Synopsis
The web server module on the remote host has a SQL injection vulnerability.
Description
According to the banner, the remote host is using a vulnerable version of mod_survey, a Perl module for managing online surveys.
This version has a flaw that could result in a SQL injection attack when the module is being used with a database backend. A remote attacker could exploit this to take control of the database.
Solution
Upgrade to mod_survey 3.0.14e / 3.0.15pre6 or later.
Plugin Details
File Name: mod_survey_sql_injection.nasl
Supported Sensors: Nessus
Vulnerability Information
Exploit Ease: No exploit is required
Vulnerability Publication Date: 3/28/2003
Reference Information
BID: 7192