27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Solution: If this service is not needed, disable it or filter incoming traffic to this port. HP has released<br />

a set of patches for Data Protector 5.10 and 5.50:<br />

http://itrc.hp.com/service/cki/docDisplay.do?docId<br />

CVE-2006-4201<br />

Owl Intranet Engine < 0.91 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 3729 FAMILY: CGI RISK: HIGH NESSUS ID:22232<br />

Description: Synopsis :\n\nThe remote web server contains a PHP application that is prone to several<br />

issues.\n\nThe remote host is running Owl Intranet Engine, a web-based document<br />

management system written in PHP. The version of Owl Intranet Engine on the remote host<br />

fails to sanitize input to the session ID cookie before using it in a database query. Provided<br />

PHP's 'magic_quotes_gpc' setting is disabled, an unauthenticated attacker may be able to<br />

exploit this issue to uncover sensitive information such as password hashes, modify data,<br />

launch attacks against the underlying database, and more. In addition, the application<br />

reportedly suffers from at least one cross-site scripting (XSS) issue.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE-2006-4211<br />

Informix Database Detection (Windows)<br />

<strong>PVS</strong> ID: 3730 FAMILY: Database<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:22228<br />

Description: Synopsis :\n\nThe remote host passes information across the network in an insecure<br />

manner.\n\nThe remote host is running the Informix database server for Microsoft<br />

Windows. Further, clients connecting to this server are passing plaintext credentials across<br />

the network.<br />

Solution: Enable encrypted communications between the Informix client and server.<br />

CVE Not available<br />

Informix Database Detection (Unix)<br />

<strong>PVS</strong> ID: 3731 FAMILY: Database<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:22228<br />

Description: Synopsis :\n\nThe remote host passes information across the network in an insecure<br />

manner.\n\nThe remote host is running the Informix database server for Unix. Further,<br />

clients connecting to this server are passing plaintext credentials across the network.<br />

Solution: Enable encrypted communications between the Informix client and server.<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 963

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!