| ID # |
Risk |
Test Title |
| 60171 | High | UebiMiau Webmail Session authentication bypass |
| 60169 | Medium | Snitz Forums 2000 <= 3.4.05 script injection |
| 60168 | High | Snitz Forums 2000 <= 3.4.06 redirection |
| 60166 | Medium | Wordpress Multiple vulnerabilities |
| 60163 | Medium | Wordpress Path and SQL Structure Disclosure |
| 60149 | High | NetRisk 1.9.7 SQL injection |
| 60132 | High | NetRisk remote command execution |
| 60130 | High | PHP glob vulnerability via open_basedir |
| 60129 | High | TUTOS Remote Command Execution |
| 60128 | High | FlexBB <= 0.5.5 SQL Injection |
| 60127 | High | FlexBB <= 0.6.3 SQL Injection |
| 60125 | High | eggBlog < 3.x Multiple vulnerabilities |
| 60124 | High | eggBlog <= 3.07 SQL injection |
| 60123 | High | eggBlog < 3.0 Admin password change |
| 60122 | High | eggBlog <= 3.1.0 Session Hijacking |
| 60120 | High | eggBlog <= 3.1.0 SQL injection |
| 58314 | Medium | BosDates Payment.PHP Remote File Include Vulnerability |
| 58313 | Medium | CMSimple Multiple Input Validation Vulnerabilities(2) |
| 58312 | High | PHP < 4.4.7/5.2.3 Multiple Vulnerabilities |
| 58311 | High | PHP < 4.4.3/5.1.3 Multiple Vulnerabilities |
| 58310 | Medium | PHP < 4.4.1/5.1.0 Multiple Vulnerabilities |
| 58049 | Medium | Coppermine Photo Gallery Picmgr.PHP SQL Injection |
| 58048 | Medium | Coppermine Photo Gallery Albmgr.PHP SQL Injection |
| 57075 | Medium | Blog:CMS SQL Injection Vulnerability |
| 57020 | Medium | YaBB SE Profile.php SQL Injection Vulnerability |
| 57018 | Medium | MyBulletinBoard Usercp.PHP SQL Injection Vulnerability |
| 57017 | High | W-Agora <= 4.2 Multiple Remote File Include Vulnerabilities |
| 57016 | High | IceWarp Web Mail < 5.5.1 Multiple Vulnerabilities |
| 57015 | Medium | IceWarp Web Mail < 4.1.5 Session Vulnerability |
| 57014 | Medium | IceWarp Web Mail < 5.3.1 Multiple Vulnerabilities |
| 57013 | Medium | IceWarp Web Mail < 5.2.8 Multiple Vulnerabilities |
| 57012 | Medium | IceWarp Web Mail < 5.3.0 Multiple Vulnerabilities |
| 57010 | Medium | BosDates Multiple SQL Injection Vulnerabilities |
| 57009 | Medium | BosDates SQL Injection Vulnerability |
| 56994 | Medium | CMSimple Multiple Input Validation Vulnerabilities |
| 56992 | Low | Typo3 Information Disclosure |
| 56990 | High | Contenido Remote File Include |
| 56988 | Low | BLOG:CMS Unspecified Information Disclosure |
| 56987 | Low | BLOG:CMS Origin Spoofing Vulnerability |
| 56986 | Medium | Blog:CMS Image Upload HTML Injection Vulnerability |
| 56985 | High | BLOG:CMS Common.PHP Remote File Include |
| 56983 | High | Nucleus CMS Multiple Remote File Include Vulnerabilities |
| 56982 | High | Nucleus CMS GLOBALS[DIR_LIBS] Remote File Include |
| 56981 | Medium | Nucleus CMS Multiple Input Validation Vulnerabilities |
| 56980 | Medium | Nucleus CMS Action.PHP SQL Injection |
| 56979 | High | Nucleus CMS Common.PHP Remote File Include |
| 56970 | High | DokuWiki Remote PHP Script Code Injection Vulnerability |
| 56968 | High | DokuWiki Remote Arbitrary File Upload Vulnerability |
| 56917 | High | ByteHoard Remote File Inclusion Vulnerability |
| 56900 | High | RaidenHTTP < 1.1.34 multiple vulnerabilities |
| 56897 | Medium | Dwarf HTTP Server Multiple Input Validation Vulnerabilities |
| 56896 | Medium | CherryPy StaticFilter Directory Traversal |
| 56895 | Medium | Geeklog < 1.4.0sr1, 1.3.11sr4 Multiple Vulnerabilities |
| 56881 | High | vBulletin Portal.PHP SQL Injection Vulnerability |
| 56878 | Medium | RunCMS <= 1.3a SQL Injection |
| 56876 | Medium | RunCMS <= 1.2 Arbitrary Variable Overwrite |
| 56875 | Medium | RunCMS <= 1.2 SQL Injection |
| 56874 | Medium | RunCMS Database Configuration Information Disclosure |
| 56873 | High | Geeklog < 1.4.0sr3 Multiple Vulnerabilities |
| 56871 | High | Geeklog Authorization Bypass Vulnerability |
| 56870 | High | ELOG Multiple Remote Buffer Overflow Vulnerabilities |
| 56867 | Medium | ELOG Web Logbook <2.6.1 multiple flaws |
| 56866 | Medium | Resin File Disclosure Vulnerability |
| 56865 | Medium | Resin Remote Directory Traversal Vulnerability |
| 56864 | High | Invision Power Board < 2.1.5.2006.04.25 Multiple Vulnerabilities |
| 56863 | Medium | Lighttpd remote script disclosure |
| 56842 | High | PHPsysInfo Multiple Input Validation Vulnerabilities |
| 56829 | High | phpWebThings <= 1.4 Patched Multiple vulnerabilities |
| 56827 | Medium | PHPFM < 0.9.3 |
| 56825 | Medium | phpBB < 2.0.18 Multiple vulnerabilities |
| 56824 | Medium | PHP < 4.4.1/5.0.6 Multiple Vulnerabilities |
| 56823 | Medium | GNUMP3d <= 2.9.7 Multiple Vulnerabilities |
| 56822 | Medium | GNUMP3d <= 2.9.6 Multiple Vulnerabilities |
| 56821 | Medium | WindWeb <= 2.0 Denial of Service |
| 56820 | Medium | phpMyAdmin Multiple Vulnerabilities(2) |
| 56819 | Medium | Xerver < 4.20 Multiple Input Validation Vulnerabilities |
| 56818 | High | W-Agora Multiple Remote Input Validation Vulnerabilities |
| 56817 | High | W-Agora Multiple Arbitrary PHP Code Injection Vulnerabilities |
| 56816 | High | W-Agora BBCode Script Injection Vulnerability |
| 56814 | Medium | UBB.threads Showflat.PHP SQL Injection Vulnerability |
| 56813 | High | UBB.threads < 6.5.2 Beta2 Multiple Vulnerabilities |
| 56812 | High | UBB.threads Addpost_newpoll.PHP Remote File Include |
| 56811 | High | ByteHoard < 2.1 Multiple Vulnerabilities |
| 56809 | High | Socketmail <= 2.2.6 - Remote File Include Vulnerability |
| 56797 | Medium | PHP-Fusion < 6.00.110 Multiple Vulnerabilities |
| 56763 | Medium | phpBB code injection (2) |
| 56762 | Medium | WebCalendar Username Enumeration Vulnerability |
| 56761 | Medium | WebCalendar Layers_Toggle.PHP HTTP Response Splitting |
| 56760 | Medium | WebCalendar Export_Handler.PHP File Corruption Vulnerability |
| 56759 | Medium | WebCalendar Multiple SQL Injection Vulnerabilities |
