5
CVSSv2

CVE-2014-4980

Published: 23/07/2014 Updated: 09/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The /server/properties resource in Tenable Web UI prior to 2.3.5 for Nessus 5.2.3 up to and including 5.2.7 allows remote malicious users to obtain sensitive information via the token parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

tenable nessus 5.2.6

tenable nessus 5.2.7

tenable web ui

tenable nessus 5.2.3

tenable nessus 5.2.4

tenable nessus 5.2.5

Vendor Advisories

Nessus was found to be vulnerable to a parameter tampering issue that could result in a limited information disclosure The issue is due to the web server's /server/properties resource including information meant for authenticated users This resource is designed to provide limited information about the scanner for API requests However, manipulati ...

Exploits

Tenable Nessus versions 523 through 527 suffer from authentication bypass vulnerabilities via parameter tampering ...