27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: The remote web server can be disabled remotely by sending a malformed HTTP request.<br />

An attacker may use this flaw to prevent the remote host from functioning properly.<br />

Solution: Upgrade to Abyss X1 v1.1.4 or higher.<br />

CVE-2003-1364<br />

mod_jk Chunked Encoding DoS<br />

<strong>PVS</strong> ID: 1571 FAMILY: Web Servers RISK: HIGH NESSUS ID:11519<br />

Description: The remote host is using a version of the Apache mod_jk module which is older than 1.2.1.<br />

There is a bug in this version which may allow an attacker to use chunked encoding<br />

requests to desynchronize Apache and Tomcat and therefore prevent this host from<br />

working properly.<br />

Solution: Upgrade to mod_jk 1.2.1 or higher.<br />

CVE-2002-2272<br />

AutomatedShops webc.cgi Multiple Overflows<br />

<strong>PVS</strong> ID: 1572 FAMILY: Web Servers RISK: HIGH NESSUS ID:11516<br />

Description: The remote host is running webc.cgi, a shopping cart application, which is older than 5.020.<br />

This CGI is vulnerable to a remote buffer overflow as well as a local one. An attacker may<br />

exploit this flaw to execute arbitrary code on this host.<br />

Solution: Upgrade to version 5.020 or higher.<br />

CVE Not available<br />

NETGEAR ProSafe Router Password Disclosure / Port Filtering Bypass<br />

<strong>PVS</strong> ID: 1573 FAMILY: Web Servers RISK: HIGH NESSUS ID:11514<br />

Description: The remote NETGEAR FM114P ProSafe Wireless router discloses the username and the<br />

password of the WAN when it receives specially crafted UPnP SOAP requests.<br />

Solution: Disable UPnP on this device.<br />

CVE Not available<br />

Ecartis User Password Reset Privilege Escalation<br />

<strong>PVS</strong> ID: 1574 FAMILY: Web Servers<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:11505<br />

Family Internet Services 404

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!