| 56758 | High | E107 SQL Injection Vulnerability |
| 56756 | Medium | e107 Website System Voting Manipulation Vulnerability |
| 56755 | Medium | E107 Resetcore.PHP SQL Injection Vulnerability |
| 56750 | High | CuteNews Remote File Disclosure Vulnerability |
| 56748 | Medium | CutePHP CuteNews Directory Traversal Vulnerability |
| 55719 | High | Arcadia Internet Store 1.0 directory traversal |
| 55695 | Medium | WebLogic Server Password Leakage via Exception |
| 55694 | Medium | WebLogic Server Priviledge Escalation |
| 55693 | Low | WebLogic Server Authentication leaks via memory |
| 55692 | Medium | WebLogic Server Proxy Plugin Crash |
| 55691 | Low | WebLogic Server SSL T3 Bypass |
| 55690 | Medium | WebLogic Server Potential Password Disclosure Weakness |
| 55689 | Medium | WebLogic Server Denial of Service |
| 55688 | Medium | WebLogic Server Security Role Tag Removal |
| 55687 | Medium | WebLogic Server Secrets Insecurely Stored |
| 55683 | Medium | WebLogic Server Start/Stop Site Restriction Enforcement |
| 55682 | High | WebLogic Server Boot Credentials Disclosure |
| 55681 | Medium | WebLogic Server Pattern Matching Restriction Bypass |
| 55680 | Medium | WebLogic Server Administrative credentials disclosure |
| 55679 | Medium | WebLogic Server EJB Bean Removal Permissions |
| 55678 | Medium | WebLogic Server Group Deletion Permission Leakage |
| 55677 | Low | WebLogic Server Incorrect Certificate Identity |
| 55676 | Medium | WebLogic Server Invalid Certificate Chain |
| 55660 | High | SysCP < 1.2.11 Multiple Vulnerabilities |
| 55625 | Medium | WebSTAR Statistical information disclosure |
| 55624 | High | ACI 4D Web Server Directory Traversal |
| 55623 | High | HIS Software Auktion Arbitrary File Disclosure |
| 55622 | High | CoolForum avatar.php Arbitrary File Disclosure |
| 55621 | High | Moreover.com cached_feed.cgi Arbitrary File Disclosure |
| 55620 | High | EZ Systems HTTPBench Arbitrary File Disclosure |
| 55619 | High | phpNewsManager functions.php File Disclosure |
| 55618 | High | My Postcards MagicCard.CGI Arbitrary File Disclosure |
| 55617 | High | webutil.pl arbitrary command execution |
| 55616 | High | ScreamingMedia SITEWare arbitrary file disclosure |
| 55473 | High | Lucid CMS 1.0.11 multiple vulnerabilities |
| 55451 | Medium | Wordpress User Priviledge Escalation |
| 55450 | Medium | WebLogic Server Potential Password Disclosure Weakness |
| 55449 | High | SEO-Board SQL injection |
| 55447 | High | WebLogic Server TRACE request |
| 55446 | Medium | WebLogic Server Password Disclosure |
| 55406 | Medium | WebLogic Server Network Port Consumption |
| 55405 | High | WebLogic Server Authentication Failure Disclosure |
| 55404 | Medium | WebLogic Server JDBC Connection Pool Manipulation |
| 55403 | High | WebLogic Server Multiple Vulnerabilities |
| 55402 | Medium | WebLogic Server No Logout |
| 55401 | High | WebLogic Server UserLogin password disclosure |
| 55400 | High | WebLogic Server Cookie Cluster Control |
| 55385 | High | WebLogic Server Multiple Vulnerabilities |
| 55384 | Medium | WebLogic LDAP Anonymous Binds |
| 55383 | Medium | WebLogic Buffer Overflow CPU starvation |
| 55382 | High | WebLogic Server Multiple Vulnerabilities |
| 55381 | Medium | WebLogic Access Restriction Bypass |
| 55380 | High | Invision Power Board Priviledge Escalation |
| 55376 | Medium | vBulletin <= 3.0.9 XSS and SQL injection |
| 55372 | High | CuteNews Client-IP Script Injection |
| 55371 | High | CuteNews admin code injection vulnerability |
| 55370 | High | CuteNews admin account creation vulnerability |
| 55369 | High | CuteNews Comment HTML Injection Vulnerability |
| 55366 | Medium | CuteNews X-Forwarded-For Script Injection |
| 55365 | Medium | CuteNews Cross-Site Scripting, path disclosure |
| 55363 | High | CuteNews Remote File Include Vulnerability |
| 55362 | Medium | CuteNews information disclosure |
| 55351 | Medium | Wordpress cat_ID SQL Injection |
| 55338 | Low | WebCalendar < 1.0.0 unauthorized access |
| 55326 | Medium | Inframail SMTP Server Remote Buffer Overflow |
| 55324 | High | Geeklog < 1.3.11sr1 SQL Injection Vulnerability |
| 55320 | Medium | Comersus Cart Multiple Vulnerabilities |
| 55300 | Medium | Drupal Privilege Escalation Vulnerability |
| 55299 | High | Drupal Arbitrary PHP Code Execution |
| 55298 | High | Drupal XML-RPC for PHP Remote Code Injection |
| 55289 | High | FlatNuke < 2.5.6 Multiple Vulnerabilities |
| 55287 | High | Silvernews Admin.PHP SQL Injection Vulnerability |
| 55282 | High | Gravity Board X <= 1.1 Multiple Vulnerabilities |
| 55280 | High | Wordpress Code Injection via cache_lastpostdate cookie |
| 55266 | High | WebCalendar PHP Code Injection |
| 55263 | High | CMS Made Simple Remote File Include Vulnerability |
| 55248 | Medium | WebGUI < 6.7.3 Command Execution Vulnerabilities |
| 55246 | High | PBLang < 4.66z Multiple vulnerabilities |
| 55245 | High | PBLang Directory Traversal and HTML Injection |
| 53986 | High | phpBB Viewtopic.PHP Remote Code Execution |
| 53985 | High | S9Y Serendipity XML-RPC for PHP Remote Code Injection |
| 53984 | High | Wordpress XML-RPC for PHP Remote Code Injection |
| 53022 | High | Invision Power Board Multiple Vulnerabilities |
| 52759 | Medium | YaBB Multiple Input Validation Vulnerabilities |
| 52758 | Medium | YaBB Shadow BBCode Tag JavaScript Injection |
| 52757 | Medium | YaBB Bulletin Board Corruption |
| 52754 | High | Help Center Live Multiple Vulnerabilities |
| 52753 | Medium | phpBB Photo Album Multiple vulnerabilities(3) |
| 52752 | High | ArGoSoft Mail Server Multiple Vulnerabilities |
| 52751 | High | Help Center Live Multiple Vulnerabilities |
| 52749 | High | WoltLab Burning Board Multiple Vulnerabilities |
| 52747 | High | Wordpress Multiple Vulnerabilities |
