27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

malicious code being executed within the client browser. An attacker exploiting the SQL<br />

injection flaw would only need to be able to send HTTP queries to the remote application.<br />

A successful attack would give the attacker the ability to read and write database data as<br />

well as potentially execute arbitrary remote commands on the SQL or MySQL system.<br />

Solution: Upgrade to version 1.36 or higher.<br />

CVE-2005-1016<br />

Bakbone NetVault Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 2784 FAMILY: Generic RISK: HIGH NESSUS ID:18257<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote host is<br />

running Bakbone NetVault, an enterprise backup/restore application. This version of<br />

NetVault is vulnerable to a remote heap overflow as well as a local content-parsing<br />

overflow. An attacker exploiting the first flaw would need to be able to connect to the<br />

application on port 20031. A successful exploit would result in arbitrary code being<br />

executed by the SYSTEM process. An attacker exploiting the second flaw would need local<br />

read/write access to the Netvault configuration files. A successful attack would lead to<br />

arbitrary code being executed.<br />

Solution: No solution is known at this time.<br />

CVE-2005-1547<br />

Windows 2003 SP1 Server Detection<br />

<strong>PVS</strong> ID: 2785 FAMILY: Operating System Detection RISK: NONE NESSUS ID:Not Available<br />

Description: The remote host is running Windows 2003 Server SP1.<br />

Solution: N/A<br />

CVE Not available<br />

Windows 2003 (No Service Pack) Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 2786 FAMILY: Generic RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis : \n\nThe remote host is missing a critical security patch or upgrade.\n\nThe<br />

remote host is running Windows 2003 Server. Multiple vulnerabilities were fixed in<br />

SP1.\nThe reported version of Microsoft 2003 running on this server is: \n %L<br />

Solution: Upgrade to Windows 2003 SP1 or higher.<br />

CVE-1999-0662<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

phpMyAdmin < 2.6.2 RC1 Remote Command Execution<br />

<strong>PVS</strong> ID: 2787 FAMILY: CGI NESSUS ID:17689<br />

Family Internet Services 717

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!