CGI abuses Family for Nessus

IDNameSeverity
35363Oracle Secure Backup Administration Server login.php Arbitrary Command Injection
critical
35326XOOPS Multiple Scripts mydirname Parameter Arbitrary Command Injection
high
35321XStandard Lite Plugin for Joomla! X_CMS_LIBRARY_PATH Header Directory Traversal
medium
35278XOOPS xoopsConfig[language] Parameter Local File Inclusion (DSECRG-08-040)
medium
35273RoundCube Webmail bin/html2text.php Post Request Remote PHP Code Execution
high
35262Pligg evb/check_url.php url Parameter SQL Injection
medium
35261OneOrZero Helpdesk tinfo.php Arbitrary File Upload
high
35259phpList cline Parameter Array Remote File Inclusion
high
35224Barracuda Spam Firewall < 3.5.12.007 Multiple Vulnerabilities
medium
35109Live Chat Component for Joomla! 'last' Parameter Multiple SQLi
high
35105Sun Java System Identity Manager Default Credentials
high
35104Sun Java System Identity Manager Detection
info
35090Moodle 'filter/tex/texed.php' 'pathname' Parameter Remote Command Execution
medium
35067PHP < 5.2.8 Multiple Vulnerabilities
high
35060phpPgAdmin index.php _language Parameter Local File Inclusion
medium
35043PHP 5 < 5.2.7 Multiple Vulnerabilities
high
35041Oempro index.php FormValue_Email Parameter SQL Injection Authentication Bypass
high
35029Dell Remote Access Controller Default Password (calvin) for 'root' Account
critical
35008OraMon config/oramon.ini Information Disclosure
medium
34992CMS Made Simple admin/login.php cms_language Cookie Local File Inclusion
medium
34947Apache Struts 2 devMode Information Disclosure
medium
34946Apache Struts 2 < 2.0.12 / 2.1.3 Dispatcher Directory Traversal
high
34726PHPWebAdmin for hMailServer Multiple File Inclusions
medium
34725Openfire AuthCheck Authentication Bypass
high
34507Eaton Network Shutdown Module < 3.20 Authentication Bypass / Command Execution
critical
34448yappa-ng index.php album Parameter Local File Inclusion
medium
34443Security Center < 3.4.2.1 Directory Traversal Arbitrary File Access
medium
34420Ignite Gallery Component for Joomla! 'gallery' Parameter SQLi
high
34419PhpWebGallery comments.php sort_by Parameter SQL Injection
high
34399GForge top/topusers.php offset Parameter SQL Injection
high
34397ASG-Sentry File Check Utility /snmx-cgi/fcheck.exe Arbitrary File Overwrite
high
34395ASG-Sentry CGI Default Credentials
high
34394ASG-Sentry CGI Detection
info
34373OpenX ac.php bannerid Parameter SQL Injection
high
34372Openads Delivery Engine OA_Delivery_Cache_store() Function name Argument Arbitrary PHP Code Execution
high
34351OpenNMS Web Console Default Credentials
high
34350OpenNMS Web Console Detection
info
34338phpScheduleIt reserve.php start_date Parameter Arbitrary Command Injection
high
34337phpScheduleIt Detection
info
34304Pluck update.php Remote Privilege Escalation
medium
34293MailWatch for MailScanner mailscanner/docs.php doc Parameter Traversal Local File Inclusion
medium
34292Observer <= 0.3.2.1 Multiple Remote Command Execution Vulnerabilities
high
34209Simple Machines Forum Validation Code Prediction Arbitrary Password Reset
high
34202Calendarix Basic cal_cat.php catview Parameter SQL Injection
high
34169pluck < 4.5.3 Multiple Local File Include Vulnerabilities
medium
34110Simple PHP Blog config/users.php Arbitrary User Password Hash Disclosure
medium
34109Simple PHP Blog Detection
info
34108Zen Cart products_id[] Array SQL Injection
medium
34095Moodle 'lib/kses.php' 'kses_bad_protocol_once' Function Arbitrary PHP Code Execution
high
34055AWStats Totals awstatstotals.php multisort() Function sort Parameter Arbitrary PHP Code Execution
high