CGI abuses Family for Nessus

IDNameSeverity
38832HP System Management Homepage < 3.0.1.73 Multiple Flaws
medium
38828Flyspeck lang Parameter Local File Inclusion
medium
38794SquirrelMail map_yp_alias Username Mapping Alias Arbitrary Code Execution
high
38762Open Virtual Desktop Detection
info
38717IceWarp Merak WebMail Server < 9.4.2 Multiple Vulnerabilities
medium
38701Oracle GlassFish Server Administration Console Default Credentials
high
38695Sun Java System Identity Manager ext Parameter Arbitrary File Retrieval
high
38694LimeSurvey sUser Parameter SQL Injection
high
38688Openfire < 3.6.4 jabber:iq:auth Crafted password_change Request Password Manipulation
medium
38665OpenCart route Parameter Local File Inclusion
medium
38653Symantec Reporting Server Improper URL Handling Exposure
medium
38648Atmail Webmail / AtmailOpen Webmail Detection
info
38198Sun Java System Identity Manager Account Disclosure
medium
38183ClearSpace Detection
info
38156FogBugz Interface Detection
info
38155Fortify 360 Web Interface Detection
info
38152Linksys WVC54GCA Wireless-G '/img/main.cgi' Information Disclosure
medium
36205Novell Teaming Login User Account Enumeration Weakness
medium
36171phpMyAdmin Setup Script Configuration Parameters Arbitrary PHP Code Injection (PMASA-2009-4)
high
36170phpMyAdmin setup.php save Action Arbitrary PHP Code Injection (PMASA-2009-3)
high
36144Geeklog SEC_authenticate Function SQL Injection
high
36143Geeklog Detection
info
36129HP LaserJet Web Server Unspecified Admin Component Traversal Arbitrary File Access
high
36102Jinzora name Parameter Local File Inclusion
medium
36083phpMyAdmin file_path Parameter Vulnerabilities (PMASA-2009-1)
medium
36074MapServer < 5.2.2 / 4.10.4 Multiple Flaws
high
36050Moodle LaTeX Information Disclosure
medium
36019Tenable Security Center Default Credentials
high
36018Sitecore CMS < 5.3.2 rev. 090212 Web Service Security Database Information Disclosure
medium
36017NextApp Echo XML Parsing Information Disclosure Vulnerability
high
35975AWStats 'awstats.pl' Path Disclosure
medium
35974AWStats Detection
info
35805OneOrZero Helpdesk default_language Local File Inclusion
medium
35803zFeeder admin.php Direct Request Admin Authentication Bypass
high
35787Zabbix Web Interface extlang[] Parameter Remote Code Execution
high
35786Zabbix Web Interface Detection
info
35765Coppermine Photo Gallery keysToSkip Parameter Overwrite
medium
35751Drupal Theme System Template Local File Inclusion
high
35750PHP < 5.2.9 Multiple Vulnerabilities
medium
35749Moodle Forum 'post.php' Unauthorized Post Deletion CSRF
medium
35661SquirrelMail HTTPS Session Cookie Secure Flag Weakness
medium
35657HP OpenView Network Node Manager webappmon.exe Command Injection (c01661610)
high
35656HP OpenView Network Node Manager ovlaunch.exe Information Disclosure (c01661610)
medium
35655TYPO3 'jumpUrl' Mechanism Information Disclosure
medium
35649Trend Micro InterScan Web Security Suite Default Credentials
high
35628Openfire < 3.6.3 Multiple Vulnerabilities
medium
35618Sun OpenSSO / Java System Access Manager Login Module User Account Enumeration Weakness
medium
35610Jaws language Parameter Multiple Local File Includes
high
35609SocialEngine Blog Plugin category_id Parameter SQL Injection
high
35600Meeting Room Booking System (MRBS) month.php area Parameter SQL Injection
high