27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>PVS</strong> ID: 3666 FAMILY: Generic RISK: INFO NESSUS ID:Not Available<br />

Description: The remote server is a Nokia Intellisync Server. These portals are designed for access by<br />

users of portable devices (PDA, cell phone, etc.). One of the server components is a<br />

syncing port (TCP/3102) that maintains state and synchronization with the remote clients.<br />

Solution: N/A<br />

CVE Not available<br />

ZoneAlarm < 6.5.722.000 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 3667 FAMILY: Generic<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:21165<br />

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack vectors.\n\nThe remote host<br />

is running ZoneAlarm, a firewall for Windows. The vendor has released version<br />

6.5.722.000 of ZoneAlarm. This version corrects several bugs within the firewall.<br />

Solution: Upgrade to version 6.5.722.000 or higher.<br />

BlueDragon <<br />

CVE-2006-1221<br />

<strong>PVS</strong> ID: 3668 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack vectors.\n\nThe remote host<br />

is running BlueDragon, a ColdFusion Markup Language server. This version of<br />

BlueDragon is vulnerable to a Cross-Site Scripting (XSS) flaw where attackers can inject<br />

malicious scripting code that will run within the browser of BlueDragon clients. A second<br />

flaw would allow the attacker the ability to crash the application remotely, thereby denying<br />

services to legitimate users.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

YaBB SE <<br />

CVE-2006-2311<br />

<strong>PVS</strong> ID: 3669 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a SQL Injection attack.\n\nThe remote host<br />

is running the YaBB SE forum management system. There is a flaw in this version of<br />

YaBB SE that allows attackers to inject SQL commands via the web interface. An attacker<br />

exploiting this flaw would be able to execute arbitrary SQL commands on the backend<br />

database server used by YaBB SE.<br />

Solution: No solution is known at this time.<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 947

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!