OSSIM 'host/draw_tree.php' Access Restriction Weakness Information Disclosure

medium Nessus Plugin ID 42338

Synopsis

An application running on the remote web server has an unauthorized access vulnerability.

Description

The version of OSSIM running on the remote host has an unauthorized access vulnerability. It is possible to access the 'host/draw_tree.php' page without providing authentication. This page includes information about the network's topology. A remote attacker could use this information to mount further attacks.

Solution

Upgrade to OSSIM version 2.1.2 or later.

See Also

https://www.securityfocus.com/archive/1/506663

http://www.nessus.org/u?9fa7cc84

Plugin Details

Severity: Medium

ID: 42338

File Name: ossim_web_drawtree_unauth.nasl

Version: 1.13

Type: remote

Family: CGI abuses

Published: 11/2/2009

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

Required KB Items: www/PHP, www/ossim

Exploit Ease: No exploit is required

Patch Publication Date: 9/21/2009

Vulnerability Publication Date: 9/21/2009

Reference Information

CVE: CVE-2009-3441

BID: 36504

CWE: 287

Secunia: 36867