27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Description: The remote host is running a NetCharts server with the default login and password<br />

(Admin/Admin).<br />

Solution: Change the default password.<br />

CVE Not available<br />

12Planet Chat Server Path Disclosure<br />

<strong>PVS</strong> ID: 1542 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:11592<br />

Description: The remote host is running 12Planet Chat Server, a web based chat server written in Java.<br />

There is a flaw in this software that may allow an attacker to obtain the physical path of the<br />

installation of the remote server by sending a malformed request to this service.<br />

Solution: None solution is known at this time.<br />

CVE Not available<br />

12Planet Chat Server ClearText Password Remote Disclosure<br />

<strong>PVS</strong> ID: 1543 FAMILY: CGI RISK: LOW NESSUS ID:11591<br />

Description: The remote host is running 12Planet Chat Server over an unencrypted channel. An attacker<br />

who can sniff traffic on this network may use this configuration issue to obtain the<br />

password of the administrator of this site and use it to take control.<br />

Solution: No solution is known at this time.<br />

CVE Not available<br />

JetDB Direct Request Database Download<br />

<strong>PVS</strong> ID: 1544 FAMILY: Web Servers RISK: LOW NESSUS ID:Not Available<br />

Description: The following request was used to download a JetDB database over HTTP : %P<br />

Solution: Ensure that proper permissions are set on this file.<br />

CVE Not available<br />

YaBB SE < 1.5.2 Remote File Inclusion and SQL Injection<br />

<strong>PVS</strong> ID: 1545 FAMILY: Web Servers<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:11588<br />

Description: The remote host is running the YaBB SE forum management system. There is a flaw in this<br />

version which may allow an attacker to execute arbitrary commands on this host and to<br />

inject arbitrary values in the remote SQL database.<br />

Family Internet Services 397

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!