27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Solution: Upgrade to YaBB SE 1.5.2 or higher.<br />

CVE-2002-1176<br />

XMB < 1.8 SP1 member.php SQL Injection<br />

<strong>PVS</strong> ID: 1546 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:11587<br />

Description: The remote host is running XMB Forum. There is flaw in the version this host is using<br />

which may allow an attacker to perform a SQL injection attack against this host.<br />

Solution: Upgrade to XMB 1.8 SP1 or higher.<br />

CVE Not available<br />

Sambar Cleartext Password Remote Disclosure<br />

<strong>PVS</strong> ID: 1547 FAMILY: Web Servers RISK: LOW NESSUS ID:11585<br />

Description: The remote Sambar server does not run on top of SSL, therefore passwords are transmitted<br />

in cleartext over HTTP. An attacker who can sniff network traffic may use this flaw to gain<br />

access on the web interface of this host.<br />

Solution: No solution is known at this time.<br />

CVE Not available<br />

TrueGalerie admin.php loggedin Parameter Admin Authentication Bypass<br />

<strong>PVS</strong> ID: 1548 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:11582<br />

Description: It is possible to gain administrative privileges on the remote TrueGallerie installation by<br />

requesting the URL '/admin.php?loggedin<br />

Solution: Disable the option 'register_globals' in php.ini.<br />

CVE-2003-1488<br />

album.pl < 6.2 Remote Command Execution<br />

<strong>PVS</strong> ID: 1549 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:11581<br />

Description: The remote host is running a version of the CGI 'album.pl' which may allow an attacker to<br />

execute arbitrary commands on this host.<br />

Solution: Upgrade to version 6.2 or higher.<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 398

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!