27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE-2004-1120<br />

AppServ Open Project Remote Insecure Default Password<br />

<strong>PVS</strong> ID: 2429 FAMILY: Database<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is configured with default or easily-guessed<br />

credentials.\n\nThe remote MySQL server appears to allow connections as root without a<br />

password. AppServ Open Project, an installation utility for APACHE/PHP/MySQL under<br />

Windows, creates a passwordless database by default. Anyone can log into the database and<br />

change data or increase their privileges.<br />

Solution: Connect to the remote MySQL database and set a password.<br />

CVE-2004-1532<br />

Alt-N MDaemon File Creation Local Privilege Escalation<br />

<strong>PVS</strong> ID: 2430 FAMILY: SMTP Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a local buffer overflow.\n\nThe remote host<br />

is running ALT-N MDaemon, a mail server for Microsft Windows. There is a local<br />

privilege escalation vulnerability in the remote version of this software that may allow a<br />

local attacker to execute arbitrary code on the remote host with the SYSTEM privileges.<br />

Solution: No solution is known at this time.<br />

CVE-2004-2504<br />

Brooky CubeCart < 2.0.2 index.php cat_id Parameter SQL Injection<br />

<strong>PVS</strong> ID: 2431 FAMILY: CGI RISK: HIGH NESSUS ID:15442<br />

Description: Synopsis :\n\nThe remote web server contains a script that is vulnerable to a SQL injection<br />

attack.\n\nThe remote host is using Brooky CubeCart, an online storefront application<br />

written in PHP. A vulnerability exists in the remote version of this product that may allow a<br />

remote attacker to perform a SQL injection attack against the remote host. An attacker may<br />

exploit this flaw to execute arbitrary SQL statements against the remote database and<br />

possibly execute arbitrary commands on the remote host.<br />

Solution: Upgrade to Brooky CubeCart 2.0.2 or higher.<br />

CVE-2004-1580<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Youngzsoft CMailServer < 5.2.1 Multiple Remote Vulnerabilities<br />

<strong>PVS</strong> ID: 2432 FAMILY: SMTP Servers RISK: HIGH NESSUS ID:Not Available<br />

Family Internet Services 616

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!