| 52745 | Medium | Wordpress Wp-login.PHP HTTP Response Splitting |
| 52744 | Medium | Wordpress Multiple XSS, HTML and SQL Injection |
| 52743 | Medium | Wordpress Multiple XSS and SQL Injection |
| 52741 | Medium | Wordpress WP-Trackback.PHP SQL Injection |
| 52738 | High | E107 <= 0.617 Multiple Vulnerabilities |
| 52737 | High | Invision Power Board <2.0.4 Multiple Vulnerabilities |
| 52736 | High | S9Y Serendipity Multiple Remote Vulnerabilities |
| 52726 | Medium | S9Y Serendipity Exit.PHP SQL injection |
| 52725 | Medium | S9Y Serendipity Plugin HTML Injection |
| 52724 | Medium | S9Y Serendipity Multiple Remote Vulnerabilities |
| 52115 | High | Koobi CMS SQL Injection |
| 52109 | Medium | phpBB Multiple vulnerabilities(2) |
| 52101 | High | CoolForum XSS and SQL injection |
| 52098 | Medium | Coppermine Photo Gallery FAVPICS SQL Injection |
| 52093 | High | UBB.threads Printthread.PHP SQL Injection |
| 52088 | High | Monkey HTTP Server Invalid POST Request DoS |
| 52087 | High | Monkey HTTP Daemon POST Data Buffer Overflow |
| 52086 | High | Monkey HTTP Daemon Missing Content-Type Field DoS |
| 52085 | High | Monkey HTTP Daemon Missing Host Field DoS |
| 52084 | High | Monkey HTTP Daemon < 0.9.1 Multiple Vulnerabilities |
| 52082 | Medium | Coppermine Photo Gallery Displayimage.PHP SQL Injection |
| 52080 | Medium | Coppermine Photo Gallery Voting Restriction Failure |
| 52077 | High | phpBB KB.php SQL injection |
| 52070 | High | Invision Power Board Index.PHP SQL Injection |
| 52069 | High | Invision Power Board Calendar.PHP SQL Injection |
| 52068 | High | Invision Power Board ST Parameter SQL Injection(2) |
| 52066 | High | Invision Power Board Error Message Path Disclosure |
| 52064 | High | PHP 4.3.10, 5.0.3 multiple vulnerabilities |
| 52063 | High | Invision Power Board SSI.PHP SQL Injection |
| 52058 | High | Invision Power Board Index.PHP Post Action SQL Injection |
| 52057 | High | Invision Power Board SML Code Script Injection |
| 52056 | High | Invision Power Board HTML Injection |
| 52055 | High | Invision Power Board ST Parameter SQL Injection |
| 52052 | Medium | Comersus Cart Multiple Vulnerabilities |
| 52051 | High | Comersus Cart SQL Injection Vulnerability |
| 52050 | Medium | Comersus Cart HTTP Response Splitting |
| 52049 | Medium | Comersus Cart Multiple Vulnerabilities |
| 52032 | High | CubeCart Multiple SQL vulnerabilities |
| 52028 | High | CommuniGate Pro Web Admin DoS Vulnerability |
| 52023 | High | CommuniGate Pro Webmail Session Hijacking |
| 52022 | Other | Detect the version of CommuniGate Pro Web Server |
| 52014 | Medium | ProductCart XSS and SQL injection attacks |
| 52010 | Medium | SiteEnable XSS and SQL injection attacks |
| 51994 | Medium | PHP Image File Format Remote Denial Of Service |
| 51983 | High | phpMyAdmin Multiple Local File Include Vulnerabilities |
| 51982 | High | phpMyAdmin Multiple Input Validation Vulnerabilities |
| 51981 | High | phpMyAdmin Remote Command Execution |
| 51980 | High | phpMyAdmin Multiple Vulnerabilities |
| 51977 | High | phpMyAdmin Export.PHP File Disclosure |
| 51975 | High | phpMyAdmin Remote Command Execution |
| 51969 | High | ELog Web Logbook Multiple Buffer Overflow |
| 51968 | High | vBulletin SQL Injection(2) |
| 51967 | High | vBulletin Calendar Script SQL Injection |
| 51965 | High | ArGoSoft Mail Server Directory Traversal(2) |
| 51964 | High | ArGoSoft Mail Server Pro Mail Loop DoS |
| 51963 | High | ArGoSoft Mail Server Pro E-Mail HTML Injection |
| 51962 | High | ArGoSoft New User Denial of Service |
| 51961 | High | ArGoSoft Mail Server Authentication Bypass |
| 51960 | High | ArGoSoft Mail Server Directory Traversal |
| 51959 | High | ArGoSoft Mail Server Multiple GET Requests DoS |
| 51956 | High | phpMyFAQ Image Upload Authentication Bypass |
| 51955 | High | phpMyFAQ Action Parameter Arbitrary File Disclosure |
| 51954 | Medium | PHP-Fusion Forum_Search.PHP Information Disclosure |
| 51951 | Low | PHP-Fusion Viewthread.PHP Information Disclosure |
| 51932 | High | PerlDesk SQL Injection Vulnerability |
| 51915 | High | Icecast File Disclosure Vulnerability |
| 51854 | High | UBB.threads Editpost.PHP SQL Injection Vulnerability |
| 51852 | High | CoolForum HTML and SQL injection vulnerabilities |
| 51850 | High | Geeklog Image Upload Code injection attack |
| 51849 | High | Geeklog Authentication SQL Injection Vulnerability |
| 51846 | High | Geeklog 1.3 multiple vulnerabilities |
| 51845 | Medium | E107 database contents disclosure |
| 51844 | Medium | E107 Image Manager Unauthorized File Upload |
| 51842 | High | PHP 4.2.2 code injection vulnerability |
| 51841 | High | PHP 4.0.3 IMAP Module Buffer Overflow Vulnerability |
| 51840 | High | PHP Socket Integer Overflow |
| 51839 | High | PHP Error Logging Format String Vulnerability |
| 51838 | High | PHP Upload Arbitrary File Disclosure Vulnerability |
| 51837 | High | PHP CGI SAPI Code Execution Vulnerability |
| 51836 | High | PHP HTTP POST Incorrect MIME Header Parsing Vulnerability |
| 51835 | Medium | PHP 4/5 Arbitrary File Upload |
| 51834 | Medium | PHP 4/5 Multiple Vulnerabilities |
| 51831 | High | phpBB Autologin Priviledge Escalation Vulnerability |
| 51830 | High | Stadtaus code injection and file disclosure |
| 51829 | High | phpMyFAQ SQL injection vulnerability |
| 51794 | High | PHPNews code injection and file disclosure |
| 51793 | High | PBLang sendpm.php file read vulnerability |
| 51792 | High | PBLang PM Deletion |
| 51788 | High | Exponent CMS Cross Site scripting vulnerabilities |
| 51782 | High | ExBB Nested BBcode Script Injection Vulnerability |
| 51779 | High | JAWS arbitrary file disclosure vulnerability |
| 51778 | High | phpBB Fetch All |
| 51777 | High | PHPLinks arbitrary file disclosure |
