27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Solution: Upgrade to PHP 5.0.3 or 4.3.10 or higher.<br />

CVE-2004-1065<br />

IBM WebSphere Commerce Database Update Default User Information Disclosure<br />

<strong>PVS</strong> ID: 2461 FAMILY: Web Servers RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a flaw that allows attackers to retrieve<br />

sensitive files or data.\n\nThe remote WebSphere webserver is vulnerable to an<br />

information leak. User information is sometimes stored under the profile of the<br />

'default' user. Unintended users may gain access to this information and use the<br />

information to elevate privileges on the remote machine. It is also possible that the<br />

default user account may disclose information regarding other users.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE Not available<br />

Ikonboard < 3.1.3 ikonboard.cgi Multiple Parameter SQL Injection<br />

<strong>PVS</strong> ID: 2462 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote web server contains a script that is vulnerable to a SQL injection<br />

attack.\n\nThe remote host appears to be running Ikonboard, a bulletin board service<br />

implemented in Perl. This version is reported vulnerable to a SQL injection vulnerability.<br />

An attacker may gain access to unauthorized information or may steal authentication<br />

credentials by sending malformed string to ikonboard.cgi.<br />

Solution: Upgrade to Ikonboard 3.1.3 or higher.<br />

CVE-2004-1406<br />

Samba < 3.0.10 Directory Access Control List Remote Integer Overflow<br />

<strong>PVS</strong> ID: 2463 FAMILY: Samba<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a remote overflow.\n\nThe remote Samba<br />

server, according to its version number ('%L'), may be vulnerable to a remote buffer<br />

overflow.\nThe remote integer overflow vulnerability may allow an attacker to execute<br />

code on the server.\n An attacker needs access to a vulnerable share to exploit this issue.<br />

Solution: Upgrade to Samba 3.0.10 or higher.<br />

CVE-2004-1154<br />

JSBoard Remote Arbitrary Script Upload<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 2464 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Family Internet Services 625

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!