NASLDB: Active WebCam Webserver <= 5.5 Multiple Vulnerabilities (DoS, Path Disc)
General
ID: 17320
Name: Active WebCam Webserver <= 5.5 Multiple Vulnerabilities (DoS, Path Disc)
Summary: Checks for multiple remote vulnerabilities in Active WebCam webserver 5.5 and older
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P
CVSS Temporal Vector: CVSS2#E:H/RL:U/RC:ND
Port: 8080
Family: CGI abuses
Type: Remote
Description
The version of PY Software’s Active WebCam web server running on the
remote host is affected by multiple vulnerabilities:
o Denial of Service Vulnerabilities.
A request for a file on floppy drive may result in a dialog
prompt, causing the service to cease until it is acknowledged by
an administrator. In addition, requesting the file ‘Filelist.html’
reportedly causes CPU usage on the remote host to increase,
ultimately leading to denial of service.
o Information Disclosure Vulnerabilities.
A request for a nonexistent file will return an error message
with the installation path for the software. Further, error
messages differ depending on whether a file exists or is
inaccessible. An attacker may exploit these issues to gain
information about the filesystem on the remote host.
Note that while versions 4.3 and 5.5 are known to be affected, earlier
versions are likely to be as well.
Exploiting
Exploit Available: True
Exploitability Ease: No exploit is required
Sources
CVE: CVE-2005-0730
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: 2005/03/10
Patch Release: –
Plugin Release: 2005/03/12
Plugin
Version: 1.23
Filename: activewebcam_multiple_vulns.nasl
Filesize: 4104 bytes
MD5 Hash: 9e9009dc2ee4fdfde0f6c68b69a84966
Identification: –
Require Keys: –
Dependencies: "http_version.nasl"
Copyright: This script is Copyright© 2005-2012 Tenable Network Security, Inc.
- Latest Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













