CGI abuses Family for Nessus

IDNameSeverity
20176MailWatch authenticate() Function SQL Injection
medium
20171Horde Admin Account Default Password
critical
20170phpWebThings Multiple Scripts SQL Injection
high
20169PHPFM Arbitrary File Upload
high
20168toendaCMS < 0.6.2.1 Multiple Vulnerabilities
medium
20137CuteNews Multiple Script Traversal Privilege Escalation
high
20133vCard define.inc.php match Parameter Remote File Inclusion
high
20132phpBB <= 2.0.17 Multiple Vulnerabilities
high
20131Comersus BackOffice comersus_backoffice_menu.asp Multiple Parameter SQL Injection
high
20130Comersus Cart /comersus/database/comersus.mdb Direct Request Datbase Disclosure
medium
20129e107 Detection
info
20112Invision Gallery index.php st Parameter SQL Injection
high
20111PHP < 4.4.1 / 5.0.6 Multiple Vulnerabilities
high
20110GNUMP3d < 2.9.6 Multiple Remote Vulnerabilities (XSS, Traversal)
medium
20095ATutor < 1.5.1-pl1 Multiple Remote Vulnerabilities (XSS, RFI, Command Exe)
high
20093Mantis < 0.19.3 Multiple Vulnerabilities
medium
20091PHP iCalendar index.php phpicalendar Parameter Remote File Inclusion
medium
20088phpMyAdmin < 2.6.4-pl3 Multiple Vulnerabilities
medium
20069e107 resetcore.php user Field SQL Injection
high
20068TWiki %INCLUDE Parameter Arbitrary Command Injection
medium
20061w-Agora <= 4.2.0 Multiple Vulnerabilities
high
20015Gallery main.php g2_itemId Parameter Traversal Arbitrary File Access
medium
20014WebGUI < 6.7.6 Asset.pm Asset Addition Arbitrary Code Execution
high
20013PunBB search.php old_searches Parameter SQL Injection
medium
20011phpWebSite index.php Search Module SQL Injection
high
20009PHP-Fusion < 6.00.110 Multiple Scripts SQL Injection
medium
19950phpMyAdmin grab_globals.lib.php subform Parameter Traversal Local File Inclusion
medium
19949MediaWiki < 1.3.17 / 1.4.11 / 1.5.0 Multiple Vulnerabilities
medium
19947Mailgust Password Reminder email Field SQL Injection
medium
19942GuppY < 4.5.6a Multiple Vulnerabilities
medium
19941TWiki Detection
info
199393Com Network Supervisor Traversal Arbitrary File Access
high
19784IceWarp Web Mail Multiple Flaws (4)
high
19780Alkalay.Net Multiple Scripts Arbitrary Command Execution
high
19779Interchange < 5.0.2 / 5.2.1 Multiple Vulnerabilities (SQLi, Code Exe)
high
19778phpMyFAQ < 1.5.2 Multiple Vulnerabilities
medium
19776Movable Type < 3.2 Multiple Vulnerabilities
medium
19775PunBB < 1.2.8 Multiple Vulnerabilities
medium
19774Land Down Under HTTP Referer Header SQL Injection
medium
19770Digital Scribe login.php SQL Injection
high
19768PHP Advanced Transfer Manager <= 1.30 Multiple Vulnerabilities
medium
19765ATutor Password Reminder SQL Injection
high
19760vBulletin <= 3.0.9 Multiple Vulnerabilities
high
19756CuteNews flood.db.php Client-IP HTTP Header Arbitrary Code Injection
high
19755Hosting Controller <= 6.1 Hotfix 2.3 Information Disclosure Vulnerabilities
medium
19753phpGroupWare < 0.9.16 Addressbook Unspecified Vulnerability
low
19751Discuz! <= 4.0.0 rc4 Arbitrary File Upload
medium
19750DeluxeBB Multiple Scripts SQL Injection
high
19749Calendar Express Multiple Vulnerabilities (SQLi, XSS)
high
19748Sendcard sendcard.php id Parameter SQL Injection
high