Bandersnatch <= 0.4 Multiple Vulnerabilities

Medium Nessus Network Monitor Plugin ID 4149


The remote host is vulnerable to multiple attack vectors.


The remote server is running Bandersnatch, an open-source PHP application that generates Jabber usage statistics. This version of Bandersnatch is vulnerable to a flaw in the way that it parses multiple user-supplied variables. An attacker exploiting these flaws can inject script and SQL code that would be executed on the server with the permissions of the web server.


Upgrade or patch according to vendor recommendations.

See Also

Plugin Details

Severity: Medium

ID: 4149

File Name: 4149.prm

Family: CGI

Published: 2007/07/31

Modified: 2016/01/21

Dependencies: 1442

Risk Information

Risk Factor: Medium


Base Score: 5.8

Temporal Score: 5.5

Vector: CVSS2#AV:A/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:F/RL:U/RC:ND


Base Score: 6.3

Temporal Score: 6.2


Temporal Vector: CVSS3#E:F/RL:U/RC:X

Reference Information

CVE: CVE-2007-3909, CVE-2007-3910

BID: 25094