vendor:
nweb2fax
by:
dun
8.8
CVSS
HIGH
Local File Inclusion, Arbitrary File Download, Remote Command Execution
22, 434, 78
CWE
Product Name: nweb2fax
Affected Version From: 2000.2.7
Affected Version To: 2000.2.7
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
nweb2fax <= 0.2.7 Multiple Remote Vulnerabilities
nweb2fax is vulnerable to multiple remote vulnerabilities. The first vulnerability is a Local File Inclusion vulnerability which allows an attacker to read any file on the server. The second vulnerability is an Arbitrary File Download vulnerability which allows an attacker to download any file from the server. The third vulnerability is a Remote Command Execution vulnerability which allows an attacker to execute arbitrary commands on the server.
Mitigation:
Upgrade to the latest version of nweb2fax, disable the script if not in use, and restrict access to the script.