27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Description: Synopsis :\n\nThe remote host is vulnerable to a 'format string' flaw.\n\nThe remote host is<br />

running PeerCast, a streaming audio server. This version of PeerCast is vulnerable to a<br />

remote format string flaw within its HTTP server component. An attacker exploiting this<br />

flaw would be able to crash the server or execute arbitrary code on the remote system.<br />

Solution: Upgrade to version 0.1212 or higher.<br />

CVE-2005-1806<br />

Exhibit Engine < 1.5 RC 5 list.php Multiple Parameter SQL Injection<br />

<strong>PVS</strong> ID: 2944 FAMILY: CGI RISK: HIGH NESSUS ID:18416<br />

Description: The remote host is running Exhibit Engine, a web-based PHP application for sharing<br />

photos. This version of Exhibit Engine is vulnerable to a remote SQL injection flaw. An<br />

attacker exploiting this flaw would send a malformed HTTP query to the application.<br />

Successful exploitation would result in the attacker being able to read or write confidential<br />

data. In addition, the attacker may be able to execute arbitrary code on the remote database<br />

server.<br />

Solution: Upgrade to version 1.5 RC 5 or higher.<br />

CVE-2005-1875<br />

CROB FTP Server Multiple Command Remote Overflow DoS<br />

<strong>PVS</strong> ID: 2945 FAMILY: FTP Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote host is<br />

running the CROB FTP Server. This version of CROB is vulnerable to a remote<br />

stack-based overflow when sent a malformed RMD command. An attacker exploiting this<br />

flaw would be able to execute arbitrary code. In addition, there are also multiple<br />

heap-based overflows within many other FTP commands.<br />

Solution: No solution is known at this time.<br />

CVE-2006-6558<br />

FlexCast < 2.0 Remote Overflow<br />

<strong>PVS</strong> ID: 2946 FAMILY: Web Servers RISK: NONE NESSUS ID:18429<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote host is<br />

running FlexCast, a streaming audio and video server. This version of FlexCast is<br />

vulnerable to a remote buffer overflow. An attacker exploiting this flaw would be able to<br />

execute arbitrary code on the remote system.<br />

Solution: Upgrade to version 2.0 or higher.<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 764

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!