27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: The remote server is running the admin interface of osCommerce. OsCommerce is an<br />

application for deploying and managing e-commerce servers.<br />

Solution: Ensure that only valid Administrators can access the Admin interface. Also ensure<br />

that you are running the latest version of osCommerce.<br />

CVE Not available<br />

Terminal Services Web Detection<br />

<strong>PVS</strong> ID: 2508 FAMILY: Web Servers RISK: NONE NESSUS ID:12234<br />

Description: Synopsis :\n\nThe remote host may give an attacker information useful for future<br />

attacks.\n\nThe remote host appears to be configured to facilitate the client download of an<br />

ActiveX Terminal Services Client. Users can access the web page and click a 'connect'<br />

button that will prompt a client-side download of a .cab file that will be used to connect the<br />

client directly to a terminal services server using Remote Desktop Protocol -- RDP. You<br />

will want to manually inspect this page for possible information regarding systems offering<br />

RDP access, system information, IP addressing information, and more.<br />

Solution: Password protect access to the 'tsweb' resource.<br />

CVE Not available<br />

Nessus Scan Report Disclosure<br />

<strong>PVS</strong> ID: 2509 FAMILY: Web Servers RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host may give an attacker information useful for future<br />

attacks.\n\nThe remote web server is hosting a Nessus scan report at the following location<br />

: \n%P\nAn anonymous user reading this report will be able to obtain information useful in<br />

attacking vulnerable hosts on the network.<br />

Solution: Remove or protect the scan report data.<br />

CVE Not available<br />

ISS Scan Report Disclosure<br />

<strong>PVS</strong> ID: 2510 FAMILY: Web Servers RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host may give an attacker information useful for future<br />

attacks.\n\nThe remote web server is hosting an ISS scan report at the following URL :<br />

\n%P\nAn anonymous user reading this report will be able to obtain information useful in<br />

attacking vulnerable hosts on the network.<br />

Solution: Remove or protect the scan report data.<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 638

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!