Thanks for the info, I did a search for those files on all of the hard drives and the search came up empty.
 
I think the plugin that is generating the hit is plugin 11952
 
Family Windows
Nessus Plugin ID 11952
Bugtraq ID
CVE ID

Description:

The remote host is running a version of flash player older than 7.0.19.0.

This version can be abused in conjunction with several flaws in the web
browser to read local files on this system.

To exploit this flaw, an attacker would need to lure a user of this system
into visiting a rogue website containing a malicious flash applet.

Solution : Upgrade to version 7.0.19.0 or newer.
See also : http://www.macromedia.com/devnet/security/security_zone/mpsb03-08.html
Risk factor : High
 
 
Thanks --John
-------------- Original message --------------
From: Nicolas Pouvesle <[EMAIL PROTECTED]>

>
> On Jan 25, 2006, at 9:50 AM, [EMAIL PROTECTED] wrote:
>
> > That's the issue, flash is not installed. Does it query the version
> > of a DLL, how does it determine if Flash is installed.
> >
>
> The nasl script gets the following file versions :
>
> %systemroot%\System32\Macromed\Flash\Flash.ocx
> %systemroot%\System32\Macromed\Flash\SWFlash.ocx
>
>
> Nicolas
> _______________________________________________
> Nessus mailing list
> [email protected]
> http://mail.nessus.org/mailman/listinfo/nessus
_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to