27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

BNC IRC Server < 2.9.1 Authentication Bypass<br />

<strong>PVS</strong> ID: 2404 FAMILY: IRC Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a flaw that allows for the<br />

bypassing of authentication.\n\nThe remote host is running a version of BNC,<br />

an IRC proxy, that is vulnerable to an authentication bypass vulnerability. An<br />

attacker may use this issue to access the remote IRC proxy server.<br />

Solution: Upgrade to version 2.9.1 or higher.<br />

CVE-2004-2612<br />

Skype < 1.0.0.100 CallTo URI Buffer Remote Overflow<br />

<strong>PVS</strong> ID: 2405 FAMILY: Internet Messengers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote host is<br />

using Skype, a peer to peer chat and VoIP software. The remote version of this software<br />

contains a security issue that may allow an attacker to execute code on the remote<br />

host.\nAn attacker needs to send a malicious URI to the user to exploit this flaw.<br />

Solution: Upgrade to Skype 1.0.0.100 or higher.<br />

Skype Detection (Host)<br />

CVE-2004-1114<br />

<strong>PVS</strong> ID: 2406 FAMILY: Internet Messengers RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is running software that should be authorized with respect to<br />

corporate policy\n\nThe remote host is using the Skype program, a peer to peer chat and<br />

VoIP software.<br />

Solution: Ensure that the use of this software is in accordance with organizational security policies.<br />

CVE Not available<br />

miniBB < 1.7f index.php user Parameter SQL Injection<br />

<strong>PVS</strong> ID: 2407 FAMILY: CGI RISK: HIGH NESSUS ID:15763<br />

Description: Synopsis :\n\nThe remote web server contains a script that is vulnerable to a SQL injection<br />

attack.\n\nThe remote host is using the miniBB forum management system.\nAccording to<br />

its version number, this forum is vulnerable to a SQL injection attack that may allow an<br />

attacker to execute arbitrary SQL statements against the remote database.<br />

Solution: Upgrade to miniBB 1.7f or higher.<br />

CVE-2004-2456<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 609

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!