Summary
The remote host seems to be running cvstrac,
a web-based bug and patch-set tracking system for CVS.
This version contains a flaw related to the timeline_page() function in timeline.c that may allow an attacker to cause a buffer overflow.
An attacker, exploiting this flaw, would be potentially able to run exploit code on the remote machine.
***** OVS has determined the vulnerability exists on the target ***** simply by looking at the version number(s) of CVSTrac ***** installed there.
Solution
Update to version 1.1.4 or disable this CGI suite
Severity
Classification
-
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- appRain CMF SQL Injection And Cross Site Scripting Vulnerabilities
- A-Blog 'sources/search.php' SQL Injection Vulnerability
- Alcatel-Lucent OmniPCX Enterprise Remote Command Execution Vulnerability
- ASAS Server End User Self Service (EUSS) SQL Injection Vulnerability
- Adobe ColdFusion Multiple Vulnerabilities-02 May-2014