27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: Synopsis :\n\nThe remote host is vulnerable to a heap overflow.\n\nThe remote host is<br />

running Winamp, a multi-media software application. This version of Winamp is<br />

vulnerable to multiple heap overflows. Specifically, the application fails to handle buffers<br />

when handling 'ultravox-max' and 'Lyrics3' tags. An attacker exploiting this flaw would<br />

need to be able to convince a user into perusing a malicious media server. Successful<br />

exploitation would give the attacker the ability to execute code with the privileges of the<br />

user running Winamp.<br />

Solution: Upgrade to version 5.31 or higher.<br />

CVE-2006-5567<br />

Web Wiz Forums forum/search.asp KW Parameter SQL Injection<br />

<strong>PVS</strong> ID: 3801 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a SQL Injection attack.\n\nThe remote host<br />

is vulnerable to a SQL injection flaw in its search.asp script. An attacker exploiting this<br />

flaw would be able to execute arbitrary commands on the remote database server.<br />

Successful exploitation would only require that the attacker be able to send malformed<br />

requests to the search.asp application. Successful exploitation would result in a loss of<br />

confidentiality, integrity, and availability.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE-2006-5635<br />

FreePBX VoIP Administrative Interface Detection<br />

<strong>PVS</strong> ID: 3802 FAMILY: Web Servers RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running the FreePBX administrative interface. FreePBX is an Asterisk<br />

derivative that includes a Voice Over IP (VoIP) server and an administrative web interface.<br />

The web interface is used to manage the VoIP services. The version of FreePBX is\n%L<br />

Solution: Ensure that the default settings for the web interface have been disabled or changed. Also<br />

ensure that only trusted IP ranges can access the service.<br />

CVE Not available<br />

WordPress < 2.0.5 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 3803 FAMILY: CGI<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack vectors.\n\nThe remote host<br />

is running WordPress, a web blog manager written in PHP.\nThe remote version of this<br />

software is reported to be vulnerable to a number of flaws. At the time of this writing, the<br />

flaws have not been verified by the vendor. Allegedly, an attacker can exploit these flaws to<br />

gain information about the server that would be useful in future attacks. The WordPress<br />

application is hosted at the following location:\n%P<br />

Family Internet Services 983

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!