27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

user to browse to a malicious URI. Successful exploitation would result in attacker code<br />

running within the victim browser possibly resulting in the loss of confidential data (such<br />

as cookies).<br />

Solution: Upgrade to version 2.0.14 or higher.<br />

CVE-2005-1115<br />

Oracle Database Multiple Remote Vulnerabilities<br />

<strong>PVS</strong> ID: 2822 FAMILY: Database RISK: HIGH NESSUS ID:18034<br />

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack vectors.\n\nAccording to its<br />

version number, the installation of Oracle on the remote\nhost is reportedly subject to<br />

multiple unspecified vulnerabilities.\nSome vulnerabilities don't require authentication. It<br />

may allow an attacker\nto craft SQL queries such that they would be able to retrieve any<br />

file on\nthe system and potentially retrieve and/or modify confidential data on the\ntarget's<br />

Oracle server.<br />

Solution: http://www.oracle.com/technology/deploy/security/pdf/cpuapr2005.pdf<br />

CVE-2005-3203<br />

AS400 Default POP Services Information Disclosure<br />

<strong>PVS</strong> ID: 2823 FAMILY: POP Server<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:18046<br />

Description: Synopsis :\n\nThe remote host may give an attacker information useful for future<br />

attacks.\n\nThe remote host is running the AS400 (version 4.5 or higher) POP3 server. This<br />

version of the POP daemon is vulnerable to an information disclosure flaw. An attacker can<br />

gain information about valid accounts, accounts with expired passwords, system accounts<br />

by querying the POP server. This information can be useful in other attacks that require a<br />

user ID and/or password.<br />

Solution: No solution is known at this time.<br />

CVE-2005-1133<br />

AS/400 Server Detection<br />

<strong>PVS</strong> ID: 2824 FAMILY: Operating System Detection RISK: NONE NESSUS ID:Not Available<br />

Description: The remote host is AS/400 version 4.5 or higher.<br />

Solution: N/A<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

IBM WebSphere JSP Source Disclosure / XSS Vulnerabilities<br />

Family Internet Services 728

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!