27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: An Informix telnet server is running on this port.<br />

Solution: N/A<br />

CVE Not available<br />

phpMyAdmin < 2.6.4-RC1 Multiple XSS<br />

<strong>PVS</strong> ID: 3193 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:19519<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Cross-Site Scripting (XSS) attack\n\nThe<br />

version of phpMyAdmin installed on the remote host may suffer from two cross-site<br />

scripting vulnerabilities due to its failure to sanitize user input to the 'error' parameter of the<br />

'error.php' script and in 'libraries/auth/cookie.auth.lib.php'. A remote attacker may use these<br />

vulnerabilities to cause arbitrary HTML and script code to be executed in a user's browser<br />

within the context of the affected application.<br />

Solution: Upgrade to version 2.6.4-RC1 or higher.<br />

CVE-2005-2869<br />

PHP-Fusion < 6.00.11 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 3194 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to an HTML Injection attack.\n\nAccording to<br />

its version number, the remote host is running a version of PHP-Fusion that suffers from an<br />

HTML injection vulnerability. An attacker can inject malicious code using specially-crafted<br />

posts. Successful exploitation would affect how the site is rendered to remote viewers.<br />

Solution: Upgrade to version 6.00.11 or higher.<br />

CVE-2005-2783<br />

phpLDAPadmin < 0.9.6c Anonymous Bind <strong>Security</strong> Bypass<br />

<strong>PVS</strong> ID: 3195 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:19546<br />

Description: Synopsis :\n\nThe remote application may allow anonymous connections despite the<br />

configuration details.\n\nThe remote host is running phpLDAPadmin, a PHP-based LDAP<br />

browser. The version of phpLDAPadmin installed on the remote host may allow access to<br />

an LDAP server anonymously, even if anonymous binds have been disabled in the<br />

application's configuration.<br />

Solution: Upgrade to version 0.9.6c or higher.<br />

CVE-2005-2654<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 820

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!