27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CVE Not available<br />

Geeklog FCKeditor < 1.4.0sr4 Arbitrary File Upload<br />

<strong>PVS</strong> ID: 3677 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:21780<br />

Description: Synopsis :\n\nThe remote web server contains a PHP application that is affected by an<br />

arbitrary file upload vulnerability.\n\nThe remote host is running Geeklog, an open-source<br />

weblog powered by PHP and MySQL. The version of Geeklog installed on the remote host<br />

includes an older version of FCKeditor that is enabled by default and allows an<br />

unauthenticated attacker to upload arbitrary files containing PHP code, and then to execute<br />

them subject to the privileges of the web server user ID.<br />

Solution: Upgrade to Geeklog 1.4.0sr4 or higher.<br />

CVE-2006-3362<br />

phpFormGenerator Arbitrary File Upload<br />

<strong>PVS</strong> ID: 3678 FAMILY: CGI RISK: HIGH NESSUS ID:21918<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Script Injection attack.\n\nThe remote host<br />

is running phpFormGenerator, a PHP-based tool for generating web forms. The version of<br />

phpFormGenerator installed on the remote host allows an unauthenticated attacker to create<br />

forms supporting arbitrary file uploads. This issue can then be leveraged to upload a file<br />

with arbitrary code and execute it subject to the privileges of the web server user ID.<br />

Solution: No solution is known at this time.<br />

CVE Not available<br />

CommuniGate Pro < 5.1c2 POP3 Overflow<br />

<strong>PVS</strong> ID: 3679 FAMILY: Web Servers RISK: HIGH NESSUS ID:20827<br />

Description: Synopsis :\n\nThe remote mail server is prone to multiple attack vectors.\n\nAccording to<br />

its banner, the version of CommuniGate Pro running on the remote host will crash when<br />

certain mail clients try to open an empty mailbox. Remote code execution may even be<br />

possible.<br />

Solution: Upgrade to version 5.1c2 or higher.<br />

CVE-2006-0468<br />

Zope < 2.9.4 docutils Information Disclosure<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 3680 FAMILY: Web Servers RISK: LOW NESSUS ID:Not Available<br />

Family Internet Services 950

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!