27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: Synopsis :\n\nThe remote web server contains a PHP script that is prone to a SQL injection<br />

attack.\n\nThe version of Burning Board / Burning Board Lite on the remote host fails to<br />

sanitize user input to the 'boardids' parameter of the 'search.php' script before using it in<br />

database queries. Regardless of PHP's 'register_globals' and 'magic_quotes_gpc' settings, an<br />

unauthenticated remote attacker can leverage this issue to launch SQL injection attacks<br />

against the affected application, including discovery of password hashes of users of the<br />

application.<br />

Solution: No solution is known at this time.<br />

BitDefender Detection<br />

CVE-2007-1518<br />

<strong>PVS</strong> ID: 3889 FAMILY: Web Clients RISK: INFO NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host has an antivirus software package installed on it.\n\nThe<br />

remote host is running BitDefender, a commercial antivirus software package for Windows.<br />

Solution: N/A<br />

CVE Not available<br />

WordPress < 2.1 Pingback Information Disclosure<br />

<strong>PVS</strong> ID: 3890 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:24237<br />

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack vectors.\n\nThe version of<br />

WordPress installed on the remote host fails to sanitize the 'sourceURI' before passing it to<br />

the 'wp_remote_fopen()' function when processing pingbacks. An unauthenticated remote<br />

attacker can leverage this issue to determine the existence of local files and possibly even to<br />

view parts of those files, subject to the permissions of the web server user ID. In addition,<br />

the version is also reportedly susceptible to a denial of service attack because it allows an<br />

anonymous attacker to cause a server to fetch arbitrary URLs without limits. The path to<br />

the WordPress application is:\n%P<br />

Solution: Upgrade to version 2.1 or higher.<br />

CVE Not available<br />

Symantec Antivirus Version Number Detection<br />

<strong>PVS</strong> ID: 3891 FAMILY: Web Clients RISK: LOW NESSUS ID:Not Available<br />

Description: The remote host is running Symantec Antivirus.<br />

Solution: Ensure that you are running the latest version of Symantec Antivirus.<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 1007

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!