<?xml version="1.0" encoding="UTF-8"?>

<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns="http://purl.org/rss/1.0/">

<channel rdf:about="http://www.tenablesecurity.com/">
  <title>The Passive Vulnerability Scanner (PVS) Plugins</title>
  <link>http://www.tenablesecurity.com/tenable_plugins.pdf</link>
  <description>All the newest security checks for the Tenable Passive Vulnerability Scanner (PVS)</description>
  <image rdf:resource="http://www.tenablesecurity.com/images/RssLogo.jpg" />
  <items>

    <rdf:Seq>
<rdf:li rdf:resource="http://www.tenablesecurity.com/5091.html" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/5090.html" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/5089.html" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/5088.html" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/5087.html" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/5086.html" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/5085.html" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/5084.html" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/5083.html" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/5082.html" />

    </rdf:Seq>

  </items>
</channel>

<image rdf:about="http://www.tenablesecurity.com/images/RssLogo.jpg">
<title>PVS Plugins</title>
<url>http://www.tenablesecurity.com/images/RssLogo.jpg</url>
<link>http://www.tenablesecurity.com/</link>
</image>

<item rdf:about="http://www.tenablesecurity.com/5091.html">
<title>Joomla! &lt; 1.5.12 Multiple Vulnerabilities</title>
<description><![CDATA[<br />
Synopsis :<br><br>The remote web server contains a PHP application that is vulnerable to multiple attack vectors.<br><br>The installed version of Joomla! is earlier than 1.5.12. Such versions are reportedly affected by multiple vulnerabilities :<br><br>  - A cross-site scripting vulnerability in the 'PHP_SELF' property. (20090605)<br><br>  - A cross-site scripting vulnerability in the 'HTTP_REFERER' parameter. (20090604)<br><br>  - An information disclosure vulnerability because several files were missing checks for JEXEC. (20090606)<br><br>For your information, the reported version of Joomla was:<br>%L<br><br><br><br>CVSS Base Score : 5.0<br>CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N
<br /><br />See also :<br />
<br />
<a href="http://www.joomla.org/announcements/release-news/5242-joomla-1512-released.html" target="_blank">http://www.joomla.org/announcements/release-news/5242-joomla-1512-released.html</a><br />
<br />
Solution :<br />
<br />
Upgrade to Joomla! 1.5.12 or later.<br />
<br />
Risk factor :<br />
<br />
MEDIUM<br /><br />Copyright Tenable Network Security Inc. 2009]]></description>
<dc:date>2009-07-02T18:16:00-05:00</dc:date>
<link>http://www.tenablesecurity.com/5091.html</link>

</item>

<item rdf:about="http://www.tenablesecurity.com/5090.html">
<title>FireStats &lt; 1.6.2 SQL Injection Vulnerability</title>
<description><![CDATA[<br />
Synopsis :<br><br>The remote web server is running a PHP application that is affected by multiple attack vectors.<br><br>The remote web server is running FireStats, a PHP-based website statistics application. The installed version of FireStats is earlier than 1.6.2. Such versions are reportedly affected by a SQL-injection vulnerability through an unspecified vector.<br><br>For your information, the reported version of FireStats is:<br>%L<br><br><br><br>CVSS Base Score : 7.5<br>CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
<br /><br />See also :<br />
<br />
<a href="http://firestats.cc/wiki/ChangeLog#a1.6.2-stable13062009" target="_blank">http://firestats.cc/wiki/ChangeLog#a1.6.2-stable13062009</a><br />
<br />
Solution :<br />
<br />
Upgrade to FireStats 1.6.2 or later.<br />
<br />
Risk factor :<br />
<br />
HIGH<br /><br />References:<br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2144" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2144</a><br />
<br /><br />Copyright Tenable Network Security Inc. 2009]]></description>
<dc:date>2009-07-02T18:16:00-05:00</dc:date>
<link>http://www.tenablesecurity.com/5090.html</link>

</item>

<item rdf:about="http://www.tenablesecurity.com/5089.html">
<title>MyBB &lt; 1.4.8 Multiple Cross-Site Scripting Issues</title>
<description><![CDATA[<br />
Synopsis :<br><br>The remote web server is running a PHP application that is affected by multiple attack vectors.<br><br>The remote web server is running a version of MyBB earlier than 1.4.8. Such versions reportedly fail to properly sanitize user-supplied data to unspecified parameters in the 'Archive' and 'Attachment' features of the application. An attacker could exploit this flaw to launch cross-site scripting attacks. For your information, the reported version of MyBB is:<br>%L<br><br><br><br>CVSS Base Score : 4.3<br>CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N
<br /><br />See also :<br />
<br />
<a href="http://blog.mybboard.net/2009/06/26/mybb-148-released-maintenance-security-release" target="_blank">http://blog.mybboard.net/2009/06/26/mybb-148-released-maintenance-security-release</a><br />
<br />
Solution :<br />
<br />
Upgrade to MyBB 1.4.8 or later.<br />
<br />
Risk factor :<br />
<br />
MEDIUM<br /><br />Copyright Tenable Network Security Inc. 2009]]></description>
<dc:date>2009-07-02T18:16:00-05:00</dc:date>
<link>http://www.tenablesecurity.com/5089.html</link>