| 51774 | High | phpBB code injection |
| 51772 | High | phpBB SQL injection(3) |
| 51771 | High | phpBB SQL injection(2) |
| 51770 | High | phpBB SQL injection |
| 51768 | High | phpBB Multiple vulnerabilities |
| 51764 | High | PBLang Script injection vulnerability |
| 51752 | Medium | MyBulletinBoard MEMBER.PHP SQL Injection Vulnerability |
| 51749 | High | VideoDB Multiple vulnerabilities |
| 51739 | High | Mambo Tar.php arbitrary code execution |
| 51738 | High | PaNews remote code execution vulnerability |
| 51736 | High | pMachine code injection and file disclosure |
| 51734 | High | MidiCart Remote Information Retrieval |
| 51733 | High | Mantis multiple vulnerabilities |
| 51732 | High | FileSeek directory traversal |
| 51731 | High | Stephen Ball File Manager Remote File Access |
| 51730 | High | Dispair Remote Command Execution |
| 51729 | High | Seminole WebServer Empty Request DoS |
| 51728 | High | Seminole WebServer Invalid Request Buffer Overflow |
| 51727 | Medium | Biz Mail Form mail relay vulnerability |
| 51725 | High | TrackerCam Multiple Remote Vulnerabilities |
| 51721 | High | Sami HTTP Server buffer overflow |
| 51720 | High | Sami HTTP Server multiple vulnerabilities |
| 51719 | High | ELOG Web Logbook multiple flaws |
| 51707 | Medium | WebCalendar SQL injection |
| 51706 | Medium | WebCalendar arbitrary file disclosure |
| 51705 | Medium | WebCalendar XSS, authentication flaws |
| 51703 | Medium | Kayako eSupport SQL injection and XSS |
| 51694 | High | OpenVMS WASD HTTP Vulnerabilities |
| 51693 | Medium | Lighttpd remote script disclosure |
| 51689 | High | CitrusDB 0.3.6 multiple vulnerabilities |
| 51687 | High | MyWebServer HTML Injection |
| 51686 | Low | MyWebServer Web Root Disclosure |
| 51684 | High | Web602 Vulnerable to Denial of Service |
| 51683 | Medium | Web602 directory listing |
| 51676 | Medium | Lidik Webserver directory traversal |
| 51675 | Low | Lotus Private Network Information Leak |
| 51673 | High | Blazix jsp source disclosure |
| 51292 | Medium | PHP 4.3.2 integer overflow |
| 51284 | Medium | PHP safe mode bypass vulnerability |
| 51277 | High | phpBB code injection |
| 51276 | High | Bugzilla Cross Site Scripting |
| 51275 | Medium | Squid WCCP and Gopher vulnerabilities |
| 51274 | Medium | Gallery XSS and Information Disclosure vulnerability |
| 51273 | High | Minis WebLogging directory traversal vulnerability |
| 21572 | Medium | Ipswitch WhatsUp Professional Authentication bypass detection |
| 21562 | Low | Ipswitch WhatsUp Professional Multiple Vulnerabilities |
| 21329 | Medium | Aardvark Topsites CONFIG[path] Parameter Remote File Inclusion Vulnerability |
| 21311 | Medium | WEBalbum Local File Include Vulnerability |
| 21310 | Medium | phpListPro returnpath Remote File Include Vulnerabilities |
| 21309 | Medium | Monster Top List Remote File Include |
| 21305 | Medium | phpMyAgenda rootagenda Parameter File Include Vulnerability |
| 21246 | Medium | Multiple Remote Vulnerabilities in myEvent |
| 21168 | Medium | gCards Multiple Vulnerabilities |
| 21146 | Medium | Free Articles Directory Remote File Inclusion Vulnerability |
| 21080 | High | Admbook PHP Code Injection Flaw |
| 21035 | Medium | Woltlab Burning Board SQL injection flaw |
| 21020 | High | 4Images <= 1.7.1 Directory Traversal Vulnerability |
| 20978 | Medium | SPIP < 1.8.2-g SQL Injection and XSS Flaws |
| 20972 | Medium | Plume CMS <= 1.0.2 Remote File Inclusion Vulnerability |
| 20825 | Low | RCBlog post Parameter Directory Traversal Vulnerability |
| 20824 | High | Limbo CMS Multiple Vulnerabilities |
| 20376 | Medium | PHPSurveyor sid SQL Injection Flaw |
| 20374 | Medium | phpDocumentor <= 1.3.0 RC4 Local And Remote File Inclusion Vulnerability |
| 20346 | High | VisNetic / Merak Mail Server multiple flaws |
| 20317 | High | vTiger multiple flaw |
| 20296 | High | The Includer remote command execution flaw |
| 20286 | Medium | SugarCRM <= 4.0 beta Remote File Inclusion Vulnerability |
| 20252 | Low | Edgewall Software Trac SQL injection flaw |
| 20223 | Medium | Help Center Live module.php local file include flaw |
| 20170 | Medium | phpWebThings forum Parameter SQL Injection Vulnerabilities |
| 20108 | Low | Fingerprint web server with favicon.ico |
| 20095 | Medium | ATutor < 1.5.1-pl1 Multiple Flaws |
| 20093 | Medium | Mantis File Inclusion and SQL Injection Flaws |
| 20014 | High | WebGUI < 6.7.6 arbitrary command execution |
| 19947 | Low | MailGust SQL Injection Vulnerability |
| 19943 | Medium | Guppy Request Header Injection Vulnerabilities |
| 19942 | Low | GuppY pg Parameter Vulnerability |
| 19770 | Low | Digital Scribe login.php SQL Injection flaw |
| 19765 | Medium | ATutor password reminder SQL injection |
| 19753 | Low | PhpGroupWare Addressbook < 0.9.16 Unspecified Flaw |
| 19749 | Medium | Calendar Express Multiple Flaws |
| 19748 | Medium | Sendcard SQL injection |
| 19678 | Medium | Land Down Under <= 800 Multiple Vulnerabilities |
| 19603 | Medium | Land Down Under <= 801 Multiple Vulnerabilities |
| 19602 | Other | Detects LDU version |
| 19596 | High | ASP/ASA source using Microsoft Translate f: bug (IIS 5.1) |
| 19595 | High | phpCommunityCalendar Multiple Vulnerabilities |
| 19497 | High | Ultimate PHP Board users.dat Information Disclosure |
| 19496 | Other | SugarCRM Detection |
| 19495 | Medium | Multiple vulnerabilities in PHP TopSites |
| 19494 | High | Multiple vulnerabilities in PHP Surveyor |
| 19493 | Medium | MyBB finduser SQL Injection |
| 19492 | Medium | Grandstream Budgetone Default Password |
| 19474 | Medium | w-Agora Site parameter remote directory traversal flaw |
| 19426 | Other | Detects Xaraya version |
| 19395 | High | File Inclusion Vulnerability in Jaws |
| 19392 | Low | Multiple vulnerabilities in Clever Copy |
