27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Sun Secure Global Desktop / Tarantella < 4.20.983 Multiple XSS<br />

<strong>PVS</strong> ID: 3760 FAMILY: Generic<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:22495<br />

Description: The remote web server contains CGI scripts that are vulnerable to cross-site scripting<br />

attacks. The remote web server contains a CGI script used by Sun Secure Global Desktop<br />

or Tarantella, a Java-based program for web-enabling applications running on a variety of<br />

platforms. According to the version reported in one of its scripts, the installation of the<br />

software on the remote host fails to sanitize user-supplied input to several unspecified<br />

parameters before using it to generate dynamic web content. An unauthenticated remote<br />

attacker may be able to leverage these issues to inject arbitrary HTML and script code into<br />

a user's browser to be evaluated within the security context of the affected web site.<br />

Solution: Upgrade to version 4.20.983 or higher.<br />

CVE-2006-4958<br />

SiVus VOIP Vulnerability Scanner Detection<br />

<strong>PVS</strong> ID: 3761 FAMILY: Policy RISK: INFO NESSUS ID:Not Available<br />

Description: The remote client is scanning the network with the SiVus VOIP vulnerability scanner. This<br />

tool scans networks and detects vulnerable VOIP SIP phones.<br />

Solution: Ensure that such scanning is in alignment with corporate policies and guidelines.<br />

SIP Client Detection<br />

CVE Not available<br />

<strong>PVS</strong> ID: 3762 FAMILY: Generic RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running the following SIP client: \n %L \nThis protocol is used to<br />

connect VoIP users via the Internet.<br />

Solution: N/A<br />

SIP Server Detection<br />

CVE Not available<br />

<strong>PVS</strong> ID: 3763 FAMILY: Generic RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running the following SIP server: \n %L \nThis protocol is used to<br />

connect VoIP users via the Internet.<br />

Solution: N/A<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 972

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!