27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE-2004-1103<br />

IceWarp Web Mail < 5.3.1 Multiple Vulnerabilities (2)<br />

<strong>PVS</strong> ID: 2387 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:15643<br />

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack vectors.\n\nThe remote host<br />

is running IceWarp Web Mail, a webmail solution available for the Microsoft Windows<br />

platform.\n\nThe remote version of this software is vulnerable to multiple input validation<br />

issues that may allow an attacker to compromise the integrity of the remote host.<br />

Solution: Upgrade to IceWarp Web Mail 5.3.1 or higher.<br />

CVE Not available<br />

Moodle < 1.4.3 Glossary Module SQL Injection<br />

<strong>PVS</strong> ID: 2388 FAMILY: Web Servers RISK: HIGH NESSUS ID:15639<br />

Description: Synopsis :\n\nThe remote web server contains a script that is vulnerable to a SQL injection<br />

attack.\n\nThe remote host is running a version of the Moodle suite, an open-source course<br />

management system written in PHP, that is older than version 1.4.3.\nThe remote version<br />

of this software is vulnerable to a SQL injection issue in the 'glossary' module due to a lack<br />

of user input sanitization.<br />

Solution: Upgrade to Moodle 1.4.3 or higher.<br />

CVE-2004-1425<br />

Gallery < 1.4.4-p12 Unspecified HTML Injection<br />

<strong>PVS</strong> ID: 2389 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:15624<br />

Description: Synopsis :\n\nThe remote host is vulnerable to an HTML Injection attack.\n\nThe remote<br />

host is running the Gallery web-based photo album.\nThere is a flaw in the remote version<br />

of this software that may allow an attacker to inject arbitrary HTML tags in the remote web<br />

server.<br />

Solution: Upgrade to Gallery 1.4.4-pl2 or higher.<br />

CVE-2004-1106<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Helm Control Panel < 3.1.20 Multiple Input Validation Vulnerabilities<br />

<strong>PVS</strong> ID: 2390 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Family Internet Services 604

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!