27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: The file viewcode.asp is a default IIS file that can give a malicious user information about<br />

your file system or source files. Specifically, viewcode.asp can allow a remote user to<br />

potentially read any file on a web server's hard drive.<br />

Solution: Delete the file if not needed or use suitable access control lists to ensure that the file is not<br />

world readable.<br />

CVE-1999-0737<br />

Microsoft IIS viewcode.asp Arbitrary File Access<br />

<strong>PVS</strong> ID: 1709 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:10576<br />

Description: The file viewcode.asp is a default IIS file that can give a malicious user information about<br />

your file system or source files. Specifically, viewcode.asp can allow a remote user to<br />

potentially read any file on a web server's hard drive.<br />

Solution: Delete the file if not needed or use suitable access control lists to ensure that the files are<br />

not world readable.<br />

CVE-1999-0737<br />

Microsoft IIS viewcode.asp Arbitrary File Access<br />

<strong>PVS</strong> ID: 1710 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:10576<br />

Description: The file viewcode.asp is a default IIS files that can give a malicious user information about<br />

your file system or source files. Specifically, viewcode.asp can allow a remote user to<br />

potentially read any file on a web server's hard drive.<br />

Solution: Delete the file if not needed or use suitable access control lists to ensure that the files are<br />

not accessible without credentials.<br />

CVE-1999-0737<br />

ION ion-p.exe Traversal File Access<br />

<strong>PVS</strong> ID: 1711 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:11729<br />

Description: The ion-p.exe file exists on this web server. Some versions of this file are vulnerable to<br />

remote exploit.<br />

Solution: No solution is known at this time.<br />

CVE-2002-1559<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Netdynamics ndcgi.exe Previous User Session Replay<br />

Family Internet Services 435

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!