sos5.0.0,
sos5.1.0
medium
This signature detects attempts to exploit a vulnerability in
phpBB, an open-source bulletin board package. The
search_id parameter in phpBB is vulnerable to SQL injection.
Attackers may query private data (such as hashed
passwords) then embed the password in a cookie to gain
administrative access to the Web site.
HTTP:PHP:PHPBB:SEARCH-INJECT
sos5.1.0
high
This signature detects attempts to exploit a vulnerability in
PhpDig 1.6. Attackers may include a malicious
'relative_script_path' parameter in a direct request to the
config.php script; this request causes the server to download
php code from remote location and execute it. Attackers
may execute arbitrary code on the server with permissions
of the web server.
HTTP:PHP:PHPDIG-FILE-INC
sos5.0.0,
sos5.1.0
medium
This signature detects attempts to exploit a vulnerability in
PHPLILB, a code library that provides support for managing
sessions in Web applications. Attackers may remotely submit
maliciously crafted Web requests to cause the application
to fetch and execute scripts from another host, allowing
local access to the Web server.
HTTP:PHP:PHPLIB-REMOTE-EXEC
sos5.1.0
medium
This signature detects attempts to exploit a vulnerability in
PHPMyAdmin. Attackers may use HTTP form parameters
to remotely provide mysql server configuration data. This
attack is typically one stage in a multi-stage exploit attempt.
HTTP:PHP:PHPMYADMIN:SVR-PARAM
sos5.1.0
medium
This signature detects attempts to exploit a vulnerability in
PHP-Nuke. Attackers may execute arbitrary SQL commands
on a Web server.
HTTP:PHP:PHPNUKE:CID-SQL-INJECT
sos5.0.0,
sos5.1.0
medium
This signature detects attempts to exploit a SQL injection
vulnerability in the modules.php script that ships with
PHPNuke. PHPNuke 6.0 and earlier are vulnerable. Attackers
may produce a process that increases system load on the
server, making it unusable until the process is killed.
HTTP:PHP:PHPNUKE:MODULES-DOS
sos5.1.0
medium
This signature detects attempts to exploit a vulnerability in
the authform.inc.php script included in the PHProjekt
package. Attackers may supply a remote location in the
'path_pre' input parameter to force the target to download
and execute arbitrary PHP code from the remote location.
HTTP:PHP:PHPROJEKT-INC
sos5.0.0,
sos5.1.0
high
This signature detects attempts to exploit a vulnerability in
phpWebsite. Version 0.8.2 and earlier are vulnerable.
Attackers may specify a remote file location for file inclusion
to cause phpWebsite to execute arbitrary PHP code;
attackers may execute commands with HTTP daemon user
permissions.
HTTP:PHP:PHPWEB-REMOTE-FILE
sos5.0.0,
sos5.1.0
high
This signature detects attempts to exploit a vulnerability in
pMachine, an online publishing application. pMachine version
2.2.1 and other versions are vulnerable. Attackers may send
a malicious HTTP request to force the pMachine Web server
to execute PHP code from a remote server; commands are
executed with web server privileges.
HTTP:PHP:PMACHINE-INCLUDE
Copyright © 2010, Juniper Networks, Inc.
892
Network and Security Manager Administration Guide
Содержание NETWORK AND SECURITY MANAGER 2010.3
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Страница 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Страница 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 94 Network and Security Manager Administration Guide...
Страница 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Страница 234: ...Copyright 2010 Juniper Networks Inc 184 Network and Security Manager Administration Guide...
Страница 310: ...Copyright 2010 Juniper Networks Inc 260 Network and Security Manager Administration Guide...
Страница 364: ...Copyright 2010 Juniper Networks Inc 314 Network and Security Manager Administration Guide...
Страница 366: ...Copyright 2010 Juniper Networks Inc 316 Network and Security Manager Administration Guide...
Страница 478: ...Copyright 2010 Juniper Networks Inc 428 Network and Security Manager Administration Guide...
Страница 576: ...Copyright 2010 Juniper Networks Inc 526 Network and Security Manager Administration Guide...
Страница 580: ...Copyright 2010 Juniper Networks Inc 530 Network and Security Manager Administration Guide...
Страница 592: ...Copyright 2010 Juniper Networks Inc 542 Network and Security Manager Administration Guide...
Страница 684: ...Copyright 2010 Juniper Networks Inc 634 Network and Security Manager Administration Guide...
Страница 690: ...Copyright 2010 Juniper Networks Inc 640 Network and Security Manager Administration Guide...
Страница 696: ...Copyright 2010 Juniper Networks Inc 646 Network and Security Manager Administration Guide...
Страница 698: ...Copyright 2010 Juniper Networks Inc 648 Network and Security Manager Administration Guide...
Страница 748: ...Copyright 2010 Juniper Networks Inc 698 Network and Security Manager Administration Guide...
Страница 778: ...Copyright 2010 Juniper Networks Inc 728 Network and Security Manager Administration Guide...
Страница 870: ...Copyright 2010 Juniper Networks Inc 820 Network and Security Manager Administration Guide...
Страница 872: ...Copyright 2010 Juniper Networks Inc 822 Network and Security Manager Administration Guide...
Страница 898: ...Copyright 2010 Juniper Networks Inc 848 Network and Security Manager Administration Guide...
Страница 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Страница 910: ...Copyright 2010 Juniper Networks Inc 860 Network and Security Manager Administration Guide...
Страница 995: ...PART 6 Index Index on page 947 945 Copyright 2010 Juniper Networks Inc...
Страница 996: ...Copyright 2010 Juniper Networks Inc 946 Network and Security Manager Administration Guide...