CGI abuses Family for Nessus

IDNameSeverity
20379phpBB < 2.0.19 Multiple XSS
medium
20378PHP Support Tickets index.php Multiple Parameter SQL Injection
high
20376PHPSurveyor Multiple SQL Injections
high
20375Web Wiz check_user.asp txtUserName Parameter SQL Injection
high
20374phpDocumentor <= 1.3.0 RC4 Local And Remote File Inclusion
high
20373MyBB < 1.01 function_upload.php SQLi
high
20372Xaraya index.php module Parameter Traversal Arbitrary File/Directory Manipulation
medium
20349eFiction < 2.0.2 Multiple Remote Vulnerabilities (SQLi, XSS, Disc)
high
20348Cerberus Helpdesk GUI Agent < 2.7.1 Multiple Remote Vulnerabilities (SQLi, XSS)
high
20347Cerberus Support Center Multiple Remote Vulnerabilities (SQLi, XSS)
high
20346VisNetic / Merak Mail Server Multiple Remote Vulnerabilities
high
20343Webmin 'miniserv.pl' 'username' Parameter Format String
high
20342MyBB calendar.php 'month' Parameter SQLi
critical
20339PhpGedView PGV_BASE_DIRECTORY Parameter Remote File Inclusion
high
20338Plogger plog-admin-functions.php config Parameter Remote File Inclusion
high
20337FTGate <= 4.4.002 Multiple Remote Vulnerabilities (OF, FS, XSS)
high
20321ELOG Remote Buffer Overflow Vulnerabilities
high
20317vTiger < 4.5a2 Multiple Vulnerabilities
high
20303SimpleBBS topics.php name Parameter Arbitrary Command Execution
high
20300phpCOIN < 1.2.2 2005-12-13 Fix-File Multiple Vulnerabilities
high
20296The Includer includer.cgi Arbitrary Command Execution
high
20295ListManager Error Message Information Disclosure
medium
20294ListManager < 8.9b Multiple Vulnerabilities
high
20293FlatNuke index.php id Parameter Traversal Arbitrary File Access
medium
20292Contenido contenido/classes/class.inuse.php Multiple Parameter Remote File Inclusion
high
20286SugarCRM <= 4.0 beta acceptDecline.php Remote File Inclusion
high
20255MediaWiki Language Option eval() Function Arbitrary PHP Code Execution
high
20254Zen Cart password_forgotten.php admin_email Parameter SQL Injection
medium
20253DUware Multiple Products type.asp iType Parameter SQL Injection
high
20252Trac Ticket Query Module group Parameter SQL Injection
high
20251PHPX admin/index.php username Parameter SQL Injection
high
20250WebCalendar < 1.0.2 Multiple Vulnerabilities
high
20248GuppY <= 4.5.9 Multiple Remote Vulnerabilities (Traversal, Code Exec)
high
20246PHP Doc System index.php show Parameter Local File Inclusion
medium
20241Google Search Appliance proxystylesheet Parameter Multiple Remote Vulnerabilities (XSS, Code Exec, ID)
high
20227Winmail Server <= 4.2 Build 0824 Multiple Vulnerabilities
medium
20223Help Center Live module.php file Parameter Local File Inclusion
high
20222Mambo Open Source / Joomla! GLOBALS Variable Remote File Include
high
20216phpwcms 1.2.5 Multiple Vulnerabilities
medium
20215phpSysInfo < 2.4.1 Multiple Vulnerabilities
medium
20214CodeGrrl Applications Remote File Inclusion Vulnerabilities
medium
20213XOOPS xoopsConfig[language] Parameter Local File Inclusion (XOOPS_WFd205_xpl)
medium
20211Exponent CMS < 0.96.4 Multiple Remote Vulnerabilities (XSS, SQLi, Code Exe, Disc)
critical
20210Moodle < 1.5.3 Multiple SQL Injection Vulnerabilities
high
20185TikiWiki < 1.8.6 / 1.9.1 Multiple Vulnerabilities
medium
20180phpAdsNew XML-RPC Library Remote Code Injection
high
20176MailWatch authenticate() Function SQL Injection
medium
20171Horde Admin Account Default Password
critical
20170phpWebThings Multiple Scripts SQL Injection
high
20169PHPFM Arbitrary File Upload
high