CGI abuses Family for Nessus

IDNameSeverity
40872Kayako SupportSuite Ticket Subject XSS
medium
40824FlexCMS Login Cookie SQL Injection
high
40796phpSANE file_save Parameter Remote File Include
high
40773Web Application Potentially Sensitive CGI Parameter Detection
info
40668Google Analytics on An Internal Web Server Detection
info
40667Adobe ColdFusion On Apache Double Encoded NULL Byte Request File Content Disclosure
medium
40592WP-Syntax Plugin for WordPress 'apply_filters' function Command Execution
high
40578WordPress < 2.8.4 'wp-login.php' 'key' Parameter Remote Administrator Password Reset (uncredentialed check)
medium
40577WordPress < 2.8.4 Password Reset
medium
40552Spiceworks HTTP Response Accept Header Handling Overflow DoS
critical
40551CMS Made Simple url Parameter Arbitrary File Access
medium
40470Snitz Forums 2000 <= 3.4.07 register.asp 'Email' Parameter SQL Injection
high
40469Snitz Forums 2000 Detection
info
40419MODx config.js.php Information Disclosure
medium
40406CGI Generic Tests HTTP Errors
info
40354OpenWrt Router with a Blank Password (telnet check)
critical
40352phpMyAdmin Installation Not Password Protected
high
11139CGI Generic SQL Injection
high
40349eAccelerator encoder.php File Backup
high
40334Ruby on Rails HTTP Digest Authentication Bypass
high
40331Log Rover pword Parameter SQL Injection
high
39875FCKeditor.Java Connector Servlet 'CurrentFolder' Infinite Loop DoS
medium
39806FCKeditor 'CurrentFolder' Arbitrary File Upload
high
39790Adobe ColdFusion FCKeditor 'CurrentFolder' File Upload
high
39621FireStats < 1.6.2 Multiple Vulnerabilities
high
39617HP DDMI on Windows Unspecified Remote Agent Access
high
39616HP DDMI Web Interface Default Credentials
high
39537Movable Type Detection
info
39536BASE < 1.2.5 readRoleCookie() Auth Bypass
high
39535Basic Analysis and Security Engine Authentication Check
medium
39501Zen Cart password_forgotten.php Admin Access Bypass
high
39500Zen Cart Detection
info
39482Acajoom Component for Joomla! <= 3.2.6 Backdoor Detection
high
39480PHP < 5.2.10 Multiple Vulnerabilities
medium
39470CGI Generic Tests Timeout
info
39469CGI Generic Remote File Inclusion
high
39468CGI Generic Header Injection
medium
39467CGI Generic Path Traversal
medium
39465CGI Generic Command Execution
high
39447Apache Tomcat RequestDispatcher Directory Traversal Arbitrary File Access
medium
39365Drupal SA-CONTRIB-2009-036: Services Module Key-Based Access Bypass
medium
39314Sun Java System Directory Server Online Help Feature Information Disclosure
medium
38974JVideo! Component for Joomla! 'user_id' Parameter SQLi
high
38952CrashPlan Server Default Administrative Credentials
high
38926DokuWiki config_cascade Parameter Remote File Inclusion
medium
38925WP-Lytebox 'pg' Parameter Local File Inclusion
medium
38890VICIDIAL Call Center Suite Default Administrative Credentials
high
38889VICIDIAL Call Center Suite admin.php SQL Injection
medium
38888TinyWebGallery lang Parameter Local File Inclusion
high
38879Coppermine Photo Gallery GLOBALS[USER[lang] Parameter Local File Inclusion
medium