

Temporal Score: 6.2

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Temporal Vector: CVSS2#E:F/RL:U/RC:ND


Base Score: 6.3

Temporal Score: 6.2


Temporal Vector: CVSS3#E:F/RL:U/RC:X

Reference Information

CVE: CVE-2006-1485

BID: 17271

OSVDB: 24210