27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Solution: Upgrade to ESET update 4036 or higher.<br />

CVE Not available<br />

Citrix Web Interface 4.6/5.0/5.0.1 XSS<br />

<strong>PVS</strong> ID: 5010 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a cross-site scripting attack.\n\nThe remote<br />

host is running Citrix Web Interface, a tool for connecting to Citrix services through a web<br />

browser. The reported version of Citrix Web Interface is: \n%L\n\nThe version of Citrix<br />

Web Interface installed on the remote host is affected by an unspecfied cross-site scripting<br />

vulnerability. An attacker, exploiting this cross-site scripting flaw, would be able to execute<br />

script code within the browser of an unsuspecting Citrix Web Interface user.<br />

Solution: Upgrade to Citrix Web Interface 5.1.0 or later.<br />

CVE-2009-2454<br />

Flash Media < 3.0.4/3.5.2 Privilege Escalation<br />

<strong>PVS</strong> ID: 5011 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis : \n\nThe remote host is vulnerable to a remote 'privilege escalation' flaw\n\nThe<br />

remote host is running Flash Media server version: \n %L \n\nThis version of Flash Media<br />

server is vulnerable to a flaw wherein malicious script code can be injected and executed<br />

via an RPC call. An attacker, exploiting this flaw, would need access to the application port<br />

and the ability to send malformed requests to the service port. An attacker, exploiting this<br />

flaw, would be able to escalate privileges on the remote system.<br />

Solution: Adobe has released Flash Media Server versions 3.04 and 3.5.2 to address these flaws<br />

CVE-2009-1365<br />

MyBB < 1.4.6 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5012 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis : \n\nThe remote host is vulnerable to multiple attack vectors\n\nThe version of<br />

MyBB installed on the remote host is vulnerable to an html-injection flaw. An attacker,<br />

exploiting this flaw, would be able to execute script code within the browser of an<br />

unsuspecting user. Allegedly, the host is also vulnerable to several unspecified<br />

vulnerabilities. While the details are sketchy, the vendor has addressed the issue. The<br />

reported version of MyBB is: \n %L \n<br />

Solution: Upgrade to MyBB 1.4.6 or later.<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 1326

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!