27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Lotus Notes < 6.5.5 Web Mail Attachment HTML Injection<br />

<strong>PVS</strong> ID: 3052 FAMILY: SMTP Clients<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Script Injection attack.\n\nThe remote host<br />

is running the Lotus Notes email client. Lotus Notes client versions 6.5.4 and earlier could<br />

allow a remote attacker to inject HTML and JavaScript into email messages. An attacker<br />

exploiting this flaw would only need to send a malicious email to a Lotus Notes recipient.<br />

Successful exploitation would result in potentially malicious code executing with the user's<br />

privileges.<br />

Solution: Upgrade to version 6.5.5 or higher.<br />

CVE Not available<br />

Drupal Public Comment PHP Code Injection<br />

<strong>PVS</strong> ID: 3053 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Script Injection attack.\n\nThe remote host<br />

is running Drupal, a content management system. This version of Drupal is vulnerable to a<br />

flaw in the way that it handles user-supplied 'comments'. Specifically, an attacker can<br />

embed PHP script code within a comment that would then be executed by the remote<br />

webserver. An attacker exploiting this flaw would only need to post a specially formatted<br />

comment via the Drupal web interface.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

Comersus Cart <<br />

CVE-2005-2106<br />

<strong>PVS</strong> ID: 3054 FAMILY: CGI RISK: HIGH NESSUS ID:18643<br />

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack vectors.\n\nThe installed<br />

version of Comersus Cart on the remote host suffers from multiple SQL injection and<br />

cross-site scripting flaws due to its failure to sanitize user-supplied input. Attackers may be<br />

able to exploit these flaws to influence database queries or cause arbitrary HTML and script<br />

code to be executed in users' browsers within the context of the affected site.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE-2005-2190<br />

PHPAUCTION Multiple Vulnerabilities<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 3055 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Family Internet Services 780

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!