27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>PVS</strong> ID: 1642 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: The bbs_forum.cgi script exists on this web server. Some versions of this file may allow a<br />

remote attacker to execute arbitrary commands with the same privileges as the web server.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE-2001-0123<br />

BNBForm bnbform.cgi Automessage Arbitrary File Retrieval<br />

<strong>PVS</strong> ID: 1643 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: The bnbform.cgi script exists on this web server. Some versions of this file may<br />

allow an attacker to access arbitrary files on the server.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE-1999-0937<br />

bsguest.cgi Guestbook Email Address Variable Arbitrary Command Execution<br />

<strong>PVS</strong> ID: 1644 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: The bsguest.cgi script exists on this web server. Some versions of this file may allow a<br />

remote attacker to execute arbitrary commands with the same privileges as the web server.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE-2001-0099<br />

bslist.cgi Email Address Variable Arbitrary Command Execution<br />

<strong>PVS</strong> ID: 1645 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: The bslist.cgi script exists on this web server. Some versions of this file may allow a<br />

remote attacker to execute arbitrary commands with the same privileges as the web server.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE-2001-0100<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Aktivate Shopping System catgy.cgi desc Parameter XSS<br />

<strong>PVS</strong> ID: 1646 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: The catgy.cgi script exists on this web server. Some versions of this file are vulnerable to a<br />

cross-site scripting vulnerability.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

Family Internet Services 420

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!