27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Solution: Install Opera 7.54u1 or higher.<br />

CVE-2004-1490<br />

Netscape < 7.2 Cross-domain Window Injection<br />

<strong>PVS</strong> ID: 2468 FAMILY: Web Clients RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote browser allows attackers to spoof popup windows.\n\nThe<br />

remote host is using the Netscape 7 web browser. There is a flaw in this version of<br />

Netscape browser that allows an attacker to spoof popup windows from trusted hosts. An<br />

attacker exploiting this flaw would need to be able to entice a user to browse a malicious<br />

website while browsing a trusted site in another browser window. These sort of attacks are<br />

commonly referred to as 'Phishing' attacks. \nThe remote host is running Netscape version<br />

%L<br />

Solution: Upgrade to Netscape 7.2 or higher.<br />

Retina REM Detection<br />

CVE-2004-1160<br />

<strong>PVS</strong> ID: 2469 FAMILY: Policy RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is running software that should be authorized with respect to<br />

corporate policy.\n\nThe remote host is running the EEYE REM server. This server is used<br />

to manage multiple EEYE Retina scanners. The presence of this server indicates that a<br />

group is scanning the network for vulnerabilities. \nThe version of the REM server is %L<br />

Solution: Ensure that these servers are authorized for your network.<br />

CVE Not available<br />

CVSTrac < 1.1.5 Unspecified XSS<br />

<strong>PVS</strong> ID: 2470 FAMILY: CGI RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Cross-Site Scripting (XSS) attack.\n\nThe<br />

remote host is using the CVSTrac, a tool to browse CVS repositories.\nAccording to its<br />

version number, the remote version of this software is vulnerable to an unspecified<br />

cross-site scripting vulnerability.<br />

Solution: Upgrade to version 1.1.5 or higher.<br />

CVE-2004-1146<br />

GREED Multiple Remote Vulnerabilities<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 2471 FAMILY: Web Clients RISK: HIGH NESSUS ID:Not Available<br />

Family Internet Services 627

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!