27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE-2000-0332<br />

YaBB YaBB.cgi num Parameter XSS<br />

<strong>PVS</strong> ID: 1638 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: The YaBB.cgi file exists on this web server. Some versions of the YaBB installation are<br />

vulnerable to a cross-site scripting vulnerability.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE-2002-0955<br />

Drummond Miles A1Statistics a1disp4.cgi Traversal Arbitrary File Read<br />

<strong>PVS</strong> ID: 1639 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: The Drummond Miles A1Statistics a1disp4.cgi file exists on this web server. Some<br />

versions of this file are vulnerable to a remote traversal attack that allows read access to<br />

arbitrary files.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE-2001-0561<br />

Cobalt RAQ alert.cgi XSS<br />

<strong>PVS</strong> ID: 1640 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: The alert.cgi file exists on this web server. Some versions of this file are vulnerable to a<br />

cross-site scripting exploit.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE-2002-0346<br />

Aplio Internet Phone authenticate.cgi Arbitrary Command Execution<br />

<strong>PVS</strong> ID: 1641 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: The authenticate.cgi script exists on this web server. Some versions of this file may allow a<br />

remote attacker to execute arbitrary commands on the host with the same privileges as the<br />

web server.<br />

Solution: Update or patch according to vendor recommendations.<br />

CVE-2000-0923<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Extropia WebBBS bbs_forum.cgi Remote Command Execution<br />

Family Internet Services 419

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!