Nessus
[Top] [All Lists]

Re: nessus plugin id 14685

To: Muhaimin Bin Dzulfakar <muhaimin.dzulfakar@extol.com.my>
Subject: Re: nessus plugin id 14685
From: "George A. Theall" <theall@tenablesecurity.com>
Date: Sat, 09 Dec 2006 08:22:35 -0500
Cc: nessus@list.nessus.org, "Steven M. Christey" <coley@mitre.org>, moderators@osvdb.org
Delivered-to: sp-com-lists@consult.net
Delivered-to: nessus-list1@securepoint.com
Delivered-to: nessus@list.nessus.org
In-reply-to: <19830296.6971165633653168.JavaMail.root@mailsrv2.extol.com.my>
List-archive: <http://mail.nessus.org/pipermail/nessus>
List-help: <mailto:nessus-request@list.nessus.org?subject=help>
List-id: Discussion of Nessus software <nessus.list.nessus.org>
List-post: <mailto:nessus@list.nessus.org>
List-subscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=subscribe>
List-unsubscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=unsubscribe>
References: <19830296.6971165633653168.JavaMail.root@mailsrv2.extol.com.my>
Sender: nessus-bounces@list.nessus.org
User-agent: Thunderbird 1.5.0.8 (X11/20061110)
On Sat, Dec 09, 2006 at 11:07:33AM +0800, Muhaimin Bin Dzulfakar wrote:

I found a vulnerability with plugin id 14685 which is equal to
CVE-2004-1665. The plugin shows that it checks on index.php for cross
site scripting

Right. Look at the original advisory:

  http://archives.neohapsis.com/archives/bugtraq/2004-09/0066.html

It shows exploits that work through index.php.

but from the vendor site,
http://psnews.sourceforge.net/, you can find all the source code are
coded with asp.

The original advisory doesn't actually specify the vendor, only the product name. I suspect one of the vulnerability databases assumed incorrectly that the vendor was http://psnews.sourceforge.net/ and the others copied that information without verifying it as Bugtraq / OSVDB / CVE / SecurityTracker / etc all reference that. If you search for sites with "Powered by PsNews", though, you'll turn up a lot of Polish sites that use something called PsNews from IMPSystems, http://www.imps.pl/. And if you explore them, you'll see they use PHP as well as the same parameter arguments as in the original advisory; eg,

  http://free.of.pl/t/toxnews/index.php?function=add_kom&no=44


George
--
theall@tenablesecurity.com
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>