SCAN: Bigconf.cgi Access
This signature detects access to the bigconf.cgi file. Attackers can view arbitrary files on the Web server.
Extended Description
BigIP is a load balancing system from F5 software. It has a web-based configuration system, which is vulnerable to several standard CGI attacks. According to Guy Cohen , it is possible to view arbitrary files on the BSDI system which it is installed on. To add to this, the configuration program is installed setuid root. This is considered a local vulnerability since htaccess authentication is required to get to the configuration area. No more information on this vulnerability is available.
Affected Products
F5 bigip
References
BugTraq: 778
CVE: CVE-1999-1550
URL: http://www.securityspace.com/smysecure/catid.html?id=10027
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
F5
5.0