27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

unspecified error allows XMLHttpRequests to directories. (20450)\n\n - An unspecified<br />

error exists related to escaping characters in shortcuts. (23693)\n\n - Renderer memory<br />

error exist when drawing on canvases. (8864, 24701, 24646)\n\n - An image decoding<br />

memory error. (28566)\n\n - An unspecified error exists, which may result in failure to strip<br />

'Referer'. (29920)\n\n - An unspecified cross-domain access error. (30660)\n\n - An<br />

unspecified bitmap deserialization error. (31307)\n\n - An unspecified browser crash<br />

related to nested URLs. (31517)\n\nFor your information, the observed version of Google<br />

Chrome is: \n %L<br />

Solution: Upgrade to Google Chrome 4.0.249.78 or later.<br />

CVE-2010-0664<br />

SilverStripe < 2.3.5 Cross-site Scripting Vulnerability<br />

<strong>PVS</strong> ID: 5329 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:44332<br />

Description: Synopsis : \n\nThe remote web server is hosting an application that is vulnerable to a<br />

cross-site scripting attack.\n\nThe remote web server is hosting SilverStripe CMS. The<br />

installed version of SilverStripe is earlier than 2.3.5. Such versions are potentially affected<br />

by a persistent cross-site scripting vulnerability becase the application fails to properly<br />

sanitize user-supplied input to the 'CommenterURL' parameter in the comment posting<br />

mechanism. An attacker could exploit this flaw in order to execute arbitrary script code in a<br />

user's browser. For your information, the observed version of SilverStripe is: \n %L<br />

Solution: Upgrade to SilverStripe 2.3.5 or later.<br />

CVE-2010-1593<br />

Symantec Altiris Notification Server 6.0 < SP3 R12 Static Encryption Key<br />

<strong>PVS</strong> ID: 5330 FAMILY: CGI RISK: HIGH NESSUS ID:44339<br />

Description: Synopsis : \n\nThe remote host is vulnerable to an information disclosure<br />

vulnerability.\n\nThe remote host is running Symantec Altiris Notification Server 6.0<br />

earlier than SP3 R12. Such versions are potentially affected by a local information<br />

disclosure vulnerability because the application uses a static encryption key for encrypted<br />

credentials entered by the administrator. An attacker, exploiting this flaw, could view<br />

unauthorized information or possibly execute code. For your information, the observed<br />

version of Symantec Altiris Notification Server is: \n %L<br />

Solution: Upgrade to Altiris Notification Server 6.0 SP3 R12 or later.<br />

CVE-2009-3035<br />

Bugzilla < 3.0.11 / 3.2.6 / 3.4.5 / 3.5.3 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5331 FAMILY: CGI<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:44426<br />

Family Internet Services 1426

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!