27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Description: Synopsis :\n\nThe remote host is vulnerable to a flaw that allows attackers to retrieve<br />

sensitive files or data.\n\nThe remote host is running a version of MySQL that is older than<br />

version 3.23.49 or than 4.0.20. The version of the utility Mysqlhotcopy included in these<br />

versions of MySQL is reported to be prone to a vulnerability that may permit an attacker to<br />

overwrite arbitrary files on the database server with the privilege of the targeted user.<br />

Privilege escalation may also be possible. An attacker requires local interactive access in<br />

order to exploit this vulnerability.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE-2004-0457<br />

Opera getElementsByTagName Javascript Method DoS<br />

<strong>PVS</strong> ID: 2130 FAMILY: Web Clients<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Denial of Service (DoS)<br />

attack.\n\nThe remote host is using a version of Opera that is affected by a security<br />

weakness that may permit an attacker to crash the remote web browser using<br />

Javascript.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

SQL Server Detection<br />

CVE Not available<br />

<strong>PVS</strong> ID: 2131 FAMILY: Database<br />

Description: Detects SQL servers on port 1433<br />

Solution: N/A<br />

CVE Not available<br />

eGroupWare < 1.0.0.004 Multiple XSS<br />

RISK: Risk<br />

not available<br />

NESSUS ID:Not Available<br />

<strong>PVS</strong> ID: 2132 FAMILY: CGI RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Cross-Site Scripting (XSS) attack.\n\nThe<br />

remote host is running eGroupWare, a web-based groupware solution. It is reported that<br />

versions prior 1.0.0.004 are prone to a cross-site scripting issue. An attacker may steal<br />

cookie-based authentication credentials from a legitimate user by sending malformed links<br />

to this web site.<br />

Solution: Upgrade to version 1.0.0.004 or higher.<br />

CVE-2004-1467<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 531

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!