27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Description: The remote host is running a version of PHP which is older than 3.0.17 or 4.0.3. If the<br />

option 'log_errors' is set to 'On' in php.ini, an attacker may use a bug present in this version<br />

to execute arbitrary commands on this host.<br />

Solution: Upgrade your installation of PHP to 3.0.17 or 4.0.3 or higher.<br />

CVE-2000-0967<br />

PHP < 4.2.3 Mail Function Header Spoofing<br />

<strong>PVS</strong> ID: 1481 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:11444<br />

Description: The remote web server is running a version of PHP which is 4.2.2 or older. This version<br />

has a bug in its mail() function which does not properly sanitize user input. As a result,<br />

users can forge email to make it look like it is coming from a different source that the<br />

server. The remote version of PHP is: \n %L<br />

Solution: Upgrade to PHP 4.2.3 or higher.<br />

CVE-2002-0985<br />

PHP < 4.0.4 php.cgi Shell Access Overflow<br />

<strong>PVS</strong> ID: 1482 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: The remote host seems to be running PHP as a standby application (php.cgi). Due to<br />

security bugs and performance issues, you should compile it as a module for your web<br />

server.<br />

Solution: Upgrade to version 4.0.4 or higher.<br />

CVE-1999-0058<br />

PHP < 4.1.0 Safe Mode Mail Function Command Execution<br />

<strong>PVS</strong> ID: 1483 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:12307<br />

Description: The remote host is running PHP 4.0.5. There is a flaw in this version which allows local<br />

users to circumvent the safe mode and gain the UID of the HTTP process.<br />

Solution: Upgrade to PHP 4.1.0<br />

CVE-2001-1246<br />

PHP < 4.3.2 Multiple Function Remote Overflows<br />

<strong>PVS</strong> ID: 1484 FAMILY: Web Servers<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:11468<br />

Family Internet Services 382

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!