27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Description: The remote host is running the phpBB bulletin board. The reported version is: \n %L<br />

\n\nThis version is reported vulnerable to a cross-site-scripting (XSS) flaw.<br />

Solution: Upgrade to version 2.0.15 or higher.<br />

CVE-2005-1193<br />

Horde Vacation < 2.2.2 Parent Frame Page Title XSS<br />

<strong>PVS</strong> ID: 2850 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Cross-Site Scripting (XSS) attack.\n\nThe<br />

version of Horde Vacation installed on the remote host suffers from a cross-site scripting<br />

vulnerability in which an attacker can inject arbitrary HTML and script code into an<br />

unsuspecting user's browser, enabling him to steal cookie-based authentication credentials<br />

and perform other such attacks.<br />

Solution: Upgrade to version 2.2.2 or higher.<br />

CVE-2005-1321<br />

Horde MNemo < 1.1.4 Parent Frame Page Title XSS<br />

<strong>PVS</strong> ID: 2851 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Cross-Site Scripting (XSS) attack.\n\nThe<br />

version of Horde MNemo installed on the remote host suffers from a cross-site scripting<br />

vulnerability in which an attacker can inject arbitrary HTML and script code into an<br />

unsuspecting user's browser, enabling him to steal cookie-based authentication credentials<br />

and perform other such attacks.<br />

Solution: Upgrade to version 1.1.4 or higher.<br />

CVE-2005-1320<br />

Horde Nag < 1.1.3 Parent Frame Page Title XSS<br />

<strong>PVS</strong> ID: 2852 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:18136<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Cross-Site Scripting (XSS) attack.\n\nThe<br />

version of Horde Nag installed on the remote host suffers from a cross-site scripting<br />

vulnerability in which an attacker can inject arbitrary HTML and script code into an<br />

unsuspecting user's browser, enabling him to steal cookie-based authentication credentials<br />

and perform other such attacks.<br />

Solution: Upgrade to version 1.1.3 or higher.<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 736

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!