27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: The remote host is running the Apple iPhone Mail program version %L<br />

Solution: N/A<br />

CVE Not available<br />

paFileDB includes/search.php categories Parameter SQL Injection<br />

<strong>PVS</strong> ID: 4136 FAMILY: CGI RISK: HIGH NESSUS ID:25708<br />

Description: Synopsis :\n\nThe remote web server contains a PHP script that is prone to SQL a injection<br />

attack.\n\nThe version of paFileDB installed on the remote host fails to sanitize<br />

user-supplied input to the 'categories' parameter before using it in the 'includes/search.php'<br />

script to make database queries. An unauthenticated attacker can exploit this issue to<br />

manipulate database queries, which may lead to disclosure of sensitive information,<br />

modification of data or attacks against the underlying database.<br />

Solution: No solution is known at this time.<br />

CVE-2007-3808<br />

Curl < 7.16.4 Expired Certificate Access Restriction Bypass<br />

<strong>PVS</strong> ID: 4137 FAMILY: Web Clients RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host may allow access to unauthorized websites via an expired<br />

certificate.\n\nThe remote host is running Curl, a download client for various protocols.<br />

This version of Curl is vulnerable to an authentication flaw in the GnuTLS certificate<br />

verification routine. An attacker exploiting this flaw would be able to use an expired<br />

certificate.<br />

Solution: Upgrade to version 7.16.4 or higher.<br />

CVE-2007-3564<br />

IBM AppScan Detection<br />

<strong>PVS</strong> ID: 4138 FAMILY: Policy<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is running software that should be authorized with respect to<br />

corporate policy.\n\nThe remote server is running an IBM AppScan web scanner. AppScan<br />

is a security tool that allows security staff and administrators to automate web-based attacks<br />

and exploits against web servers. The reported version is: '%L'<br />

Solution: Ensure that this application is authorized according to corporate policies and guidelines.<br />

CVE Not available<br />

Tivoli Provisioning Manager <<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 1074

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!