Synopsis
Sensitive data can be read or written on the remote host.
Description
ODBC tools are present on the remote host.
ODBC tools could allow a malicious user to hijack and redirect ODBC traffic, obtain SQL user names and passwords or write files to the local drive of a vulnerable server.
Example: http://www.example.com/scripts/tools/getdrvrs.exe
Solution
Remove ODBC tools from the /scripts/tools directory.
Plugin Details
File Name: odbc_tools_check.nasl
Configuration: Enable paranoid mode
Supported Sensors: Nessus
Vulnerability Information
Required KB Items: Settings/ParanoidReport
Vulnerability Publication Date: 1/1/1999