First published: Tue Aug 10 2010(Updated: )
nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to obtain sensitive information via a request to the /feed method, which reveals the version in a response.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nessus Web Server plugin | =1.2.4 | |
Tenable Nessus |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2989 has a medium severity rating allowing for information disclosure.
To mitigate CVE-2010-2989, update Nessus Web Server plugin to a version higher than 1.2.4.
CVE-2010-2989 exploits a vulnerability in the Nessus Web Server plugin, specifically allowing attackers to access sensitive information.
CVE-2010-2989 can reveal the version of the Nessus Web Server plugin to an attacker.
Nessus Web Server plugin version 1.2.4 is specifically affected by CVE-2010-2989.