CGI abuses Family for Nessus

IDNameSeverity
34031TWiki bin/configure 'image' Parameter Traversal Arbitrary File Access/Execution
high
34029Kayako SupportSuite < 3.30.01 Multiple Vulnerabilities
medium
33927Web Server Generic 3xx Redirect
medium
33926Adobe Dreamweaver dwsync.xml Remote Information Disclosure
medium
33925dotCMS Multiple Script id Parameter Traversal Local File Inclusion
medium
33903MailScan WebAdministrator Cookie Authentication Bypass
high
33882Joomla! reset.php Reset Token Validation Forgery
critical
33869JBoss Enterprise Application Platform (EAP) Status Servlet Request Remote Information Disclosure
medium
33867Novell iManager < 2.7 SP1 Property Book Pages Arbitrary Plug-in Studio Deletion
medium
33866Apache Tomcat allowLinking UTF-8 Traversal Arbitrary File Access
medium
33860RTH login.php uname Parameter SQL Injection
medium
33856e107 download.php extract() Function Variable Overwrite
high
33849PHP < 4.4.9 Multiple Vulnerabilities
high
33848Pligg settemplate.php template Parameter Local File Inclusion
medium
33823Plogger plog-download.php checked[] Parameter SQL Injection
medium
33822XAMPP Example Pages Detection
high
33821.svn/entries Disclosed via Web Server
medium
33811Symphony sym_auth Cookie SQL Injection
high
33789Coppermine Photo Gallery include/functions.inc.php _data Cookie lang Parameter Traversal Local File Inclusion
medium
33761Gregarius ajax.php rsargs[] Parameter Array SQL Injection
high
33546fuzzylime (cms) comssrss.php files[] Parameter Traversal Local File Inclusion
high
33532CGI::Session File Driver CGISESSID Cookie Traversal Authentication Bypass
medium
33483Maian Scripts Cookie Manipulation Authentication Bypass
high
33479Mambo < 4.6.5 mos_user_template Local File Inclusion
medium
33478Xerox CentreWare Web < 4.6.46 Multiple Vulnerabilities (XRX08-008)
medium
33446Dolphin Multiple Scripts Remote File Inclusion
medium
33445trixbox Dashboard user/index.php langChoice Parameter Local File Inclusion
high
33439Sun Java System ASP < 4.0.3 Multiple Vulnerabilities
critical
33437Sun Java ASP Server Default Admin Password
high
33391Wordtrans-web exec_wordtrans Function Arbitrary Command Execution
high
33274TrailScout Module For Drupal Session Cookie SQL Injection
high
33272nBill component for Joomla! 'cid' Parameter SQLi
high
33271Trac quickjump Search Script q Parameter Arbitrary Site Redirect
medium
33270ASP.NET DEBUG Method Enabled
medium
33269Ektron CMS400.NET WorkArea/ContentRatingGraph.aspx res Parameter SQL Injection
high
33103LifeType for Drupal (pLog) index.php albumId Parameter SQL Injection
high
32505AEC Subscription Manager Component for Mambo / Joomla! 'usage' Parameter SQLi
high
32475Symantec Backup Exec System Recovery Manager Traversal Arbitrary File Access
medium
32381ViewVC Direct Request CVSROOT Information Disclosure
medium
32325Site Documentation Module for Drupal Database Tables Access Content Permission Information Disclosure
high
32324Mantis manage_user_create.php CSRF New User Creation
medium
32318Web Site Cross-Domain Policy File Detection
info
32317DatsoGallery Component for Joomla! sub_votepic.php User-Agent HTTP Header SQLi
high
32124Webhosting Component for Joomla! 'catid' Parameter SQLi
high
32123PHP < 5.2.6 Multiple Vulnerabilities
high
32122ActualAnalyzer Lite style Parameter Traversal Local File Inclusion
medium
32080WordPress index.php 'cat' Parameter Local File Inclusion
medium
32032Red Hat Administration Server (redhat-ds-admin) Multiple Remote Vulnerabilities
high
32030XOOPS Article Module article.php id Parameter SQL Injection
high
31865WEBrick Encoded Traversal Arbitrary CGI Source Disclosure
medium