27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Check for Windows Update Traffic<br />

<strong>PVS</strong> ID: 4433 FAMILY: Generic RISK: LOW NESSUS ID:Not Available<br />

Description: The remote host is enabled and utilizing Microsoft Windows Update. This service<br />

allows users to check for missing updates and initiate remediation via the Microsoft<br />

update site. Depending on your individual policy, this may or may not be a desirable<br />

action.<br />

Solution: Ensure that Windows Update utilization is a valid use of company resources.<br />

CVE Not available<br />

Mac OS X Safari < 3.1 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 4434 FAMILY: Web Clients RISK: HIGH NESSUS ID:31604<br />

Description: Synopsis : \n\nThe remote host web browser is affected by multiple vulnerabilities.\n\nThe<br />

remote Mac OS X host is running a version of Safari that is older than version 3.1. The<br />

remote version of this software contains several security vulnerabilities that may allow an<br />

attacker to execute arbitrary code or a cross-site scripting attack on the remote host. To<br />

exploit these flaws, an attacker would need to convince a victim to visit a rogue web site or<br />

open a malicious HTML file. The exact version number that <strong>PVS</strong> observed was: \n %L<br />

Solution: Upgrade to version 3.1 or higher.<br />

CVE-2008-0050<br />

Mac OS X Version Detection<br />

<strong>PVS</strong> ID: 4435 FAMILY: Web Clients RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running Mac OS X version: '%L'<br />

Solution: N/A<br />

cPanel <<br />

CVE Not available<br />

<strong>PVS</strong> ID: 4436 FAMILY: Web Servers<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host may give an attacker information useful for future<br />

attacks.\n\nThe remote host is running cPanel, a web-hosting control panel. The remote<br />

version of this software is vulnerable to an information disclosure flaw. Specifically, the<br />

'showtree' parameter of the 'frontend/x/diskusage/index.html' script fails to sanitize<br />

user-supplied data. An attacker exploiting this flaw would be able to gain information<br />

regarding the programs and files utilized by the server. This information may be useful in<br />

more sophisticated attacks.<br />

Family Internet Services 1157

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!