SCAN: Cachemgr.cgi Access

This signature detects access to the squid cachemgr.cgi script. Attackers can use this script as a denial-of-service (DoS) attack tool.

Extended Description

The 'cachemgr.cgi' module is a management interface for the Squid proxy service. It was installed by default in '/cgi-bin' by Red Hat Linux 5.2 and 6.0 installed with Squid. This script prompts for a host and port, which it then tries to connect to. If a webserver such as Apache is running, this can be used to connect to arbitrary hosts and ports, allowing for potential use as an intermediary in denial-of-service attacks, proxied port scans, etc. Interpreting the output of the script can allow the attacker to determine whether or not a connection was established.

Affected Products

National_science_foundation squid_web_proxy

References

BugTraq: 2059

CVE: CVE-1999-0710

Short Name
SCAN:MISC:HTTP:CACHEMGR-ACCESS
Severity
Warning
Recommended
False
Recommended Action
None
Category
SCAN
Keywords
Access CVE-1999-0710 Cachemgr.cgi bid:2059
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Red_hat

Sgi

Debian

National_science_foundation

CVSS Score

7.5

Found a potential security threat?