27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Multiple SQL-injection vulnerabilities in the 'Test Case ID' field of the<br />

'/lib/general/navBar.php' script, and the 'logLevel' parameter of the<br />

'/lib/events/eventviewer.php' script.\n\nFor your information, the observed version of<br />

TestLink is: \n %L<br />

Solution: Upgrade to TestLink 1.8.5 or later.<br />

CVE-2009-4238<br />

MySQL < 5.0.88 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5259 FAMILY: Database<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:42899<br />

Description: Synopsis : \n\nThe remote database server is vulnerable to multiple attack vectors.\n\nThe<br />

remote host is running MySQL Community server < 5.0.88. Such versions are potentially<br />

affected by multiple issues : \n\n - MySQL clients linked against OpenSSL are vulnerable<br />

to man-in-the-middle attacks. (Bug #47320)\n\n - The GeomFromWKB() function can be<br />

manipulated to cause a denial of service. (Bug #47780)\n\n - Specially crafted SELECT<br />

statements containing sub-queries in the WHERE clause can cause the server to crash. (Bug<br />

48291)\n\nFor your information, the observed version of MySQL is: \n %L<br />

Solution: Upgrade to MySQL Community server 5.0.88 or later.<br />

CVE-2009-4019<br />

Invision Power Board < 3.0.5 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5260 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:43163<br />

Description: Synopsis : \n\nThe remote host is vulnerable to multiple attack vectors.\n\nThe remote host<br />

is running Invision Power Board, a PHP bulletin board application. The installed version of<br />

Invision Power Board is potentially affected by multiple vulnerabilities : \n\n - A local-file<br />

include vulnerability that affects the 'section' parameter sent to the 'forum/index.php'<br />

script.\n\n - A sql-injection vulnerability that affects the 'starter' and 'state' parameters of the<br />

'admin/applications/forum/modules_public/moderate/moderate.php' script.\n\n - A<br />

cross-site scripting vulnerability caused by incorrect handling of '.txt' file<br />

attachments.\n\nFor your information, the observed version of Invision Power Board is: \n<br />

%L<br />

Solution: Upgrade to Invision Power Board 3.0.5 or later.<br />

CVE Not available<br />

PostgreSQL < 8.4.2/8.3.9/8.2.15/8.1.19/8.0.23/7.4.27 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5261 FAMILY: Database<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Family Internet Services 1404

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!