CGI abuses Family for Nessus

IDNameSeverity
22497HAMweather Template.php do_parse_code Function Arbitrary Code Execution
high
22496OpenBiblio < 0.5.2 Multiple Scripts Local File Inclusion
high
22480UBB.threads doeditconfig Arbitrary Command Injection
high
22475DokuWiki fetch.php Multiple Parameter imconvert Function Arbitrary Command Execution
high
22448CakePHP vendors.php file Parameter Traversal Arbitrary File Access
medium
22413MyReview Admin.php email Parameter SQL Injection
high
22412Exponent CMS index.php view Parameter Local File Inclusion
medium
22409Claroline Software Detection
info
22408Limbo com_fm Component sql.php classes_dir Parameter Remote File Inclusion
medium
22368Site@School Multiple Script cmsdir Parameter Remote File Inclusion
high
22367Limbo Contact Component (com_contact) contact.html.php contact_attach Unrestricted File Upload
high
22366Dokeos claro_init_local.inc.php extAuthSource Parameter Array Remote File Inclusion
medium
22365Claroline claro_init_local.inc.php extAuthSource[newUser] Parameter Remote File Inclusion
medium
22364Moodle < 1.6.2 Multiple Vulnerabilities
high
22362TWiki 'filename' Parameter Traversal Arbitrary File Access
medium
22317RaidenHTTPD check.php SoftParserFileXml Parameter Remote File Inclusion
medium
22316PHP-Fusion extract() Global Variable Overwriting
low
22315DokuWiki doku.php X-FORWARDED-FOR HTTP Header Arbitrary Code Injection
high
22310PmWiki < 2.1.21 Global Variables Overwriting
high
22309SAP DB / MaxDB WebDBM Client Database Name Remote Overflow
critical
22307Mailman Utils.py Spoofed Log Entry Injection
low
22306WebAdmin < 3.2.6 MDaemon Account Hijacking
medium
22305Easy Address Book Web Server Query Remote Format String
medium
22303TikiWiki jhot.php Arbitrary File Upload
high
22300Webmin Null Byte Filtering Information Disclosure
medium
22299e107 ibrowser.php zend_has_del() Function Remote Code Execution
high
22298Joomla! < 1.0.11 Unspecified Remote Code Execution
medium
22297Joomla! < 1.0.11 administrator/index.php Input Weakness
medium
22296CubeCart < 3.0.13 Multiple Remote Vulnerabilities (LFI, SQLi, XSS)
high
22295Feedsplitter <= 2006-01-21 Multiple Remote Vulnerabilities (XSS, Traversal, Disc)
high
22272Fuji Xerox Printing Systems (FXPS) Print Engine Crafted Request HTTP Authentication Bypass
medium
22271PHProjekt <= 5.1 Multiple Remote File Inclusions
high
22268PHP < 4.4.3 / 5.1.4 Multiple Vulnerabilities
high
22267phpCOIN Multiple Script _CCFG Parameter Remote File Inclusion
medium
22257WebAdmin < 3.2.5 Multiple Vulnerabilities
high
22255osCommerce shopping_cart.php id Array Parameters SQL Injection
high
22235Docebo GLOBALS Variable Overwrite Remote File Inclusion
medium
22234Zen Cart autoload_func.php autoLoadConfig Array Remote File Inclusion
medium
22233Zen Cart ipn_main_handler.php custom SQL Injection
high
22232Owl Intranet Engine <= 0.91 Multiple Vulnerabilities
high
22231CubeCart < 3.0.12 Multiple Vulnerabilities (SQLi, XSS)
high
22230SquirrelMail compose.php session_expired_post Arbitrary Variable Overwriting
medium
22206WEBInsta CMS index.php templates_dir Parameter Remote File Inclusion
high
22205IPCheck Server Monitor Traversal Arbitrary File Access
medium
22204Ruby on Rails Routing Code URL Code Evaluation DoS
high
22203Apache on Windows mod_alias URL Validation Canonicalization CGI Source Disclosure
medium
22130Barracuda Spam Firewall Default Credentials
high
22124phpMyAdmin import_blacklist Variable Overwriting
medium
22123TWiki configure Script Arbitrary Command Execution
high
22117PatchLink Update Server proxyreg.asp Arbitrary Proxy Manipulation
high