27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CVE Not available<br />

Awstats Web Statistics Server Detection<br />

<strong>PVS</strong> ID: 2504 FAMILY: Web Servers RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host may give an attacker information useful for future<br />

attacks.\n\nThe remote web server is running the awstats statistics program. Awstats parses<br />

the web logs and gives a potential attacker information regarding hosts that have accessed<br />

the server, resources accessed, total statistics for the Web server, version of Web server,<br />

and more.<br />

Solution: Use ACLs to protect the awstats report.<br />

CVE Not available<br />

Exim < 4.44 Illegal IPv6 Address / SPA Authentication Buffer Overflow<br />

<strong>PVS</strong> ID: 2505 FAMILY: SMTP Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote host is<br />

running Exim, a message transfer agent (SMTP). It is reported that Exim is prone to an<br />

IPv6 address and a SPA authentication buffer overflow . An attacker exploiting those flaws<br />

may be able to execute arbitrary code on the remote host. Exim must be configured with<br />

SPA Authentication or with IPv6 support to exploit those flaws.<br />

Solution: Upgrade to version 4.44 or higher.<br />

CVE-2005-0022<br />

Webalizer Report Information Disclosure<br />

<strong>PVS</strong> ID: 2506 FAMILY: Web Servers RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host may give an attacker information useful for future<br />

attacks.\n\nThe remote host is running the Webalizer Report generator. Webalizer parses<br />

web logs and gives a potential attacker information regarding hosts that have accessed the<br />

server, resources accessed, total statistics for the Web server, version of Web server, and<br />

more.\nThe version of Webalizer is: %L<br />

Solution: Use ACLs to protect the Webalizer report.<br />

CVE Not available<br />

osCommerce Admin Interface Detection<br />

<strong>PVS</strong> ID: 2507 FAMILY: Web Servers<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Family Internet Services 637

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!