27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Lotus Domino Server Web Service NRPC Authentication Format String DoS<br />

<strong>PVS</strong> ID: 2870 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a format string flaw.\n\nThe remote host is<br />

running a version of Lotus Domino Server's web service that is prone to a remote format<br />

string vulnerability. Specifically, during Lotus Notes authentication, a server utilizing<br />

Notes Remote Procedure Call (NRPC) can be sent a malicious payload that, when parsed,<br />

would cause the server to either fail (loss of availability) or execute arbitrary code (loss of<br />

confidentiality and integrity).<br />

Solution: Upgrade to Lotus Domino Server version 6.5.4, 6.0.5 or higher.<br />

CVE-2005-1441<br />

JGS-Portal < 3.0.2 jgs_portal.php id Parameter SQL Injection<br />

<strong>PVS</strong> ID: 2871 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote web server contains a script that is vulnerable to a SQL injection<br />

attack.\n\nThe remote host is running JGS-Portal, a plugin for the Woltlab web application.<br />

This version of JGS-Portal is vulnerable to a remote SQL injection attack. An attacker<br />

exploiting this flaw would send a malformed HTTP query to the application. Successful<br />

exploitation would result in the attacker being able to read or write confidential data. In<br />

addition, the attack may be able to execute arbitrary code on the remote database server.<br />

Solution: Upgrade to version 3.0.2 or higher.<br />

CVE-2005-1479<br />

BitTorrent Client Detection<br />

<strong>PVS</strong> ID: 2872 FAMILY: Peer-To-Peer File Sharing<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is running software which should be authorized with respect<br />

to corporate policy.\n\nThe remote host is running the Bittorrent client version<br />

%L\nBitTorrent is a client application that allows users to quickly download files from<br />

multiple locations.<br />

Solution: Ensure that BitTorrent is allowed with respect to corporate policies and guidelines.<br />

CVE Not available<br />

Kerio MailServer < 6.0.10 Unspecified Admin Web Interface DoS<br />

<strong>PVS</strong> ID: 2873 FAMILY: SMTP Servers<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:18184<br />

Family Internet Services 742

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!