GreyMatter gm-upload.cgi Arbitrary File Upload
Medium Nessus Network Monitor Plugin ID 3489
SynopsisThe remote host is vulnerable to a Script Injection attack.
DescriptionThe remote host is running Greymatter, a log and journal application. This version of Greymatter is vulnerable to a flaw where an attacker can upload and execute arbitrary code with the rights of the web server. Successful exploitation would lead to the attacker executing arbitrary code that would impact confidentiality, integrity and availability.
SolutionUpgrade or patch according to vendor recommendations.