| 19391 | High | Cyberstrong eShop SQL Injection Vulnerabilities |
| 19305 | High | Community Link Pro webeditor login.cgi remote command execution |
| 19239 | High | phpauction Admin Authentication Bypass |
| 18628 | Low | YaPiG Password Protected Directory Access Flaw |
| 18586 | High | webadmin.php detection |
| 18523 | High | YaPiG Multiple Flaws |
| 18505 | Medium | Multiple DotNetNuke HTML Injection Vulnerabilities |
| 18478 | High | WebHints remote command execution flaw |
| 18410 | High | Calendarix SQL Injection Vulnerability |
| 18376 | High | Athena Web Registration remote command execution flaw |
| 18362 | High | Episodex Guestbook Unauthorized Access and HTML Injection Vulnerability |
| 18358 | High | Netref Cat_for_gen.PHP Remote PHP Script Injection Vulnerability |
| 18292 | High | WebAPP Apage.CGI remote command execution flaw |
| 18290 | High | MetaCart E-Shop ProductsByCategory.ASP SQL and XSS Injection Vulnerabilities |
| 18289 | High | JGS-Portal Multiple XSS and SQL injection Vulnerabilities |
| 18265 | Medium | Skull-Splitter Guestbook Multiple HTML Injection Vulnerabilities |
| 18260 | High | Ultimate PHP Board ViewForum.PHP SQL injection and XSS flaws |
| 18259 | High | OpenBB XSS and SQL injection flaws |
| 18255 | High | CodeThatShoppingCart Input Validation Vulnerabilities |
| 18254 | High | Dream4 Koobi CMS Index.PHP SQL Injection Vulnerability |
| 18221 | Medium | WowBB view_user.php SQL Injection Flaw |
| 18217 | High | Advanced Guestbook Index.PHP SQL Injection Vulnerability |
| 18216 | Medium | PWSPHP XSS |
| 18211 | High | Easy Message Board Command Execution |
| 18210 | Medium | Fusion SBX Password Bypass and Command Execution |
| 18209 | High | myBloggie Multiple Vulnerabilities |
| 18192 | High | YusASP Web Asset Manager Vulnerability |
| 18191 | Medium | FishCart SQL injections |
| 18187 | Medium | ASP Inline Corporate Calendar SQL injection |
| 18182 | Medium | RM SafetyNet Plus XSS |
| 18176 | Medium | Yawcam Directory Traversal |
| 18149 | High | inserter.cgi File Inclusion and Command Execution Vulnerabilities |
| 18015 | Medium | TowerBlog Admin Bypass |
| 17972 | Medium | SonicWall SOHO Web Interface XSS |
| 17343 | Medium | phpWebLog Cross Site Scripting |
| 17335 | Medium | phpAdsNew Multiple Vulnerabilities |
| 17323 | High | aeNovo Database Content Disclosure Vulnerability |
| 17282 | Other | vBulletin Detection |
| 17226 | Medium | Verity Ultraseek search request XSS |
| 16389 | Medium | ASPjar Guestbook SQL Injection |
| 16388 | High | Credit Card Data Disclosure in CitrusDB |
| 16387 | Medium | Sympa queue utility privilege escalation vulnerability |
| 16338 | Other | Mailman Detection |
| 16308 | Medium | DeskNow Mail and Collaboration Server Directory Traversal Vulnerabilities |
| 16279 | Medium | Uebimiau Session Directory Disclosure |
| 16247 | Medium | Multiple Vulnerabilities in MercuryBoard |
| 16229 | High | TikiWiki multiple remote unspecified flaws |
| 16227 | High | Comersus BackOffice Lite Administrative Bypass |
| 16203 | Medium | vBulletin Init.PHP unspecified vulnerability |
| 16189 | High | AWStats configdir parameter arbitrary cmd exec |
| 16178 | Medium | Zeroboard flaws (2) |
| 16177 | Medium | SparkleBlog SQL Injection |
| 16170 | Low | Movable Type config file |
| 16169 | High | Movable Type initialization script found |
| 16168 | High | WebLibs File Disclosure |
| 16164 | High | SGallery idimage SQL Injection |
| 16138 | Medium | PhpGroupWare index.php HTML injection vulnerabilities |
| 16121 | High | b2Evolution title SQL Injection |
| 16086 | High | IBProArcade index.php SQL Injection |
| 16071 | High | PHPCalendar Remote File Include Vulnerability |
| 16070 | High | WHM AutoPilot Multiple Vulnerabilities |
| 16063 | Medium | Owl Multiple Vulnerabilities |
| 16062 | Medium | ViewCVS HTTP Response Splitting |
| 16060 | High | Help Center Live Multiple Vulnerabilities |
| 16059 | Medium | Zeroboard flaws |
| 16056 | High | phpMyChat Information Disclosure |
| 16046 | High | 2BGal SQL Injection |
| 16045 | High | Namazu Multiple Flaws |
| 16044 | Medium | e_Board arbitrary file reading |
| 16043 | High | vBulletin last10.php SQL Injection |
| 16042 | Medium | Winmail Mail Server Information Disclosure |
| 16000 | Medium | CVSTrac Cross-Site Scripting Vulnerability |
| 15987 | High | Singapore Gallery Multiple Flaws |
| 15986 | High | IkonBoard SQL injection vulnerabilties |
| 15983 | High | PhpGroupWare XSS and SQL injection issues |
| 15975 | High | SIR GNUBoard Remote File Inclusion |
| 15974 | High | Ocean12 ASP Calendar Administrative Access |
| 15972 | High | SQL injection in iWebNegar |
| 15968 | High | ASP-Rider SQL Injection |
| 15967 | Medium | UseModWiki Cross Site Scripting |
| 15951 | Medium | UBB.threads Cross Site Scripting Vulnerabilities |
| 15950 | High | SugarSales Remote File Access |
| 15949 | High | phpDig Vulnerability |
| 15938 | Low | PunBB search dropdown information disclosure |
| 15936 | Other | PunBB detection |
| 15935 | High | IlohaMail Unspecified Vulnerability |
| 15931 | Low | F-Secure Policy Manager Path Disclosure |
| 15928 | High | PHP Live! Remote Configuration File Include |
| 15927 | High | HFS+ 'data fork' file access |
| 15924 | Medium | Blog Torrent Cross Site Scripting |
| 15911 | High | paFileDB password hash disclosure |
| 15909 | Low | PAFileDB Error Message Path Disclosure Vulnerability |
| 15908 | Medium | Apache Jakarta Cross-Site Scripting Vulnerability |
| 15905 | High | PHProjekt Unspecified Authentication Bypass Vulnerability |
| 15904 | High | Blog Torrent Remote Directory Traversal |
| 15864 | Medium | InMail/InShop XSS |
| 15861 | High | PHPNews sendtofriend.php SQL injection |
| 15858 | Medium | Post-Nuke pnTresMailer Directory Traversal |
| 15849 | Medium | Brio Unix Directory Traversal |
