Home page logo
/

openvas logo OpenVAS mailing list archives

Re: NVT Description
From: Sebastien Aucouturier <s.aucouturier () itrust fr>
Date: Fri, 25 Jan 2013 17:49:56 +0100
List-id: OpenVAS plugins <openvas-plugins.wald.intevation.org>

Overview tell the facts when vulnerability is detect:
script_tag(name:"overview", value:"The remote host contains a CGI which
is vulnerable to a cross-site scripting issue.");

Well, this is basically redundant with <summary+"yes">.

Should be, but we got plugins, that now does not let us say that, as example :

gb_winftp_serv_bof_vuln.nasl :

summary is : Check for the version of WinFTP Server

when in overview part of field description we got :
Overview: This host is running WinFTP Server and is prone to Buffer Overflow vulnerability.

So here : overview is not summary+yes :-(


I'd rather prefer then texts like we use in _detect scripts already.

+1


Well, I am not settled here, but feel not happy with "overview".

me too,
not easy to find a suitable way to easily match , use and parse nowadays plugins with the multiple description form we got.


--
"Le saviez-vous ? la technologie d'ITrust va sécuriser le cloud français"

    | Sébastien AUCOUTURIER | Responsable R&D
    | ITrust | 55 L'Occitane 31670 LABEGE
    | Email: s.aucouturier () itrust fr
    | Fixe Sdt. 05.67.34.67.80
    | IT Security Services & SaaS Editor
_______________________________________________
Openvas-plugins mailing list
Openvas-plugins () wald intevation org
https://lists.wald.intevation.org/cgi-bin/mailman/listinfo/openvas-plugins

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]