27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

VMWare Detection<br />

CVE Not available<br />

<strong>PVS</strong> ID: 3396 FAMILY: Web Clients RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host passes information across the network in an insecure<br />

manner.\n\nThe remote host is running VMWare, an application that allows users to run<br />

multiple operating systems virtually. VMWare passes the license key in plaintext across the<br />

Internet. An attacker sniffing the network will be able to gain access to the VMWare<br />

key:\n\n%L<br />

Solution: Disable automatic updates and only use encrypted sessions to update VMWare software.<br />

CVE Not available<br />

Invision Power Board Dragoran Forum < 1.4 index.php site Parameter SQL Injection<br />

<strong>PVS</strong> ID: 3397 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a SQL Injection attack.\n\nThe remote host<br />

is running the Dragoran Forum, a PHP-based web portal. This version of Dragoran is<br />

vulnerable to a SQL Injection flaw. An attacker exploiting this flaw would be able to<br />

execute arbitrary SQL commands on the Dragoran backend database server.<br />

Solution: Upgrade to version 1.4 or higher.<br />

CVE-2006-0520<br />

Oracle Database Detection<br />

<strong>PVS</strong> ID: 3398 FAMILY: Database RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running an Oracle database.<br />

Solution: N/A<br />

CVE Not available<br />

Nmap Scanner Detection<br />

<strong>PVS</strong> ID: 3399 FAMILY: Policy RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running the Nmap port scanner.<br />

Solution: Ensure that this tool is authorized according to corporate policies and guidelines.<br />

CVE Not available<br />

Nmap Scanner Detection<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 873

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!