27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

ListManager words Parameter Cross-Site Scripting Vulnerability<br />

<strong>PVS</strong> ID: 4549 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:33219<br />

Description: Synopsis :\n\nThe remote web server is affected by a cross-site scripting<br />

vulnerability.\n\nThe remote host is running ListManager, a web-based commercial mailing<br />

list management application from Lyris. The version of ListManager installed on the<br />

remote host fails to sanitize user input to the 'words' parameter of the 'read/search/results'<br />

script before including it in dynamic HTML output. An attacker may be able to leverage<br />

this issue to inject arbitrary HTML and script code into a user's browser to be executed<br />

within the security context of the affected site.<br />

Solution: Upgrade to ListManager greater than 9.3d<br />

CVE-2008-2923<br />

JXTA P2P Server Detection<br />

<strong>PVS</strong> ID: 4550 FAMILY: Peer-To-Peer File Sharing<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is running software which should be authorized with respect<br />

to Corporate policy\n\nThe remote host is running the JXTA Server\nJXTA is a P2P<br />

application which allows users to quickly download files from multiple locations.<br />

Solution: Ensure that JXTA is allowed with respect to Corporate policies and guidelines.<br />

CVE Not available<br />

JXTA P2P Client Detection<br />

<strong>PVS</strong> ID: 4551 FAMILY: Peer-To-Peer File Sharing<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is running software that should be authorized with respect to<br />

corporate policy.\n\nThe remote host is running the JXTA Client.\nJXTA is a P2P<br />

application that allows users to quickly download files from multiple locations.<br />

Solution: Ensure that JXTA is allowed according to corporate policies and guidelines.<br />

CVE Not available<br />

Sun Java Calendar Version Detection<br />

<strong>PVS</strong> ID: 4552 FAMILY: Web Servers RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running Sun Java Calendar version: \n %L<br />

Solution: N/A<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 1189

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!