27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

attacker exploiting this flaw would be able to inject arbitrary system commands into SQL<br />

statements.<br />

Solution: Upgrade to version 1.03 or higher.<br />

CVE-2005-3082<br />

Qualcomm Qpopper poppassd Local Privilege Escalation<br />

<strong>PVS</strong> ID: 3243 FAMILY: POP Server RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe host is vulnerable to a local file access flaw.\n\nThe remote host is<br />

running Qpopper, a POP3 mail server for Unix-type systems. This version of Qpopper is<br />

vulnerable to a local configuration flaws. A local attacker exploiting these flaws would be<br />

able to elevate privileges on the Qpopper system.<br />

Solution: No solution is known at this time.<br />

CVE-2005-3098<br />

Brooky CubeCart < 3.0.4 Multiple XSS<br />

<strong>PVS</strong> ID: 3244 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote web server contains a script that is vulnerable to a Cross-Site<br />

Scripting (XSS) attack.\n\nThe remote host is using Brooky CubeCart, an online storefront<br />

application written in PHP. This version of CubeCart is vulnerable to multiple XSS<br />

Injection flaws. An attacker exploiting these flaws would need to be able to convince a user<br />

to browse to a malicious URI. Successful exploitation would result in code execution<br />

within the user's browser that could lead to theft of authentication materials.<br />

Solution: Upgrade to version 3.0.4 or higher.<br />

CVE-2005-3152<br />

PHP-Fusion < 6.00.110 Multiple SQL Injection Vulnerabilities<br />

<strong>PVS</strong> ID: 3245 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote web server contains a script that is vulnerable to a<br />

SQL injection attack.\n\nAccording to its version number, the remote host is<br />

running a version of PHP-Fusion that suffers from a SQL Injection flaw. An<br />

attacker exploiting these flaws would be able to inject commands into SQL<br />

statements or inject executable code which would be executed by the database<br />

server.<br />

Solution: Upgrade to version 6.00.110 or higher.<br />

CVE-2005-3161<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 834

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!