CGI abuses Family for Nessus

IDNameSeverity
35060phpPgAdmin index.php _language Parameter Local File Inclusion
medium
35043PHP 5 < 5.2.7 Multiple Vulnerabilities
high
35041Oempro index.php FormValue_Email Parameter SQL Injection Authentication Bypass
high
35029Dell Remote Access Controller Default Password (calvin) for 'root' Account
critical
35008OraMon config/oramon.ini Information Disclosure
medium
34992CMS Made Simple admin/login.php cms_language Cookie Local File Inclusion
medium
34947Apache Struts 2 devMode Information Disclosure
medium
34946Apache Struts 2 < 2.0.12 / 2.1.3 Dispatcher Directory Traversal
high
34726PHPWebAdmin for hMailServer Multiple File Inclusions
medium
34725Openfire AuthCheck Authentication Bypass
high
34507Eaton Network Shutdown Module < 3.20 Authentication Bypass / Command Execution
critical
34448yappa-ng index.php album Parameter Local File Inclusion
medium
34443Security Center < 3.4.2.1 Directory Traversal Arbitrary File Access
medium
34420Ignite Gallery Component for Joomla! 'gallery' Parameter SQLi
high
34419PhpWebGallery comments.php sort_by Parameter SQL Injection
high
34399GForge top/topusers.php offset Parameter SQL Injection
high
34397ASG-Sentry File Check Utility /snmx-cgi/fcheck.exe Arbitrary File Overwrite
high
34395ASG-Sentry CGI Default Credentials
high
34394ASG-Sentry CGI Detection
info
34373OpenX ac.php bannerid Parameter SQL Injection
high
34372Openads Delivery Engine OA_Delivery_Cache_store() Function name Argument Arbitrary PHP Code Execution
high
34351OpenNMS Web Console Default Credentials
high
34350OpenNMS Web Console Detection
info
34338phpScheduleIt reserve.php start_date Parameter Arbitrary Command Injection
high
34337phpScheduleIt Detection
info
34304Pluck update.php Remote Privilege Escalation
medium
34293MailWatch for MailScanner mailscanner/docs.php doc Parameter Traversal Local File Inclusion
medium
34292Observer <= 0.3.2.1 Multiple Remote Command Execution Vulnerabilities
high
34209Simple Machines Forum Validation Code Prediction Arbitrary Password Reset
high
34202Calendarix Basic cal_cat.php catview Parameter SQL Injection
high
34169pluck < 4.5.3 Multiple Local File Include Vulnerabilities
medium
34110Simple PHP Blog config/users.php Arbitrary User Password Hash Disclosure
medium
34109Simple PHP Blog Detection
info
34108Zen Cart products_id[] Array SQL Injection
medium
34095Moodle 'lib/kses.php' 'kses_bad_protocol_once' Function Arbitrary PHP Code Execution
high
34055AWStats Totals awstatstotals.php multisort() Function sort Parameter Arbitrary PHP Code Execution
high
34031TWiki bin/configure 'image' Parameter Traversal Arbitrary File Access/Execution
high
34029Kayako SupportSuite < 3.30.01 Multiple Vulnerabilities
medium
33927Web Server Generic 3xx Redirect
medium
33926Adobe Dreamweaver dwsync.xml Remote Information Disclosure
medium
33925dotCMS Multiple Script id Parameter Traversal Local File Inclusion
medium
33903MailScan WebAdministrator Cookie Authentication Bypass
high
33882Joomla! reset.php Reset Token Validation Forgery
critical
33869JBoss Enterprise Application Platform (EAP) Status Servlet Request Remote Information Disclosure
medium
33867Novell iManager < 2.7 SP1 Property Book Pages Arbitrary Plug-in Studio Deletion
medium
33866Apache Tomcat allowLinking UTF-8 Traversal Arbitrary File Access
medium
33860RTH login.php uname Parameter SQL Injection
medium
33856e107 download.php extract() Function Variable Overwrite
high
33849PHP < 4.4.9 Multiple Vulnerabilities
high
33848Pligg settemplate.php template Parameter Local File Inclusion
medium