| 15829 | Medium | KorWeblog Remote Directory Listing Vulnerability |
| 15787 | High | WebGUI Unspecified Vulnerability |
| 15784 | High | PHP-Kit Multiple Input Validations |
| 15778 | High | Invision Power Board Post SQL Injection Vulnerability |
| 15775 | High | Invision Power Board Arcade SQL Injection Vulnerability |
| 15772 | Low | phpScheduleIt Unspecified Vulnerability |
| 15763 | High | miniBB sql injection |
| 15760 | High | PowerPortal SQL Injection |
| 15751 | High | phpBugTracker bug.php SQL Injection |
| 15750 | High | i-mall.cgi |
| 15721 | Other | PostNuke Detection |
| 15720 | Other | EGroupWare Detection |
| 15719 | High | EGroupWare JiNN Application Unspecified Vulnerability |
| 15718 | High | SquirrelMail decodeHeader HTML injection vulnerability |
| 15711 | Medium | PhpGroupWare arbitrary command execution |
| 15710 | High | cgi.rb |
| 15708 | High | PHP mylog.html/mlog.html read arbitrary file |
| 15651 | Low | Mantis Multiple Flaws (3) |
| 15639 | High | Moodle SQL injection flaws |
| 15626 | Medium | TIPS MailPost Multiple Flaws |
| 15624 | Medium | Gallery Unspecified HTML Injection Vulnerability |
| 15565 | High | Bugzilla remote arbitrary command execution |
| 15564 | High | Whatsup Gold vulnerable CGI |
| 15562 | High | Bugzilla Authentication Bypass and Information Disclosure |
| 15561 | High | UBB.threads dosearch.php SQL injection |
| 15557 | Low | WowBB <= 1.61 multiple flaws |
| 15542 | Medium | nbmember.cgi information disclosure |
| 15541 | High | IdealBB multiple flaws |
| 15516 | Medium | cPanel Backup File Disclosure |
| 15515 | Medium | cPanel FrontPage Extension Flaws |
| 15514 | Medium | Lotus Domino XSS (2) |
| 15506 | Medium | CoolPHP Multiple Vulnerabilities |
| 15470 | High | BugPort unspecified attachment handling flaw |
| 15468 | High | ocPortal Remote File Include |
| 15466 | High | bBlog SQL injection flaw |
| 15461 | High | CactuShop XSS and SQL injection flaws |
| 15453 | High | DUware multiple vulnerabilities |
| 15452 | High | Zanfi CMS Lite Remote File Include |
| 15450 | High | BlackBoard Internet Newsboard System remote file include flaw |
| 15442 | High | CubeCart SQL injection |
| 15437 | Medium | w-Agora remote directory traversal flaw |
| 15436 | High | php PHP_Variables Memory Disclosure |
| 15433 | High | PHP-Fusion members.php SQL injection |
| 15403 | Medium | Silent-Storm Portal Multiple Input Validation Vulnerabilities |
| 14847 | Medium | Vignette Application Portal Information Disclosure |
| 14838 | High | myServer POST Denial of Service |
| 14837 | High | PD9 MegaBBS multiple vulnerabilities |
| 14830 | High | @lex guestbook remote file include |
| 14828 | High | BroadBoard SQL Injection |
| 14824 | Medium | Pinnacle ShowCenter Skin DoS |
| 14817 | High | aspWebAlbum SQL Injection |
| 14816 | High | aspWebCalendar SQL Injection |
| 14805 | High | Emulive Server4 Authentication Bypass |
| 14787 | High | PHPMyBackupPro Input Validation Issues |
| 14786 | High | BBS E-Market File Disclosure |
| 14784 | High | Tutos SQL injection and Cross Site Scripting Issues |
| 14782 | Medium | YaBB XSS and Administrator Command Execution |
| 14733 | Medium | PerlDesk File Inclusion |
| 14722 | High | WebLogic Multiple Vulnerabities |
| 14719 | High | Turbo Seek files reading |
| 14715 | Medium | OpenCA signature verification flaw |
| 14714 | Medium | OpenCA multiple signature validation bypass |
| 14713 | High | Simple Form Mail Relaying via Subject Tags Vulnerability |
| 14655 | High | MailEnable HTTPMail Service Content-Length Overflow Vulnerability |
| 14654 | Medium | MailEnable HTTPMail Service Authorization Header DoS Vulnerability |
| 14639 | Medium | dasBlog HTML Injection Vulnerability |
| 14637 | Medium | IlohaMail User Parameter Vulnerability |
| 14636 | Low | IlohaMail Password Disclosure Vulnerability |
| 14635 | High | IlohaMail External Programs Vulnerabilities |
| 14633 | Low | IlohaMail Contacts Deletion Vulnerability |
| 14632 | Low | IlohaMail Attachment Upload Vulnerability |
| 14615 | High | TorrentTrader SQL Injection |
| 14614 | Medium | XOOPS Dictionary Module Cross Scripting Vulnerability |
| 14613 | Medium | phpScheduleIt HTML Injection Vulnerability |
| 14382 | Medium | WebMatic Security Vulnerability |
| 14379 | Medium | Multiple Vulnerabilities in Merak Webmail / IceWarp Web Mail |
| 14375 | Medium | Easy File Sharing Web Server ACL Bypass |
| 14370 | Medium | HastyMail HTML Attachement Script Execution |
| 14369 | Medium | SWsoft Plesk Reloaded Cross Site Scripting Vulnerability |
| 14368 | Medium | PHP-CSL Cross Site Scripting Vulnerability |
| 14365 | Medium | WebAPP Directory Traversal |
| 14364 | High | TikiWiki multiple input validation vulnerabilities |
| 14363 | High | INL ulog-php SQL injection |
| 14362 | High | PlaySMS Cookie SQL Injection |
| 14359 | High | TikiWiki Unauthorized Page Access |
| 14358 | Medium | eGroupWare Cross-Site Scripting Vulnerability |
| 14357 | Medium | PhotoADay Cross-Site Scripting Vulnerability |
| 14356 | Medium | PHP-Fusion Database Backup Disclosure |
| 14347 | High | AWStats rawlog plugin logfile parameter input validation vulnerability |
| 14338 | High | Gallery Script Execution |
| 14327 | High | MyDMS SQL Injection and Directory Traversal |
| 14325 | High | Zixforum database disclosure |
| 14324 | High | Mantis Multiple Flaws (2) |
| 14323 | Low | Sympa New List Cross Site Scripting |
| 14312 | Medium | ScanMail file check |
| 14308 | Other | BasiliX Detection |
| 14306 | Low | BasiliX Attachment Disclosure Vulnerability |
| 14305 | Medium | BasiliX Arbitrary File Disclosure Vulnerability |
| 14304 | High | BasiliX Arbitrary Command Execution Vulnerability |
| 14300 | Medium | Sympa unauthorised list creation security issue |
| 14299 | Medium | Sympa invalid LDAP password DoS |
