CGI abuses Family for Nessus

IDNameSeverity
34209Simple Machines Forum Validation Code Prediction Arbitrary Password Reset
high
34202Calendarix Basic cal_cat.php catview Parameter SQL Injection
high
34169pluck < 4.5.3 Multiple Local File Include Vulnerabilities
medium
34110Simple PHP Blog config/users.php Arbitrary User Password Hash Disclosure
medium
34109Simple PHP Blog Detection
info
34108Zen Cart products_id[] Array SQL Injection
medium
34095Moodle 'lib/kses.php' 'kses_bad_protocol_once' Function Arbitrary PHP Code Execution
high
34055AWStats Totals awstatstotals.php multisort() Function sort Parameter Arbitrary PHP Code Execution
high
34031TWiki bin/configure 'image' Parameter Traversal Arbitrary File Access/Execution
high
34029Kayako SupportSuite < 3.30.01 Multiple Vulnerabilities
medium
33927Web Server Generic 3xx Redirect
medium
33926Adobe Dreamweaver dwsync.xml Remote Information Disclosure
medium
33925dotCMS Multiple Script id Parameter Traversal Local File Inclusion
medium
33903MailScan WebAdministrator Cookie Authentication Bypass
high
33882Joomla! reset.php Reset Token Validation Forgery
critical
33869JBoss Enterprise Application Platform (EAP) Status Servlet Request Remote Information Disclosure
medium
33867Novell iManager < 2.7 SP1 Property Book Pages Arbitrary Plug-in Studio Deletion
medium
33866Apache Tomcat allowLinking UTF-8 Traversal Arbitrary File Access
medium
33860RTH login.php uname Parameter SQL Injection
medium
33856e107 download.php extract() Function Variable Overwrite
high
33849PHP < 4.4.9 Multiple Vulnerabilities
high
33848Pligg settemplate.php template Parameter Local File Inclusion
medium
33823Plogger plog-download.php checked[] Parameter SQL Injection
medium
33822XAMPP Example Pages Detection
high
33821.svn/entries Disclosed via Web Server
medium
33811Symphony sym_auth Cookie SQL Injection
high
33789Coppermine Photo Gallery include/functions.inc.php _data Cookie lang Parameter Traversal Local File Inclusion
medium
33761Gregarius ajax.php rsargs[] Parameter Array SQL Injection
high
33546fuzzylime (cms) comssrss.php files[] Parameter Traversal Local File Inclusion
high
33532CGI::Session File Driver CGISESSID Cookie Traversal Authentication Bypass
medium
33483Maian Scripts Cookie Manipulation Authentication Bypass
high
33479Mambo < 4.6.5 mos_user_template Local File Inclusion
medium
33478Xerox CentreWare Web < 4.6.46 Multiple Vulnerabilities (XRX08-008)
medium
33446Dolphin Multiple Scripts Remote File Inclusion
medium
33445trixbox Dashboard user/index.php langChoice Parameter Local File Inclusion
high
33439Sun Java System ASP < 4.0.3 Multiple Vulnerabilities
critical
33437Sun Java ASP Server Default Admin Password
high
33391Wordtrans-web exec_wordtrans Function Arbitrary Command Execution
high
33274TrailScout Module For Drupal Session Cookie SQL Injection
high
33272nBill component for Joomla! 'cid' Parameter SQLi
high
33271Trac quickjump Search Script q Parameter Arbitrary Site Redirect
medium
33270ASP.NET DEBUG Method Enabled
medium
33269Ektron CMS400.NET WorkArea/ContentRatingGraph.aspx res Parameter SQL Injection
high
33103LifeType for Drupal (pLog) index.php albumId Parameter SQL Injection
high
32505AEC Subscription Manager Component for Mambo / Joomla! 'usage' Parameter SQLi
high
32475Symantec Backup Exec System Recovery Manager Traversal Arbitrary File Access
medium
32381ViewVC Direct Request CVSROOT Information Disclosure
medium
32325Site Documentation Module for Drupal Database Tables Access Content Permission Information Disclosure
high
32324Mantis manage_user_create.php CSRF New User Creation
medium
32318Web Site Cross-Domain Policy File Detection
info