27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

SurgeFTP < 2.2m2 LEAK Command Remote DoS<br />

<strong>PVS</strong> ID: 2802 FAMILY: FTP Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:18000<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Denial of Service (DoS) attack.\n\nThe<br />

remote host is running SurgeFTP, an FTP server for Microsoft and Unix platforms. This<br />

version of SurgeFTP is vulnerable to a content-parsing flaw via the LEAK command.<br />

Calling the LEAK command twice consecutively causes a file IO bug that causes the server<br />

to either stop responding or stop file transfers.<br />

Solution: Upgrade to version 2.2m2 or higher.<br />

CVE-2005-1034<br />

Axel < 1.0b conn.c HTTP Redirection Remote Overflow<br />

<strong>PVS</strong> ID: 2803 FAMILY: Web Clients RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to an arbitrary 'command insertion'<br />

flaw.\n\nThe remote host is running Axel, a download accelerator for FTP and HTTP<br />

protocols. This version of Axel is vulnerable to a remote buffer overflow due to the way<br />

that it parses server '302' messages. An attacker exploiting this flaw would need to be able<br />

to entice an Axel user to browse to their malicious website. Successful exploitation would<br />

result in the attacker running arbitrary commands on the system.<br />

Solution: Upgrade to version 1.0b or higher.<br />

CVE-2005-0390<br />

ColdFusion MX Server Detection<br />

<strong>PVS</strong> ID: 2804 FAMILY: Web Servers RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running ColdFusion MX Server.<br />

Solution: N/A<br />

CVE Not available<br />

ColdFusion MX Server Detection<br />

<strong>PVS</strong> ID: 2805 FAMILY: Web Servers RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running ColdFusion MX Server.<br />

Solution: N/A<br />

CVE Not available<br />

ColdFusion < 7.0 MX File Disclosure<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 722

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!