CGI abuses Family for Nessus

IDNameSeverity
14224Simple Form Multiple Parameter Arbitrary Mail Relaying
medium
14269YaPiG < 0.92.2 Multiple Scripts Arbitrary Command Execution
high
14260Nikto (NASL wrapper)
info
14258phpMyFAQ index.php action Parameter Local File Inclusion
medium
14255Microsoft Outlook Web Access (OWA) Version Detection
info
14308BasiliX Application Detection
info
14306Basilix Webmail tmp Directory Permission Weakness Attachment Disclosure
low
14305Basilix Webmail Attachment Crafted POST Arbitrary File Access
medium
14304BasiliX login.php3 username Variable Arbitrary Command Execution
medium
14237GoScript go.cgi Arbitrary Command Execution
high
14233ASPrunner 2.4 Multiple Vulnerabilities
high
14232PSCS VPOP3 messagelist.html msglistlen Parameter DoS
medium
14226phpBB Fetch All < 2.0.12 Multiple Scripts SQL Injection
high
14220CVSTrac filediff Arbitrary Remote Code Execution
high
14219Basilix Webmail id Variable SQL Injection
medium
14227Snitz Forums 2000 < 3.4.03 register.asp Email Parameter SQL Injection
high
14222RiSearch show.pl Arbitrary File Access
medium
14194Nucleus CMS action.php itemid Parameter SQL Injection
high
14193Polar HelpDesk Authentication Bypass
high
14191Tivoli Directory Server ldacgi.exe Template Parameter Traversal Arbitrary File Access
medium
14190PostNuke Install Script Admin Password Disclosure
high
14188phpMyFAQ Image Upload Authentication Bypass
high
14187AntiBoard antiboard.php Multiple Parameter SQL Injection
medium
14183Comersus Cart Multiple Input Validation Vulnerabilities (SQLi, XSS)
high
14182MyServer 0.6.2 math_sum.mscgi Multiple Vulnerabilities
high
14180RiSearch show.pl Open Proxy Relay
high
13859osTicket open.php Support Address Crafted Mail Loop Remote DoS
high
13858osTicket Detection
info
13849Horde Chora Software Detection
info
13847OpenDocMan Access Control Bypass
medium
13845EasyWeb FileManager pathtext Traversal Arbitrary File/Directory Access
medium
13842Mensajeitor Tag Board Admin Bypass
medium
13655phpBB < 2.0.9 Multiple Vulnerabilities
high
13650PHP < 4.3.8 Multiple Vulnerabilities
medium
13648osTicket Arbitrary Attachment Disclosure
medium
13647osTicket setup.php Accessibility
medium
13646osTicket Form Field Modification File Upload Size Restriction Bypass
medium
13645osTicket Attachment Handling File Upload Arbitrary Code Execution
high
13635Bugzilla < 2.16.6 / 2.18rc1 Multiple Vulnerabilities (XSS, SQLi, Priv Esc, more)
medium
12647SquirrelMail Detection
info
14221Open WebMail Detection
info
12643IMP Software Detection
info
12637Open WebMail vacation.pl Arbitrary Command Execution
high
12300Inktomi Search MS-DOS Device Name Request Path Disclosure
medium
12295Dell OpenManage Server Administrator Detection
info
12281Horde Chora CVS Viewer diff Utility Arbitrary Command Execution
high
12278Gallery init.php Authentication Bypass
high
12272US Robotics Broadband Router 8003 menu.htm Admin Password Disclosure
critical
12271MS04-017: Crystal Reports Web Viewer Could Allow Information Disclosure and DoS (842689) (uncredentialed check)
high
12269EDIMAX Wireless AP Default Password Check
critical