27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: Synopsis :\n\nThe remote host is vulnerable to a SQL injection attack.\n\nThe remote host<br />

is running the Simple Machines Forum (SMF), a web forum. This version of SMF is<br />

vulnerable to a flaw in the way that it handles user-supplied data. Data passed to the<br />

'SMFCookie218' parameter of the 'index.php' script can contain SQL queries that are<br />

ultimately run against the default database server. An attacker exploiting this flaw would be<br />

able to execute arbitrary SQL commands against the default database server.<br />

Solution: Upgrade to version 1.1.4 or higher.<br />

CVE-2007-5646<br />

Vanilla Forum < 1.1.4 sortcategories.php CategoryID Parameter SQL Injection<br />

<strong>PVS</strong> ID: 4258 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a SQL injection attack.\n\nThe remote host<br />

is running the Vanilla Forum, a web forum. This version of Vanilla is vulnerable to a flaw<br />

in the way that it handles user-supplied data. Data passed to the 'CategoryID' parameter of<br />

the 'sortcategories.php' script can contain SQL queries that are ultimately run against the<br />

default database server. An attacker exploiting this flaw would be able to execute arbitrary<br />

SQL commands against the default database server.<br />

Solution: Upgrade to version 1.1.4 or higher.<br />

Simple PHP Blog <<br />

CVE-2007-5643<br />

<strong>PVS</strong> ID: 4259 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack vectors.\n\nThe remote host<br />

is running the Simple PHP Blog, web log (or blog) package version '%L'.\n\nThis version<br />

of Simple PHP Blog is vulnerable to multiple flaws that, at worst, allow the ability for a<br />

remote attacker to execute local script code. An attacker exploiting these flaws would only<br />

need the ability to send valid web requests to the application. Successful exploitation would<br />

result in a loss of confidentiality, integrity, and availability.<br />

Solution: No solution is known at this time.<br />

CVE Not available<br />

Delegate < 9.7.5 Multiple Vulnerabilities<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 4260 FAMILY: POP Server RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Denial of Service (DoS) attack.\n\nThe<br />

remote host is running Delegate, a proxy server. This version of Delegate is vulnerable to<br />

multiple remote Denial of Service (DoS) attacks. An attacker exploiting these flaws would<br />

be able to impact the availability of the proxy server.<br />

Family Internet Services 1108

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!