Nessus Tenable Web UI Information Disclosure Vulnerbility

Summary
This host is installed with Nessus and is prone to information disclosure vulnerability.
Impact
Successful exploitation will allow remote attackers to gain knowledge on sensitive information. Impact Level: Application
Solution
Upgrade Tenable Web UI component to 2.3.5 in Nessus. For updates refer http://www.tenable.com/products/nessus
Insight
The flaw exists due to an error in /server/properties which does not validate 'token' parameter.
Affected
Tenable Web UI before 2.3.5 in Nessus versions 5.2.3 through 5.2.7
Detection
Send a crafted data via HTTP GET request and check whether it is vulnerable or not.
References