Vulnerability Description
nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to obtain sensitive information via a request to the /feed method, which reveals the version in a response.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nessus | Web Server Plugin | 1.2.4 |
| Nessus | Nessus | All versions |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/archive/1/512645/100/0/threaded
- https://discussions.nessus.org/message/7245#7245Vendor Advisory
- http://www.securityfocus.com/archive/1/512645/100/0/threaded
- https://discussions.nessus.org/message/7245#7245Vendor Advisory
FAQ
What is CVE-2010-2989?
CVE-2010-2989 is a vulnerability with a CVSS score of 5.0 (MEDIUM). nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to obtain sensitive information via a request to the /feed method, which reveals the version in a respo...
How severe is CVE-2010-2989?
CVE-2010-2989 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-2989?
Check the references section above for vendor advisories and patch information. Affected products include: Nessus Web Server Plugin, Nessus Nessus.