27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Description: The remote host is running a version of PHP which is older than 4.2.2. This version has a<br />

bug which allows an attacker to disable the remote server or execute arbitrary code on it.<br />

Solution: Upgrade to PHP 4.2.2 or downgrade to 4.1.x<br />

CVE-2002-0986<br />

PHP < 4.3.1 CGI Module File Access<br />

<strong>PVS</strong> ID: 1477 FAMILY: Web Servers RISK: HIGH NESSUS ID:11237<br />

Description: The remote host is running PHP 4.3.0 which contains a flaw which may let anyone execute<br />

arbitrary PHP code on this host.<br />

Solution: Upgrade to PHP 4.3.1 or higher.<br />

CVE-2003-0097<br />

PHP < 3.0.17 / 4.0.3 Hidden Form Field File Upload<br />

<strong>PVS</strong> ID: 1478 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:10513<br />

Description: The remote host is running a version of PHP which is older than 3.0.17 or 4.0.3. If a PHP<br />

script that allows users to upload files and then display their content is running on this host,<br />

an attacker may use it to read arbitrary files.<br />

Solution: Upgrade to PHP 3.0.17 or 4.0.3 or higher.<br />

CVE-2000-0860<br />

PHP < 4.0.4 IMAP Module Overflow<br />

<strong>PVS</strong> ID: 1479 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:10628<br />

Description: The remote host is running a version of PHP which is older than 4.0.4. There is a buffer<br />

overflow in the IMAP module of this version which may allow an attacker to execute<br />

arbitrary commands with the privileges of the web server if a PHP script connects to a<br />

rogue IMAP server.<br />

Solution: Upgrade to PHP 4.0.4<br />

CVE Not available<br />

PHP < 3.0.17 / 4.0.3 Error Log Command Injection<br />

<strong>PVS</strong> ID: 1480 FAMILY: Web Servers<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:10535<br />

Family Internet Services 381

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!