27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: Synopsis :\n\nThe remote host is vulnerable to a flaw that allows attackers to retrieve<br />

sensitive files or data.\n\nThe remote host is running a vulnerable version of Acme<br />

mini_httpd. It is reported that versions prior 1.16 are prone to an issue that may<br />

permit an attacker to access arbitrary files on the vulnerable web server.<br />

Solution: Upgrade to mini_httpd 1.16 or higher.<br />

CVE Not available<br />

thttpd < 2.21 Error Page XSS<br />

<strong>PVS</strong> ID: 2123 FAMILY: Web Servers RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis : \n\nThe remote host is vulnerable to a Cross-Site Scripting (XSS) attack.\n\nThe<br />

remote host is running a vulnerable version of Acme thttpd. It is reported that this version<br />

of thttpd fails to check URLs for the presence of script commands when generating error<br />

pages. An attacker may craft links containing scripting code in order to execute code within<br />

the context of the website. The version of the remote thttpd server is: \n %L<br />

Solution: Upgrade to thttpd 2.21 or higher.<br />

CVE-2002-0733<br />

thttpd/mini_httpd Virtual Hosting File Disclosure<br />

<strong>PVS</strong> ID: 2124 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a flaw that allows attackers to retrieve<br />

sensitive files or data.\n\nThe remote host is running a vulnerable version of Acme<br />

mini_httpd. It is reported that versions prior 1.18 are prone to an issue that may permit an<br />

attacker to access arbitrary files on the vulnerable web server when virtual hosting is<br />

enabled. In a chrooted environment, this may only disclose directories under the chroot.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE-2003-0899<br />

thttpd/mini_httpd < 2.24 Virtual Hosting File Disclosure<br />

<strong>PVS</strong> ID: 2125 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a flaw that allows attackers to retrieve<br />

sensitive files or data.\n\nThe remote host is running a vulnerable version of Acme thttpd.<br />

It is reported that versions prior 2.24 are prone to an issue that may permit an attacker to<br />

access arbitrary files on the vulnerable web server when virtual hosting is enabled. In a<br />

chrooted environment, this may only disclose directories under the chroot.<br />

Solution: Upgrade to version 2.24 or higher.<br />

CVE-2003-0899<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 529

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!