Vulnerabilities > CVE-1999-0526 - Unspecified vulnerability in X.Org X11 7.11.1.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
Metasploit
description | This module scans for X11 servers that allow anyone to connect without authentication. |
id | MSF:AUXILIARY/SCANNER/X11/OPEN_X11 |
last seen | 2020-03-15 |
modified | 2017-07-24 |
published | 2008-10-15 |
references | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0526 |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/auxiliary/scanner/x11/open_x11.rb |
title | X11 No-Auth Scanner |
Nessus
NASL family | Misc. |
NASL id | X_OPEN.NASL |
description | The remote X11 server accepts connections from anywhere. An attacker can connect to it to eavesdrop on the keyboard and mouse events of a user on the remote host. It is even possible for an attacker to grab a screenshot of the remote host or to display arbitrary programs. An attacker can exploit this flaw to obtain the username and password of a user on the remote host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 19948 |
published | 2005-10-10 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/19948 |
title | X11 Server Unauthenticated Access |
code |
|