</item>

<item rdf:about="http://www.tenablesecurity.com/5088.html">
<title>Movable Type &lt; 4.26 Multiple Vulnerabilities</title>
<description><![CDATA[<br />
Synopsis :<br><br>The remote host is vulnerable to multiple attack vectors.<br><br>The remote host is running Movable Type, a blogging software for Unix and Windows platforms. The installed version is earlier than 4.26. Such versions are reportedly affected by multiple vulnerabilities :<br><br>  - An unspecified cross-site scripting vulnerability.<br><br>  - A security-bypass issue in the 'mt-wizard.cgi' script.<br><br>For your information, the reported version of Movable Type is :<br>%L<br><br><br><br>CVSS Base Score : 4.3<br>CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N
<br /><br />See also :<br />
<br />
<a href="http://www.movabletype.org/documentation/appendices/release-notes/426.html" target="_blank">http://www.movabletype.org/documentation/appendices/release-notes/426.html</a><br />
<br />
Solution :<br />
<br />
Upgrade to Movable Type 4.26 or later.<br />
<br />
Risk factor :<br />
<br />
MEDIUM<br /><br />Copyright Tenable Network Security Inc. 2009]]></description>
<dc:date>2009-07-02T18:16:00-05:00</dc:date>
<link>http://www.tenablesecurity.com/5088.html</link>

</item>

<item rdf:about="http://www.tenablesecurity.com/5087.html">
<title>Samba Format String and Security Bypass Vulnerabilities</title>
<description><![CDATA[<br />
Synopsis :<br><br>The remote Samba server may be affected by an unauthorized access vulnerability.<br><br>According to its banner, the version of the Samba server on the remote host has a security bypass vulnerability. Access restrictions can be bypassed due to a read of uninitialized data in smbd. This could allow a user to modify an access control list (ACL), even when they should be denied permission.<br><br>Note the 'dos filemode' parameter must be set to 'yes' in smb.conf in order for an attack to be successful (the default setting is 'no'). For your information, the reported version of SAMBA is:<br>%L<br><br><br><br>CVSS Base Score : 3.5<br>CVSS2#AV:N/AC:M/Au:S/C:N/I:P/A:N
<br /><br />See also :<br />
<br />
<a href="http://us1.samba.org/samba/security/CVE-2009-1888.html" target="_blank">http://us1.samba.org/samba/security/CVE-2009-1888.html</a><br />
<br />
Solution :<br />
<br />
Upgrade to Samba 3.3.6 / 3.2.13 / 3.0.35 or later, or apply the appropriate patch referenced in the project's advisory.<br />
<br />
Risk factor :<br />
<br />
LOW<br /><br />References:<br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1888" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1888</a><br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1886" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1886</a><br />
<br /><br />Copyright Tenable Network Security Inc. 2009]]></description>
<dc:date>2009-07-02T18:16:00-05:00</dc:date>
<link>http://www.tenablesecurity.com/5087.html</link>

</item>

<item rdf:about="http://www.tenablesecurity.com/5086.html">
<title>BASE &lt; 1.2.5 Authentication Bypass</title>
<description><![CDATA[<br />
Synopsis :<br><br>The remote host is running a PHP application that is vulnerable to an authentication bypass attack.<br><br>The remote host is running BASE, a web-based tool for analyzing alerts from one or more SNORT sensors. The version of BASE installed on the remote host is earlier than 1.2.5. Such versions are reportedly fail to sufficiently validate 'user', 'role', or passwords against the database in the 'readRoleCookie()' function of the 'includes/base_auth.inc/php' script. An attacker could exploit this in order to bypass authentication and gain unauthorized access to the application. For your information, the reported version of BASE is:<br>%L<br><br><br><br>CVSS Base Score : 5.0<br>CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N
<br /><br />See also :<br />
<br />
<a href="http://www.securityfocus.com/archive/1/504487/30/0/threaded" target="_blank">http://www.securityfocus.com/archive/1/504487/30/0/threaded</a><br />
<br />
Solution :<br />
<br />
Upgrade to BASE version 1.2.5<br />
<br />
Risk factor :<br />
<br />
MEDIUM<br /><br />Copyright Tenable Network Security Inc. 2009]]></description>
<dc:date>2009-07-02T18:16:00-05:00</dc:date>
<link>http://www.tenablesecurity.com/5086.html</link>

