Bandersnatch <= 0.4 Multiple Vulnerabilities

Medium Nessus Network Monitor Plugin ID 4149

Synopsis

The remote host is vulnerable to multiple attack vectors.

Description

The remote server is running Bandersnatch, an open-source PHP application that generates Jabber usage statistics. This version of Bandersnatch is vulnerable to a flaw in the way that it parses multiple user-supplied variables. An attacker exploiting these flaws can inject script and SQL code that would be executed on the server with the permissions of the web server.

Solution

Upgrade or patch according to vendor recommendations.

See Also

http://www.securityfocus.com/bid/25094

Plugin Details

Severity: Medium

ID: 4149

File Name: 4149.prm

Family: CGI

Published: 2007/07/31

Modified: 2016/01/21

Dependencies: 1442

Risk Information

Risk Factor: Medium

CVSSv2

Base Score: 5.8

Temporal Score: 5.5

Vector: CVSS2#AV:A/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:F/RL:U/RC:ND

CVSSv3

Base Score: 6.3

Temporal Score: 6.2

Vector: CVSS3#AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS3#E:F/RL:U/RC:X

Reference Information

CVE: CVE-2007-3909, CVE-2007-3910

BID: 25094