27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

QuickTime < 7.3 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 4277 FAMILY: Web Clients RISK: HIGH NESSUS ID:27626<br />

Description: Synopsis : \n\nThe remote Windows host contains an application that is affected by<br />

multiple issues.\n\nThe version of QuickTime installed on the remote Windows host is<br />

older than 7.3. Such versions contain several vulnerabilities that may allow an attacker to<br />

execute arbitrary code on the remote host if the user can be convinced to open a<br />

specially-crafted file with QuickTime. The reported version of QuickTime is: \n %L<br />

Solution: Upgrade to version 7.3 or higher.<br />

CVE-2007-4676<br />

OrangeHRM < 2.2.2 RepViewController.php Privilege Escalation<br />

<strong>PVS</strong> ID: 4278 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a flaw that allows attackers to retrieve<br />

sensitive files or data.\n\nThe remote host is running OrangeHRM, a human resource<br />

management system written in PHP. The version of OrangeHRM installed on the remote<br />

host fails to sanitize input within the 'RepViewController.php' PHP script. An authenticated<br />

user may use this flaw to access private data. An attacker exploiting this flaw would need a<br />

valid account on the OrangeHRM system. Successful exploitation would result in the loss<br />

of confidential data.<br />

Solution: Upgrade to version 2.2.2 or higher.<br />

CVE-2007-5931<br />

HP Radia Integration Server Version Detection<br />

<strong>PVS</strong> ID: 4279 FAMILY: CGI RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running the HP Radia Integration server, a component of HP Openview<br />

that is used to manage enterprise machines. The reported version is '%L'<br />

Solution: N/A<br />

CVE Not available<br />

Trillian Version Detection<br />

<strong>PVS</strong> ID: 4280 FAMILY: Internet Messengers RISK: INFO NESSUS ID:Not Available<br />

Description: The version of Trillian installed on the remote client is '%L'.\nTrillian is a chat client that<br />

can be used for messaging and file transfer.<br />

Solution: N/A<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 1113

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!