</item>

<item rdf:about="http://www.tenablesecurity.com/5085.html">
<title>MyBB &lt; 1.4.7 SQL Injection</title>
<description><![CDATA[<br />
Synopsis :<br><br>The remote web server is running a PHP application that is vulnerable to a SQL-injection attack.<br><br>The remote web server is running a version of MyBB earlier than 1.4.7. Such versions reportedly fail to properly sanitize user-supplied data to the 'birthdayprivacy' parameter of the 'usercp.php' script before using it in an SQL query. An attacker could exploit this flaw to access or modify sensitive information. For your information, the reported version of MyBB is:<br>%L<br><br><br><br>CVSS Base Score : 5.5<br>CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N
<br /><br />See also :<br />
<br />
<a href="http://blog.mybboard.net/2009/06/15/mybb-147-released-security-update" target="_blank">http://blog.mybboard.net/2009/06/15/mybb-147-released-security-update</a><br />
<br />
Solution :<br />
<br />
Upgrade to MyBB 1.4.7 or later.<br />
<br />
Risk factor :<br />
<br />
MEDIUM<br /><br />Copyright Tenable Network Security Inc. 2009]]></description>
<dc:date>2009-07-02T18:16:00-05:00</dc:date>
<link>http://www.tenablesecurity.com/5085.html</link>

</item>

<item rdf:about="http://www.tenablesecurity.com/5084.html">
<title>Mozilla SeaMonkey &lt; 1.1.17 Multiple Vulnerabilities</title>
<description><![CDATA[<br />
Synopsis :<br><br>The remote host is running a web browser that is vulnerable to multiple attack vectors.<br><br>The remote host is running a version of Mozilla SeaMonkey earlier than 1.1.17. Such versions are reportedly affected by multiple vulnerabilities :<br><br>  - Multiple remote memory-corruption vulnerabilities.<br><br>  - Content injection vulnerabilities.<br><br>  - An information disclosure vulnerability.<br><br>  - A cross-site scripting vulnerability.<br><br>  - A privilege escalation vulnerability.<br><br>  - A security bypass vulnerability.<br><br>  - A URI spoofing vulnerability.<br><br>For your information, the reported version of SeaMonkey is :<br>%L<br><br><br><br>CVSS Base Score : 9.3<br>CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C
<br /><br />See also :<br />
<br />
<a href="http://www.mozilla.org/security/announce" target="_blank">http://www.mozilla.org/security/announce</a><br />
<br />
Solution :<br />
<br />
Upgrade to SeaMonkey 1.1.17 or later.<br />
<br />
Risk factor :<br />
<br />
HIGH<br /><br />References:<br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0652" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0652</a><br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1307" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1307</a><br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1311" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1311</a><br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1392" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1392</a><br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1832" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1832</a><br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1833" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1833</a><br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1834" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1834</a><br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1838" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1838</a><br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1840" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1840</a><br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1841" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1841</a><br />
<br /><br />Copyright Tenable Network Security Inc. 2009]]></description>
<dc:date>2009-07-02T18:16:00-05:00</dc:date>
<link>http://www.tenablesecurity.com/5084.html</link>

</item>

<item rdf:about="http://www.tenablesecurity.com/5083.html">
<title>Last seen FTP client name</title>
<description><![CDATA[<br />
PVS observed at least one FTP session originating from this client address. PVS maintains the most recently seen FTP account used to download files. The detected user login string was:<br> %L
<br /><br />
Solution :<br />
<br />
<br />
<br />
Risk factor :<br />
<br />
LOW<br /><br />Copyright Tenable Network Security Inc. 2009]]></description>
<dc:date>2009-07-02T18:16:00-05:00</dc:date>
<link>http://www.tenablesecurity.com/5083.html</link>

</item>

<item rdf:about="http://www.tenablesecurity.com/5082.html">
<title>Google Chrome &lt; 2.0.172.33 Buffer Overflow vulnerability</title>
<description><![CDATA[<br />
Synopsis :<br><br>The remote host contains a web browser that is vulnerable to a buffer overflow attack.<br><br>The version of Google Chrome installed on the remote host is earlier than 2.0.172.33. Such versions are reportedly affected by a buffer overflow vulnerability when handling certain responses from HTTP servers. An attacker could exploit this issue to cause a denial of service, or execute arbitrary code with the privileges of the logged on user. For you information, the reported version is :<br>%L<br><br><br><br>CVSS Base Score : 9.3<br>CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C
<br /><br />See also :<br />
<br />
<a href="http://googlechromereleases.blogspot.com/2009/06/stable-beta-update-security-fix.html" target="_blank">http://googlechromereleases.blogspot.com/2009/06/stable-beta-update-security-fix.html</a><br />
<br />
Solution :<br />
<br />
Upgrade to Google Chrome 2.0.172.33 or later.<br />
<br />
Risk factor :<br />
<br />
HIGH<br /><br />References:<br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2121" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2121</a><br />
<br /><br />Copyright Tenable Network Security Inc. 2009]]></description>
<dc:date>2009-07-02T18:16:00-05:00</dc:date>
<link>http://www.tenablesecurity.com/5082.html</link>

</item>


</rdf:RDF>
