27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Solution: Upgrade to version 9.24 or higher.<br />

CVE-2007-5541<br />

RunCMS < 1.5.3 Unspecified Vulnerability<br />

<strong>PVS</strong> ID: 4250 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to unspecified remote attack vectors.\n\nThe<br />

remote host is running RunCMS, a web-based content management and messaging system.<br />

This version of RunCMS is reported to be vulnerable to a security flaw. The details of the<br />

flaw are unknown; however, it is alleged that the remote attacker would be able to impact<br />

confidentiality, integrity and availability.<br />

Solution: Upgrade to version 1.5.3 or higher.<br />

CVE-2007-5535<br />

Oracle 10g Application Server SQL Injection<br />

<strong>PVS</strong> ID: 4251 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a SQL injection attack.\n\nThe remote host<br />

is running a version of the Oracle 10g Application Server that is vulnerable to a remote<br />

SQL injection attack. An attacker exploiting this flaw would gain limited access to the<br />

remote database server. Successful exploitation would allow the attacker the ability to<br />

execute SQL commands on the database server.<br />

Solution: Apply the vendor patches for Oracle 10g versions 1 and 2.<br />

CVE-2007-5508<br />

Avocent DSView Server Detection<br />

<strong>PVS</strong> ID: 4252 FAMILY: Web Servers RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running the Avocent DSView server. This server is used to manage<br />

multiple Avocent DSR devices which, in turn, manage multiple servers. The reported<br />

version number was '%L'<br />

Solution: N/A<br />

CVE Not available<br />

Microsoft Internet Explorer Version Detection<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 4253 FAMILY: Web Clients RISK: INFO NESSUS ID:Not Available<br />

Family Internet Services 1106

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!