27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

RISK:<br />

MEDIUM<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a directory traversal flaw.\n\nThe remote<br />

host is running Web Wiz Forums, a free tool for generating web-based forums. The<br />

reported version (%L) is reported to be vulnerable to a number of flaws that, if executed,<br />

would give an attacker access to confidential data. Specifically, the 'sub' parameter of the<br />

'RTE_file_browser.asp' script fails to sanitize user-supplied data of the form '../'. An<br />

attacker can use this flaw to access data outside of the web directories. This same flaw can<br />

also be exploited via the 'file_browser.asp' script.<br />

Solution: Upgrade to version 9.08 or higher.<br />

CVE-2008-0481<br />

DB2 < 8.1 FixPak 16 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 4358 FAMILY: Database RISK: HIGH NESSUS ID:30153<br />

Description: Synopsis :\n\nThe remote database server is affected by multiple issues.\n\nAccording to its<br />

version, the installation of DB2 on the remote host is affected by one or more of the<br />

following issues :\n\n - A local user may be able to gain root privileges using the 'db2pd'<br />

tool (IZ03546).\n - The 'b2dart' tool executes a TPUT command that effectively allows<br />

users to run commands as the DB2 instance owner (IZ03647).\n - A buffer overflow and<br />

invalid memory access vulnerability exists in the DAS server code (IZ05496).\n - An<br />

unspecified vulnerability in 'SYSPROC.ADMIN_SP_C' (IZ06972).\n - An unspecified<br />

vulnerability exists due to incorrect authorization checking in 'ALTER TABLE' statements<br />

(IZ07337).<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE-2008-0698<br />

MicroTik Router Version Detection<br />

<strong>PVS</strong> ID: 4359 FAMILY: Generic RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running a MicroTik router. The reported version is: %L<br />

Solution: Ensure that you are running the latest version of MicroTik router.<br />

CVE Not available<br />

MicroTik Router Version Detection<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 4360 FAMILY: Generic RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running a MicroTik router. The reported version is: %L<br />

Solution: Ensure that you are running the latest version of MicroTik router.<br />

Family Internet Services 1136

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!