27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

RISK:<br />

MEDIUM<br />

Description: Synopsis :\n\nThe remote host is vulnerable to an HTML Injection attack\n\nThe remote<br />

host is running an older version of the Drupal Context module. Context is a module used to<br />

manage contextual conditions for different portions of the Drupal web site. The reported<br />

version ( %L ) is reported vulnerable to an HTML injection flaw wherein a remote attacker,<br />

with certain administrative rights, can insert HTML script code that would be executed<br />

within the browser of clients.<br />

Solution: Upgrade to Context version 6.x-2.0-rc4 or later<br />

CVE-2010-1584<br />

NETBIOS Domain/workgroup Detection<br />

<strong>PVS</strong> ID: 5533 FAMILY: Generic<br />

RISK: Risk<br />

not available<br />

NESSUS ID:Not Available<br />

Description: The remote host is a NETBIOS workstation which is a part of the following Domain or<br />

workgroup<br />

realtime<br />

Solution: N/A<br />

CVE Not available<br />

Samba < 3.5.2/3.4.8 Multiple DoS<br />

<strong>PVS</strong> ID: 5534 FAMILY: Samba RISK: HIGH NESSUS ID:46351<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Denial of Service (DoS)<br />

attack\n\nAccording to its banner, the version of Samba Server on the remote host is<br />

potentially affected by a flaw which would allow a remote attacker to disable the service.<br />

An attacker, exploiting this flaw, would need network access to the SAMBA server.<br />

Solution: upgrade to Samba 3.5.2 or 3.4.8<br />

CVE-2010-1642<br />

Movable Type < 5.02 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5535 FAMILY: CGI<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a cross-site scripting (XSS) attack\n\nThe<br />

remote host is running Movable Type, a blogging software for Unix and Windows<br />

platforms. The installed version is earlier than 5.02. Such versions are reportedly affected<br />

by a cross-site scripting flaw. An attacker, exploiting this flaw, would be able to post script<br />

code which would be executed in the browser of the blog readers.<br />

Family Internet Services 1482

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!