27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

potential loss of confidential data (such as cookies).<br />

Solution: Upgrade to version 1.3.3 or higher.<br />

CVE-2005-1172<br />

Oracle Database Multiple Remote Vulnerabilities<br />

<strong>PVS</strong> ID: 2840 FAMILY: Database RISK: HIGH NESSUS ID:18034<br />

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack<br />

vectors.\n\nAccording to its version number, the installation of Oracle on the<br />

remote host is reportedly subject to multiple unspecified vulnerabilities. Some<br />

vulnerabilities don't require authentication. It may allow an attacker to craft<br />

SQL queries such that they would be able to retrieve any file on the system and<br />

potentially retrieve and/or modify confidential data on the target's Oracle server.<br />

Solution: http://www.oracle.com/technology/deploy/security/pdf/cpuapr2005.pdf<br />

CVE-2005-3203<br />

webcamXP Camera Detection<br />

<strong>PVS</strong> ID: 2841 FAMILY: Policy<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is running software that should be authorized with respect to<br />

corporate policy.\n\nThe remote host is running the webcamXP application. webcamXP is<br />

an all-in-one camera/webserver appliance that allows users to view and administer a<br />

camera remotely.<br />

Solution: Ensure that this web camera is authorized with respect to corporate policies and guidelines.<br />

In addition, ensure that the images being shown by the camera do not violate any<br />

'Acceptable Usage' policies.<br />

CVE Not available<br />

webcamXP < 2.16.478 Chat Name HTML Injection<br />

<strong>PVS</strong> ID: 2842 FAMILY: Web Servers<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:18122<br />

Description: Synopsis :\n\nThe remote host is vulnerable to an HTML Injection attack.\n\nThe remote<br />

host is running the webcamXP application. webcamXP is an all-in-one camera/webserver<br />

appliance that allows users to view and administer a camera remotely. This version of<br />

webcamXP is vulnerable to an HTML injection flaw. An attacker exploiting this flaw<br />

would typically need to be able to entice a user into browsing to a malicious URI.<br />

Successful exploitation would result in the theft of confidential materials (such as<br />

authentication cookies).<br />

Family Internet Services 733

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!