27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>PVS</strong> ID: 2415 FAMILY: CGI RISK: HIGH NESSUS ID:15784<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a SQL Injection attack.\n\nThe remote host<br />

is running PHP-Kit, an open-source content management system written in PHP.\nThe<br />

remote version of this software is vulnerable to multiple flaws that may allow an attacker to<br />

execute arbitrary SQL statements against the remote database or to perform a cross-site<br />

scripting attack.<br />

Solution: Upgrade to PHPKit 1.6.04 or higher.<br />

CVE-2006-1773<br />

phpMyAdmin Detection<br />

<strong>PVS</strong> ID: 2416 FAMILY: CGI RISK: LOW NESSUS ID:Not Available<br />

Description: The remote host is running phpMyAdmin, an open-source software written in PHP to<br />

handle the administration of MySQL over the Web.\nThe remote host is running<br />

phpMyAdmin %L.<br />

Solution: N/A<br />

CVE Not available<br />

phpMyAdmin < 2.6.0-p13 Multiple XSS<br />

<strong>PVS</strong> ID: 2417 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:15770<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Cross-Site Scripting (XSS) attack.\n\nThe<br />

remote host is running phpMyAdmin, an open-source software written in PHP to handle the<br />

administration of MySQL over the Web.\nThis version is vulnerable to cross-site scripting<br />

attacks through multiple scripts.\n\n With a specially crafted URL, an attacker may use the<br />

remote host to perform a cross site scripting attack.<br />

Solution: Upgrade to phpMyAdmin 2.6.0-pl3 or higher.<br />

CVE-2004-1055<br />

phpMyAdmin sql.php Traversal Arbitrary File Access<br />

<strong>PVS</strong> ID: 2418 FAMILY: CGI<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:11116<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a flaw that allows attackers to retrieve<br />

sensitive files or data.\n\nThe remote host is running phpMyAdmin, an open-source<br />

software written in PHP to handle the administration of MySQL over the Web.\nIt is<br />

possible to make the remote phpMyAdmin installation read arbitrary data on the remote<br />

host by using a malformed URL.\nAn attacker may use this flaw to read /etc/passwd or any<br />

file that the web server has the right to access.<br />

Family Internet Services 612

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!