27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Solution: Upgrade to version 1.1.48 or higher.<br />

CVE-2006-0949<br />

SPLUNK Online Log Search Detection<br />

<strong>PVS</strong> ID: 3456 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host may give an attacker information useful for future<br />

attacks.\n\nThe remote host is running SPLUNK, a web-based application that allows<br />

remote users to search syslog log files. This application may give remote attackers the<br />

ability to gain information useful in future attacks.<br />

Solution: Ensure that access to SPLUNK is restricted to administrative users.<br />

CVE Not available<br />

Gallery < 2.0.3 GalleryUtilities.class X_FORWARDED_FOR HTTP Header XSS<br />

<strong>PVS</strong> ID: 3457 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to an HTML Injection attack.\n\nThe remote<br />

host is running the Gallery web-based photo album. This version of Gallery is vulnerable to<br />

a cross-site scripting (XSS) flaw. The vendor has released version 2.0.3 as a fix. An<br />

attacker exploiting this flaw would need to be able to convince a user to browse to a<br />

malicious URI. Successful exploitation could lead to the loss of potentially confidential<br />

data.<br />

Solution: Upgrade to version 2.0.3 or higher.<br />

CVE-2006-1127<br />

Listserv < 14.5 Multiple Buffer Overflows<br />

<strong>PVS</strong> ID: 3458 FAMILY: Web Servers RISK: HIGH NESSUS ID:21016<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote host is<br />

running Listserv, a mailing list management application. According to its version number,<br />

the Listserv install on the remote host suffers from as-yet unspecified buffer overflows,<br />

including one that reportedly can be exploited by an unauthenticated attacker to execute<br />

arbitrary code on the affected host.<br />

Solution: Upgrade to version 14.5 or higher.<br />

CVE-2006-1044<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Retrospect Client for Windows Malformed Packet DoS<br />

Family Internet Services 890

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!