27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: Synopsis :\n\nThe remote host is vulnerable to a cross-site scripting (XSS) attack.\n\nThe<br />

remote host is using a version of Konqueror that is prone to a security flaw where a<br />

malicious website can bypass the browser Java sandbox.\nAs a result, an attacker may be<br />

able to read arbitrary files on the remote host by luring a victim into visiting a rogue<br />

website hosting a malicious Java applet.<br />

Solution: Install Konqueror 3.3.2 or higher.<br />

CVE Not available<br />

iCab Web Browser Remote Window Hijacking<br />

<strong>PVS</strong> ID: 2530 FAMILY: Web Clients RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Cross-Site Scripting (XSS) attack.\n\nThe<br />

remote host is using a version of iCab that is prone to a security flaw that may allow a<br />

malicious website to influence a pop up window from a trusted site.\nAn attacker may<br />

exploit this flaw to impersonate third-party web servers and convince a victim on the<br />

remote host into revealing personal information.<br />

Solution: No solution is known at this time.<br />

CVE Not available<br />

Konqueror Web Browser < 3.3.3 Remote Window Hijacking<br />

<strong>PVS</strong> ID: 2531 FAMILY: Web Clients RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a cross-site scripting (XSS) attack.\n\nThe<br />

remote host is using a version of Konqueror that is prone to a security flaw that may allow<br />

a malicious website to influence a pop up window from a trusted site.\nAn attacker may<br />

exploit this flaw to impersonate third-party web servers and convince a victim on the<br />

remote host into revealing personal information.<br />

Solution: Install Konqueror 3.3.3 or higher.<br />

CVE-2004-1158<br />

Bugzilla < 2.18.0 Internal Error XSS<br />

<strong>PVS</strong> ID: 2532 FAMILY: CGI RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Cross-Site Scripting (XSS) attack.\n\nThe<br />

remote server is running Bugzilla, a bug tracking system. There is a flaw in the remote<br />

installation of Bugzilla that may allow an attacker to perform a cross-site scripting attack<br />

by exploiting a bug in the way Bugzilla displays internal errors mixed with user-supplied<br />

data.<br />

Solution: Upgrade to Bugzilla 2.18.0 or higher.<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 644

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!