27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>PVS</strong> ID: 1444 FAMILY: Web Servers RISK: HIGH NESSUS ID:10447<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a flaw which allows for the bypassing of<br />

authentication.\n\nThe remote web server is running a version of Zope which is older than<br />

2.1.7. There is a security problem in all the releases older than 2.1.7 which may allow the<br />

content of DTMLDocuments (or DTMLMethods) to be changed by any user without<br />

authentication.<br />

Solution: Upgrade to Zope 2.1.7 or higher.<br />

CVE-2000-0483<br />

Zope < 2.2.5 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 1445 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:10702<br />

Description: Synopsis :\n\nThe remote web server contains an application server that fails to protect<br />

stored content from modification by remote users.\n\nAccording to its banner, the remote<br />

web server is Zope < 2.2.5. Such versions suffer from security issues involving incorrect<br />

protection of a data updating method on Image and File objects. Because the method is not<br />

correctly protected, it is possible for users with DTML editing privileges to update the raw<br />

data of a File or Image object via DTML even though they do not have editing privileges<br />

on the objects themselves.<br />

Solution: Upgrade to Zope 2.2.5 or higher.<br />

CVE-2000-0483<br />

Zope < 2.3.3 ZClass Permission Mapping Modification Local Privilege Escalation<br />

<strong>PVS</strong> ID: 1446 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:10777<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a flaw which allows for the bypassing of<br />

authentication.\n\nThe remote web server is a version of Zope which is older than 2.3.3.<br />

There is a security issue in all releases prior to version 2.3.3 which allow any user to visit a<br />

ZClass declaration and change its permission mappings for methods and other objects<br />

defined within the ZClass, possibly allowing unauthorized access within the Zope instance.<br />

Solution: Update to Zope 2.3.3 or higher.<br />

CVE-2001-0567<br />

Zeus < 3.3.5a Web Server Null Byte Request CGI Source Disclosure<br />

<strong>PVS</strong> ID: 1447 FAMILY: Web Servers<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:10327<br />

Family Internet Services 372

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!