27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Solution: Upgrade to RT 3.6.9 / 3.8.5<br />

CVE Not available<br />

PHP < 5.2.11 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5178 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:41014<br />

Description: Synopsis : \n\nThe remote web server uses a version of PHP that is affected by multiple<br />

vulnerabilities.\n\nAccording to its banner, the version of PHP installed on the remote host<br />

is earlier than 5.2.11. Such versions are reportedly affected by multiple issues : \n\n - An<br />

unspecified error occurs in certificate validation inside<br />

'php_openssl_apply_verification_policy'.\n\n - An unspecified input validation<br />

vulnerability affects the color index in 'imagecolortransparent()'.\n\n - A denial-of-service<br />

vulnerability related to 'popen' when invalid modes are used. (Bug 44683)\n\nFor your<br />

information, the reported version of PHP is: \n %L<br />

Solution: Upgrade to PHP version 5.2.11 or later.<br />

CVE-2009-5016<br />

MyBB < 1.4.9 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5179 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis : \n\nThe remote web server is running a PHP application that is vulnerable to<br />

multiple attack vectors.\n\nThe remote web server is running a version of MyBB earlier<br />

than 1.4.9. Such versions are potentially affected by multiple issues : \n\n - A SQL injection<br />

vulnerability in avatar extension checking and validating. (Bug 464)\n\n - It is possible to<br />

copy another users name and put a zero-width space somewhere in it. (Bug 418)\n\nFor<br />

your information, the reported version of MyBB is: \n %L<br />

Solution: Upgrade to MyBB 1.4.9 or later.<br />

CVE Not available<br />

Interchange Search Request Information Disclosure<br />

<strong>PVS</strong> ID: 5180 FAMILY: CGI<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:41056<br />

Description: Synopsis : \n\nThe remote web server is affected by an information-disclosure<br />

vulnerability.\n\nThe remote web server is running Interchange, a web-based application<br />

server. The installed version is potentially affected by an information disclosure<br />

vulnerability. It is possible to remotely query any table configured withing Interchange by<br />

using a specially crafted search request because the application fails to limit which tables<br />

can be searched on. For your information, the reported version of Interchange is: \n %L<br />

Family Internet Services 1378

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!