Bandersnatch <= 0.4 Multiple Vulnerabilities
Medium Nessus Network Monitor Plugin ID 4149
SynopsisThe remote host is vulnerable to multiple attack vectors.
DescriptionThe remote server is running Bandersnatch, an open-source PHP application that generates Jabber usage statistics. This version of Bandersnatch is vulnerable to a flaw in the way that it parses multiple user-supplied variables. An attacker exploiting these flaws can inject script and SQL code that would be executed on the server with the permissions of the web server.
SolutionUpgrade or patch according to vendor recommendations.