Synopsis
A web application is protected using default administrator credentials.
Description
The remote web server hosts Asterisk Recording Interface (ARI), which provides a web-enabled interface for Asterisk users to manage their voicemail and phone features.
The remote installation of ARI uses a default set of credentials for the administrator's account. With this information, an attacker can gain administrative access to the application.
Solution
Edit the application's 'includes/main.conf.php' file and change the values for '$ARI_ADMIN_USERNAME' and/or '$ARI_ADMIN_PASSWORD'.
Plugin Details
File Name: ari_default_creds.nasl
Configuration: Enable thorough checks
Supported Sensors: Nessus
Vulnerability Information
Excluded KB Items: global_settings/supplied_logins_only