27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CVE-2009-3231<br />

Horde < 3.3.4 / 3.3.5 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5171 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis : \n\nThe remote web server contains a PHP application that is vulnerable to<br />

multiple attack vectors.\n\nThe version of Horde, Horde Groupware, or Horde Groupware<br />

Webmail Edition installed on the remote host is potentially affected by multiple issues :<br />

\n\n - A vulnerability in the form library that allows the overwriting of arbitrary local files,<br />

subject to the permissions of the web server user. This issue occurs only when the<br />

application uses image form fields such as Turba H3 or Ansel.\n\n - Two cross-site<br />

scripting vulnerabilities in the preference system and the MIME viewer library.\n\nFor your<br />

information, the installed version of Horde is: \n %L<br />

Solution: Upgrade to Horde version 3.2.5 / 3.3.5 or later.<br />

Aria2 Detection<br />

CVE Not available<br />

<strong>PVS</strong> ID: 5172 FAMILY: Web Clients RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running aria2, a client application used to download files via a number<br />

of protocols.<br />

Solution: N/A<br />

CVE Not available<br />

nginx Webserver Detection<br />

<strong>PVS</strong> ID: 5173 FAMILY: Web Servers RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running nginx web server.<br />

Solution: N/A<br />

CVE Not available<br />

nginx HTTP Request Remote Buffer Overflow<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 5174 FAMILY: Web Servers RISK: HIGH NESSUS ID:41608<br />

Description: Synopsis : \n\nThe remote web server is affected by a remote buffer overflow<br />

vulnerability.\n\nThe remote host is running a version of nginx web server that is<br />

potentially affected by a remote buffer overflow vulnerability. Using a specially crafted<br />

HTTP request, an attacker can cause web server to crash, or potentially run arbitrary code<br />

subject to the privileges of the web server user.\n\nFor your information, the reported<br />

Family Internet Services 1376

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!