CGI abuses Family for Nessus

IDNameSeverity
38688Openfire < 3.6.4 jabber:iq:auth Crafted password_change Request Password Manipulation
medium
38665OpenCart route Parameter Local File Inclusion
medium
38653Symantec Reporting Server Improper URL Handling Exposure
medium
38648Atmail Webmail / AtmailOpen Webmail Detection
info
38198Sun Java System Identity Manager Account Disclosure
medium
38183ClearSpace Detection
info
38156FogBugz Interface Detection
info
38155Fortify 360 Web Interface Detection
info
38152Linksys WVC54GCA Wireless-G '/img/main.cgi' Information Disclosure
medium
36205Novell Teaming Login User Account Enumeration Weakness
medium
36171phpMyAdmin Setup Script Configuration Parameters Arbitrary PHP Code Injection (PMASA-2009-4)
high
36170phpMyAdmin setup.php save Action Arbitrary PHP Code Injection (PMASA-2009-3)
high
36144Geeklog SEC_authenticate Function SQL Injection
high
36143Geeklog Detection
info
36129HP LaserJet Web Server Unspecified Admin Component Traversal Arbitrary File Access
high
36102Jinzora name Parameter Local File Inclusion
medium
36083phpMyAdmin file_path Parameter Vulnerabilities (PMASA-2009-1)
medium
36074MapServer < 5.2.2 / 4.10.4 Multiple Flaws
high
36050Moodle LaTeX Information Disclosure
medium
36019Tenable Security Center Default Credentials
high
36018Sitecore CMS < 5.3.2 rev. 090212 Web Service Security Database Information Disclosure
medium
36017NextApp Echo XML Parsing Information Disclosure Vulnerability
high
35975AWStats 'awstats.pl' Path Disclosure
medium
35974AWStats Detection
info
35805OneOrZero Helpdesk default_language Local File Inclusion
medium
35803zFeeder admin.php Direct Request Admin Authentication Bypass
high
35787Zabbix Web Interface extlang[] Parameter Remote Code Execution
high
35786Zabbix Web Interface Detection
info
35765Coppermine Photo Gallery keysToSkip Parameter Overwrite
medium
35751Drupal Theme System Template Local File Inclusion
high
35750PHP < 5.2.9 Multiple Vulnerabilities
medium
35749Moodle Forum 'post.php' Unauthorized Post Deletion CSRF
medium
35661SquirrelMail HTTPS Session Cookie Secure Flag Weakness
medium
35657HP OpenView Network Node Manager webappmon.exe Command Injection (c01661610)
high
35656HP OpenView Network Node Manager ovlaunch.exe Information Disclosure (c01661610)
medium
35655TYPO3 'jumpUrl' Mechanism Information Disclosure
medium
35649Trend Micro InterScan Web Security Suite Default Credentials
high
35628Openfire < 3.6.3 Multiple Vulnerabilities
medium
35618Sun OpenSSO / Java System Access Manager Login Module User Account Enumeration Weakness
medium
35610Jaws language Parameter Multiple Local File Includes
high
35609SocialEngine Blog Plugin category_id Parameter SQL Injection
high
35600Meeting Room Booking System (MRBS) month.php area Parameter SQL Injection
high
35587phpSlash fields Parameter PHP Code Injection
high
35580Profense Web Application Firewall Default Credentials
high
35557OpenX fc.php MAX_type Parameter Traversal Local File Inclusion
high
35554Horde Horde_Image::factory driver Argument Local File Inclusion
high
35474gigCalendar Component for Joomla! 'gigcal_gigs_id' Parameter SQLi
medium
35435Eventing Component for Joomla! 'catid' Parameter SQLi
high
35402phpList <= 2.10.8 Variable Overwriting
high
35370WP-Forum Plugin for WordPress 'forum_feed.php' 'thread' Parameter SQL Injection
high