27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Solution: Upgrade to Powie PHP Forum 1.15 or higher.<br />

CVE-2002-0319<br />

Sympa < 4.1.2 List Creation Authentication Bypass<br />

<strong>PVS</strong> ID: 1733 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: The remote host is running wwsympa.fcgi, a web interface for the Sympa mailing list<br />

manager. It is reported that this version of Sympa may permit an attacker to bypass the list<br />

master authentication in order to create unauthorized mailing list.<br />

Solution: Upgrade to version 4.1.2 or higher.<br />

HTTP Proxy Detection<br />

CVE Not available<br />

<strong>PVS</strong> ID: 1734 FAMILY: Web Clients RISK: NONE NESSUS ID:Not Available<br />

Description: The remote host is a proxy server. <strong>PVS</strong> has determined this due to the manner of header<br />

values: \n%L<br />

Solution: N/A<br />

Web Client Detection<br />

CVE Not available<br />

<strong>PVS</strong> ID: 1735 FAMILY: Web Clients RISK: NONE NESSUS ID:Not Available<br />

Description: The remote host is using the following web client : \n %L<br />

Solution: N/A<br />

CVE Not available<br />

Lynx Command Line URL CRLF Injection<br />

<strong>PVS</strong> ID: 1736 FAMILY: Web Clients RISK: LOW NESSUS ID:Not Available<br />

Description: The remote host is using Lynx as a web browser. The version used is vulnerable to a<br />

command line header injection which may allow an attacker to use Lynx to send potentially<br />

harmful requests. An attacker may use this flaw to attack third party hosts even from a<br />

limited (ie: lynx-only) environment. The version used on the remote host is : \n%L<br />

Solution: No solution is known at this time.<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 441

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!