27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Apache < 2.2.8 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 4385 FAMILY: Web Servers RISK: LOW NESSUS ID:31118<br />

Description: Synopsis :\n\nThe remote web server may be affected by several issues.\n\nThe version of<br />

Apache installed on the remote host is advertising a version older than 2.2.8. Such versions<br />

may be affected by several issues, including :\n\n - A cross-site scripting issue involving<br />

mod_imagemap (CVE-2007-5000).\n\n - A cross-site scripting issue involving 413 error<br />

pages via a malformed HTTP method (PR 44014 / CVE-2007-6203).\n\n - A cross-site<br />

scripting issue in mod_status involving the refresh parameter (CVE-2007-6388).\n\n - A<br />

cross-site scripting issue in mod_proxy_balancer involving the worker route and worker<br />

redirect string of the balancer manager (CVE-2007-6421).\n\n - A denial of service issue in<br />

the balancer_handler function in mod_proxy_balancer can be triggered by an authenticated<br />

user when a threaded Multi-Processing Module is used (CVE-2007-6422).\n\n - A<br />

cross-site scripting issue using UTF-7 encoding in mod_proxy_ftp exists because it does<br />

not define a charset (CVE-2008-0005).<br />

Solution: Upgrade to version 2.2.8 or higher.<br />

CVE-2007-6423<br />

Opera < 9.26 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 4386 FAMILY: Web Clients<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:31129<br />

Description: Synopsis :\n\nThe remote host contains a web browser that is affected by several<br />

issues.\n\nThe version of Opera installed on the remote host is reportedly affected by<br />

several issues :\n\n - Simulated text input could trick users into uploading arbitrary<br />

files.\n\n - Image properties comments containing script will be run when displaying the<br />

image properties, leading to code execution in the wrong security context.\n\n -<br />

Representation of DOM attribute values could allow cross-site scripting when importing<br />

XML into a document.<br />

Solution: Upgrade to version 9.26 or higher.<br />

CVE-2008-1082<br />

sapLPD Version Detection<br />

<strong>PVS</strong> ID: 4387 FAMILY: Generic RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running the SAP Line Printer Daemon (LPD) version: %L<br />

Solution: N/A<br />

CVE Not available<br />

SAPlpd < 6.29 Multiple Vulnerabilities<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 4388 FAMILY: Generic RISK: HIGH NESSUS ID:31121<br />

Family Internet Services 1144

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!