27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Solution: Upgrade to version 2.70.37 or higher.<br />

CVE-2007-2852<br />

Cubecart < 3.0.17 cart.inc.php Multiple Parameter SQL Injection<br />

<strong>PVS</strong> ID: 4002 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a SQL Injection attack.\n\nThe version of<br />

CubeCart installed on the remote host fails to properly sanitize user-supplied input to the<br />

'options' parameter before using it in /include/path/cart.inc.php. An unauthenticated remote<br />

attacker may be able to exploit this issue to execute arbitrary SQL commands on the remote<br />

database server. An attacker exploiting this flaw would only need to be able to send HTTP<br />

requests to the Cubecart application.<br />

Solution: Upgrade to version 3.0.17 or higher.<br />

CVE-2007-2862<br />

FTP Server .xls Office Files Detection<br />

<strong>PVS</strong> ID: 4003 FAMILY: Data Leakage RISK: INFO NESSUS ID:Not Available<br />

Description: The remote FTP server is hosting .xls files. As an example, consider the following file that<br />

was detected on the remote FTP server\n%P\n\nDistributing files over FTP is a common<br />

way of distributing information; however, efforts should be taken to ensure that the hosted<br />

files do not contain confidential data. risk<br />

Solution: N/A<br />

CVE Not available<br />

FTP Server .doc Office Files Detection<br />

<strong>PVS</strong> ID: 4004 FAMILY: Data Leakage RISK: INFO NESSUS ID:Not Available<br />

Description: The remote FTP server is hosting .doc files. As an example, consider the following file that<br />

was detected on the remote FTP server\n%P\n\nDistributing files over FTP is a common<br />

way of distributing information; however, efforts should be taken to ensure that the hosted<br />

files do not contain confidential data.<br />

Solution: N/A<br />

CVE Not available<br />

FTP Server .ppt Office Files Detection<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 4005 FAMILY: Data Leakage RISK: INFO NESSUS ID:Not Available<br />

Family Internet Services 1038

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!