27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Description: The remote host is running MySpaceIM, an application that allows MySpace users to chat<br />

with one another.<br />

Solution: Ensure that such chat clients are authorized according to corporate policies and guidelines.<br />

CVE Not available<br />

.pst File Email Attachment Detection<br />

<strong>PVS</strong> ID: 3940 FAMILY: Data Leakage RISK: LOW NESSUS ID:Not Available<br />

Description: The remote host was just observed sending the following .pst file.%L\nThe file was<br />

observed as an email attachment. If the file is confidential, check your mail server logs to<br />

see who the sender and/or recipient was.<br />

Solution: N/A<br />

CVE Not available<br />

.pst Office File Detection<br />

<strong>PVS</strong> ID: 3941 FAMILY: Data Leakage RISK: INFO NESSUS ID:Not Available<br />

Description: The remote web server is hosting .pst files. As an example, consider the following<br />

file %P\nThe webmaster should ensure that they do not contain confidential data.<br />

Solution: N/A<br />

CVE Not available<br />

LedgerSMB / SQL-Ledger Authentication Bypass<br />

<strong>PVS</strong> ID: 3942 FAMILY: Web Servers RISK: HIGH NESSUS ID:24748<br />

Description: Synopsis :\n\nThe remote web server contains a Perl application that is prone to an<br />

authentication bypass issue.\n\nThe remote host is running LedgerSMB or SQL-Ledger, a<br />

web-based double-entry accounting system. The version of LedgerSMB or SQL-Ledger on<br />

the remote host contains a design flaw that can be leveraged by a remote attacker to bypass<br />

authentication and can gain administrative access of the application.<br />

Solution: If using LedgerSMB, upgrade to 1.1.9 or higher. There is no known solution for<br />

SQL-Ledger at this time.<br />

CVE-2007-0777<br />

.ost File Email Attachment Detection<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 3943 FAMILY: Data Leakage RISK: LOW NESSUS ID:Not Available<br />

Family Internet Services 1021

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!