27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CVE Not available<br />

Sympa < 4.1.3 List Creation Description Field XSS<br />

<strong>PVS</strong> ID: 2119 FAMILY: CGI RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Cross-Site Scripting (XSS) attack.\n\nThe<br />

remote host is running wwsympa.fcgi, a web interface for the Sympa mailing list manager.<br />

It is reported that this version of Sympa may permit an attacker to inject malicious HTML<br />

in "List Info" page through the description field of the list creation form. This field is not<br />

sanitized properly by the CGI.<br />

Solution: Upgrade to version 4.1.3 or higher.<br />

CVE-2004-1735<br />

thttpd < 2.20 Arbitrary World-Readable File Disclosure<br />

<strong>PVS</strong> ID: 2120 FAMILY: Web Servers RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a flaw that allows attackers to retrieve<br />

sensitive files or data\n\nThe remote host is running a vulnerable version of Acme thttpd.<br />

This web server includes a CGI program to provide server-side-includes functionalities. It<br />

is reported that this CGI program does not properly filter certain escape sequences. An<br />

attacker may view arbitrary files in a known location on the web server.<br />

Solution: Upgrade to thttpd 2.20 or higher.<br />

CVE-2000-0900<br />

THTTPD/Mini_HTTPD < 2.22 File Disclosure<br />

<strong>PVS</strong> ID: 2121 FAMILY: Web Servers RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis : \n\nThe remote host is vulnerable to a flaw that allows attackers to<br />

retrieve sensitive files or data.\n\nThe remote host is running a vulnerable version of<br />

Acme thttpd. It is reported that versions prior 2.22 are prone to an issue that may<br />

permit an attacker to access arbitrary files on the vulnerable web server. The version<br />

of the remote thttpd server is: \n %L<br />

Solution: Upgrade to thttpd 2.22 or higher.<br />

CVE Not available<br />

THTTPD/Mini_HTTPD < 1.16 File Disclosure<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 2122 FAMILY: Web Servers RISK: LOW NESSUS ID:Not Available<br />

Family Internet Services 528

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!