27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: Synopsis :\n\nThe remote host is vulnerable to an HTML injection attack.\n\nThe target is<br />

running at least one instance of IlohaMail version 0.8.14 or earlier. The remote version of<br />

this software is vulnerable to an HTML injection attack. An attacker exploiting this flaw<br />

would need to convince a local user to open a malicious HTML email. Successful<br />

exploitation would result in the victim executing potentially damaging code and possibly<br />

theft of confidential, authentication-related data.<br />

Solution: Upgrade to version 0.8.14-RC3 or higher.<br />

CVE-2005-1120<br />

DameWare Remote Desktop Listener<br />

<strong>PVS</strong> ID: 2829 FAMILY: Generic<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: The remote host is running Dameware, a utility that allows administrators remote access to<br />

the Windows Desktop via a number of different protocols. There have been many flaws in<br />

Dameware and even one backdoor (Agobot) that uses Dameware as an attack vector for<br />

further propagation.<br />

Solution: Ensure that Dameware is authorized for your environment and that Dameware has been<br />

upgraded to the most recent version.<br />

CVE Not available<br />

Oracle Application Server 10g Detection<br />

<strong>PVS</strong> ID: 2830 FAMILY: Web Servers RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running the Oracle Application Server 10g version %L<br />

Solution: N/A<br />

CVE Not available<br />

Oracle Application Server J2EE Container Detection<br />

<strong>PVS</strong> ID: 2831 FAMILY: Web Servers RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running Oracle Application Server and has enabled J2EE containers<br />

version %L<br />

Solution: N/A<br />

CVE Not available<br />

MusicMatch Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 2832 FAMILY: Web Clients<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:18049<br />

Family Internet Services 730

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!