| 14298 | Medium | Sympa wwsympa do_search_list Overflow DoS |
| 14296 | Medium | PhpGroupWare multiple module SQL injection vulnerabilities |
| 14295 | Medium | PhpGroupWare calendar server side script execution |
| 14294 | Medium | PhpGroupWare unspecified remote file include vulnerability |
| 14293 | Medium | PhpGroupWare plaintext cookie authentication credentials vulnerability |
| 14292 | Medium | PhpGroupWare multiple HTML injection vulnerabilities |
| 14291 | High | CVSTrac timeline.c timeline_page function overflow |
| 14290 | High | CVSTrac ticket title arbitrary command execution |
| 14289 | Medium | CVSTrac malformed URI infinite loop DoS |
| 14288 | High | CVSTrac chdir() chroot jail escape |
| 14287 | High | CVSTrac invalid ticket DoS |
| 14286 | High | CVSTrac history.c history_update function overflow |
| 14285 | High | CVSTrac database plaintext password storage |
| 14284 | High | CVSTrac cgi.c multiple overflows |
| 14283 | High | CVSTrac CVSROOT/passwd arbitrary account deletion |
| 14269 | High | YaPiG Remote Server-Side Script Execution Vulnerability |
| 14255 | Medium | Outlook Web Access Version |
| 14237 | High | Goscript command execution |
| 14233 | High | ASPrunner multiple flaws |
| 14228 | Medium | SquirrelMail XSS and Local escalation |
| 14227 | High | Snitz Forums 2000 SQL injection |
| 14224 | High | Simple Form Mail Relaying Vulnerability |
| 14222 | High | RiSearch Arbitrary File Access |
| 14221 | Other | Open WebMail Detection |
| 14220 | High | CVSTrac filediff vulnerability |
| 14219 | Medium | BasiliX SQL Injection Vulnerability |
| 14218 | Low | BasiliX Message Content Script Injection Vulnerability |
| 14193 | High | Polar HelpDesk Authentication ByPass |
| 14191 | Medium | Tivoli LDACGI Directory Traversal |
| 14190 | High | PostNuke Install Script |
| 14189 | Medium | PostNuke Reviews XSS |
| 14187 | High | SQL injection in Antiboard |
| 14186 | Medium | WebCam Watchdog sresult.exe XSS |
| 14185 | Medium | Phorum Search Cross Site Scripting Vulnerability |
| 14182 | High | myServer math_sum.mscgi multiple flaws |
| 14178 | Low | PowerPortal Private Message HTML Injection |
| 13847 | Medium | OpenDocMan Access Control Bypass |
| 13845 | High | EasyWeb FileManager Directory Traversal |
| 13843 | High | Moodle < 1.3.3 |
| 13842 | Low | Mensajeitor Tag Board Admin Bypass |
| 13841 | Low | Xitami Cross Site Scripting Vulnerability |
| 13654 | High | Artmedic Kleinanzeigen File Inclusion Vulnerability |
| 13648 | Low | osTicket Attachment Viewing Vulnerability |
| 13647 | Medium | osTicket setup.php Accessibility |
| 13646 | Low | osTicket Large Attachment Vulnerability |
| 13645 | High | osTicket Attachment Code Execution Vulnerability |
| 13635 | Medium | Bugzilla Multiple Flaws (2) |
| 12648 | High | SQL Disclosure in Invision Power Board |
| 12647 | Other | SquirrelMail Detection |
| 12300 | Low | Inktomi Search Physical Path Disclosure |
| 12292 | Low | PowerPortal Path Dislcosure |
| 12289 | High | artmedic_links5 File Inclusion Vulnerability |
| 12283 | High | Singapore MD5 Administrative Password Disclosure |
| 12282 | High | File Inclusion Vulnerability in Pivot |
| 12281 | High | Chora Remote Code Execution Vulnerability |
| 12278 | Low | gallery authentication bypass |
| 12272 | High | US Robotics Disclosed Password Check |
| 12271 | High | Crystal Report virtual directory traversal |
| 12269 | High | EdiMax AP Hidden Password Check |
| 12258 | High | NetGear Hidden Password Check |
| 12256 | High | SQL injection in JPortal |
| 12251 | High | RealServer default.cfg file search |
| 12245 | Medium | Jave Source Code Disclosure |
| 12234 | Medium | Terminal Services Web Detection |
| 12229 | Low | Microsoft IIS Cookie information disclosure |
| 12225 | High | Web Server reverse proxy bug |
| 12224 | Low | Web Server load balancer detection |
| 12221 | Medium | 3Com NBX VoIP NetSet Detection |
| 12202 | High | Nuked-klan file include |
| 12198 | Low | Ultimate PHP Board Information Leak |
| 12127 | High | Aborior Command Execution |
| 12123 | Medium | Apache Tomcat source.jsp malformed request information disclosure |
| 12097 | High | cPanel Login Command Execution |
| 12096 | High | cfWebStore SQL injection |
| 12095 | Medium | Emumail WebMail multiple vulnerabilities |
| 12094 | High | vHost Cross-Site scripting vulnerabilities |
| 12089 | Medium | HotOpenTickets Privilege Escalation |
| 12088 | High | SpiderSales Shopping Cart SQL injection |
| 12087 | Medium | SandSurfer Cross Site Scripting Vulnerabilities |
| 12079 | High | File Disclosure in OWL's Workshop |
| 12074 | Low | Talentsoft Web+ reveals install path |
| 12068 | Medium | x-news 1 |
| 12064 | High | ShopCartCGI arbitrary file reading |
| 12062 | High | Ecommerce Corp. Online Store Kit More.php Injection Vulnerability |
| 12059 | Medium | SandSurfer User Authentication Vulnerability |
| 12058 | Medium | JelSoft VBulletin XSS |
| 12057 | Medium | ASP Portal XSS |
| 12045 | Medium | Mambo Site Server XSS |
| 12043 | Low | BEA WebLogic Operator/Admin Password Disclosure Vulnerability |
| 12042 | High | SQL injection in ReviewPost PHP Pro |
| 12040 | High | Qualiteam X-Cart remote command execution |
| 12038 | High | SQL injection in Photopost PHP Pro |
| 12035 | High | PJreview_Neo.cgi arbitrary file reading |
| 12034 | High | phpGedView arbitrary file reading |
| 12033 | High | LeifWright's blog.cgi command execution |
| 12032 | High | JBrowser multiple flaws |
| 12031 | High | aprox portal file disclosure |
| 12030 | High | gallery code injection (3) |
| 12026 | High | phpix remote command execution |
| 12025 | High | Mambo Code injection Vulnerability |
| 12022 | High | Multiple phpShop Vulnerabilities |
| 12021 | High | Remote Code Execution in ezContents |
