13.07.2015 Views

Nessus Scan Report - Columbia University

Nessus Scan Report - Columbia University

Nessus Scan Report - Columbia University

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Synopsis:The remote FTP server has a cross-site request forgery vulnerability.Description:The version of FTP running on the remote host has a cross-site requestforgery vulnerability. Long file names are not processed properly,resulting in the execution of arbitrary commands. If a user is logged intothe FTP server via web browser, a remote attacker could exploit this bytricking them into requesting a maliciously crafted web page, resulting inthe execution of arbitrary FTP commands.Risk factor:MediumCVSS Base Score:4.3CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:NSee also:http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0283.htmlSee also:http://securityreason.com/achievement_securityalert/84Solution:There is no known solution at this time.Plugin ID:47040BID:40320Other references:OSVDB:64869, Secunia:39856Anonymous FTP EnabledSynopsis:Anonymous logins are allowed on the remote FTP server.Description:This FTP service allows anonymous logins. Any remote user may connectand authenticate without providing a password or unique credentials.This allows a user to access any files made available on the FTP server.Risk factor:MediumCVSS Base Score:5.0CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:NSolution:Disable anonymous FTP if it is not required. Routinely check the FTP

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!