27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

lucidCMS Login Form Field SQL Injection<br />

<strong>PVS</strong> ID: 3246 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote web server contains a script that is vulnerable to a<br />

SQL injection attack.\n\nAccording to its version number, the remote host is<br />

running a version of lucidCMS that suffers from a SQL Injection flaw. An<br />

attacker exploiting these flaws would be able to inject commands into SQL<br />

statements or inject executable code which would be executed by the database<br />

server.<br />

Solution: No solution is known at this time.<br />

CVE-2005-3130<br />

Squid < 2.5 STABLE11 NTLM Authentication Header DoS<br />

<strong>PVS</strong> ID: 3247 FAMILY: Web Servers RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote proxy is vulnerable to a DoS attack.\n\nThe remote squid<br />

caching proxy, according to its version number, is vulnerable to an attack where an<br />

attacker can disable the Squid proxy by sending a malformed NTLM request.<br />

Successful exploitation leads to a loss of availability.<br />

Solution: Upgrade to version 2.5 STABLE11 or higher.<br />

CVE-2005-2917<br />

IceWarp Web Mail Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 3248 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:19782<br />

Description: Synopsis :\n\nIt is possible to retrieve or delete local files on the remote system through the<br />

WebMail.\n\nThe remote host is running IceWarp Web Mail, a webmail solution available<br />

for the Microsoft Windows platform. The remote version of this software is vulnerable to a<br />

Directory Traversal vulnerability that may allow an attacker to retrieve arbitrary files on the<br />

system. Another input validation flaw allows an attacker to delete arbitrary files on the<br />

remote host. In addition, the existence of these two flaws indicates that IceWarp is<br />

vulnerable to cross-site scripting attack.<br />

Solution: No solution is known at this time.<br />

CVE-2005-3131<br />

4D WebStar < 5.3.5 IMAP Mac OS Client DoS<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 3249 FAMILY: Web Servers RISK: LOW NESSUS ID:Not Available<br />

Family Internet Services 835

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!