27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CVE-2005-1322<br />

Horde Chora < 1.2.3 Parent Frame Page Title XSS<br />

<strong>PVS</strong> ID: 2853 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:18131<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Cross-Site Scripting (XSS) attack.\n\nThe<br />

version of Horde Chora installed on the remote host suffers from a cross-site scripting<br />

vulnerability in which an attacker can inject arbitrary HTML and script code into an<br />

unsuspecting user's browser, enabling him to steal cookie-based authentication credentials<br />

and perform other such attacks.<br />

Solution: Upgrade to version 1.2.3 or higher.<br />

CVE Not available<br />

Horde Accounts < 2.1.2 Parent Frame Page Title XSS<br />

<strong>PVS</strong> ID: 2854 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Cross-Site Scripting (XSS) attack.\n\nThe<br />

version of Horde Accounts installed on the remote host suffers from a cross-site scripting<br />

vulnerability in which an attacker can inject arbitrary HTML and script code into an<br />

unsuspecting user's browser, enabling him to steal cookie-based authentication credentials<br />

and perform other such attacks.<br />

Solution: Upgrade to version 2.1.2 or higher.<br />

CVE Not available<br />

Horde Forwards < 2.2.2 Parent Frame Page Title XSS<br />

<strong>PVS</strong> ID: 2855 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Cross-Site Scripting (XSS) attack.\n\nThe<br />

version of Horde Forwards installed on the remote host suffers from a cross-site scripting<br />

vulnerability in which an attacker can inject arbitrary HTML and script code into an<br />

unsuspecting user's browser, enabling him to steal cookie-based authentication credentials<br />

and perform other such attacks.<br />

Solution: Upgrade to version 2.2.2 or higher.<br />

CVE Not available<br />

Horde Imp < 3.2.8 Parent Frame Page Title XSS<br />

<strong>PVS</strong> ID: 2856 FAMILY: CGI<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Family Internet Services 737

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!