| 12020 | High | SQL injection in XTreme ASP Photo Gallery |
| 12008 | High | phpdig Code injection Vulnerability |
| 11991 | High | File Disclosure in PHP Manpage |
| 11982 | High | phpGedView Code injection Vulnerability |
| 11979 | High | HotNews code injection |
| 11976 | High | EasyDynamicPages code injection |
| 11975 | High | quickstore traversal (2) |
| 11973 | Medium | BulletScript MailList bsml.pl Information Disclosure |
| 11972 | Medium | miniBB cross site scripting |
| 11969 | High | PHPCatalog SQL injection |
| 11966 | High | Remote Code Execution in PHP Ping |
| 11954 | Low | sgdynamo_path |
| 11944 | Medium | Snif File Disclosure |
| 11942 | High | VP-ASP shopsearch SQL injection |
| 11939 | High | foxweb CGI |
| 11937 | High | mod_python malformed query |
| 11931 | High | My_eGallery code execution |
| 11923 | High | Frontpage Overflow (MS03-051) |
| 11918 | High | Oracle 9iAS PORTAL_DEMO ORG_CHART |
| 11917 | Medium | Bugzilla SQL flaws |
| 11911 | High | 'Les Visiteurs' script injection |
| 11877 | High | myPHPcalendar injection |
| 11876 | High | gallery code injection (2) |
| 11873 | High | PayPal Store Front code injection |
| 11872 | High | ODBC tools check |
| 11866 | High | Cafe Wordpress SQL injection |
| 11851 | High | myServer 0.4.3 / 0.7 Directory Traversal Vulnerability |
| 11836 | High | myphpnuke code injection |
| 11833 | High | EZsite Forum Discloses Passwords to Remote Users |
| 11824 | Low | myPHPNuke phptonuke.php Directory Traversal |
| 11817 | Low | StellarDocs Path Disclosure |
| 11816 | High | phpWebSite multiple flaws |
| 11810 | Low | gallery xss |
| 11806 | Medium | paFileDB command execution |
| 11799 | High | PHP Ashnews code injection |
| 11796 | Medium | Forum51/Board51/News51 Users Disclosure |
| 11795 | High | AtomicBoard file reading |
| 11786 | High | VP-ASP SQL Injection |
| 11785 | High | ProductCart SQL Injection |
| 11782 | High | iXmail SQL injection |
| 11781 | Medium | iXmail arbitrary file upload |
| 11780 | High | mailreader.com directory traversal and arbitrary command execution |
| 11776 | High | Carello detection |
| 11775 | Low | Sambar CGIs path disclosure |
| 11771 | High | webadmin.dll detection |
| 11769 | Low | Zope Invalid Query Path Disclosure |
| 11766 | Low | pmachine cross site scripting |
| 11764 | Low | TMax Soft Jeus Cross Site Scripting |
| 11760 | Low | Pod.Board Forum_Details.PHP Cross Site Scripting |
| 11758 | Medium | eLDAPo cleartext passwords |
| 11753 | High | SquirrelMail's Multiple Flaws |
| 11751 | High | Dune Web Server Overflow |
| 11750 | High | Psunami.CGI Command Execution |
| 11749 | High | Vignette StoryServer TCL code injection |
| 11748 | High | Various dangerous cgi scripts |
| 11747 | Medium | Trend Micro Emanager software check |
| 11746 | High | AspUpload vulnerability |
| 11745 | High | Hosting Controller vulnerable ASP pages |
| 11744 | High | Post-Nuke SQL injection |
| 11743 | Low | Post-Nuke Multiple XSS |
| 11741 | Medium | lednews XSS |
| 11740 | High | Infinity CGI Exploit Scanner |
| 11739 | High | pmachine code injection |
| 11735 | High | Mnogosearch overflows |
| 11732 | Medium | Webnews.exe vulnerability |
| 11731 | High | VsSetCookie.exe vulnerability |
| 11730 | High | ndcgi.exe vulnerability |
| 11729 | High | ion-p.exe vulnerability |
| 11728 | High | ddicgi.exe vulnerability |
| 11727 | High | CWmail.exe vulnerability |
| 11726 | High | CSNews.cgi vulnerability |
| 11725 | High | counter.exe vulnerability |
| 11724 | High | WebLogic source code disclosure |
| 11723 | High | PDGSoft Shopping cart vulnerability |
| 11722 | High | cgiWebupdate.exe vulnerability |
| 11721 | High | CgiMail.exe vulnerability |
| 11719 | High | admin.cgi overflow |
| 11714 | Low | Non-Existant Page Physical Path Disclosure Vulnerability |
| 11708 | High | zentrack files reading |
| 11706 | Medium | Spyke Flaws |
| 11702 | High | zentrack code injection |
| 11700 | High | ImageFolio Default Password |
| 11698 | High | SQL injection in XPression Software |
| 11694 | Low | P-Synch multiple issues |
| 11692 | High | WebStores 2000 browse_item_details.asp SQL injection |
| 11690 | High | JBoss source disclosure |
| 11688 | High | WF-Chat User Account Disclosure |
| 11686 | High | mod_gzip format string attack |
| 11685 | Low | mod_gzip running |
| 11684 | High | rot13sj.cgi |
| 11682 | High | Philboard database access |
| 11681 | Medium | Zeus Admin Interface XSS |
| 11680 | High | Webfroot Shoutbox Directory Traversal |
| 11678 | High | Super-M Son hServer Directory Traversal |
| 11676 | High | Post-Nuke Rating System Denial Of Service |
| 11675 | High | Philboard philboard_admin.ASP Authentication Bypass |
| 11672 | Medium | Bandmin XSS |
| 11671 | High | Ultimate PHP Board admin_ip.php code injection |
| 11669 | Medium | p-news Admin Access |
| 11668 | High | Webfroot shoutbox file inclusion |
| 11667 | High | b2 cafelog code injection |
| 11666 | Low | Post-Nuke information disclosure (2) |
| 11664 | High | nsiislog.dll DoS |
| 11663 | High | iiprotect bypass |
| 11662 | High | iiprotect sql injection |
| 11661 | High | Unpassworded iiprotect administrative interface |
| 11660 | High | TextPortal Default Passwords |
| 11658 | High | SunONE Application Server source disclosure |
| 11657 | Low | Synchrologic User account information disclosure |
| 11653 | High | Mantis Multiple Flaws |
| 11647 | High | BLnews code injection |
| 11646 | Low | Turba Path Disclosure |
| 11644 | Low | ezPublish Directory Cross Site Scripting |
| 11643 | High | OneOrZero SQL injection |
| 11639 | Medium | Web-ERP Configuration File Remote Access |
| 11638 | High | biztalk server flaws |
| 11636 | High | ttCMS code injection |
| 11630 | High | php-proxima file reading |
| 11629 | Medium | Poster version.two privilege escalation |
| 11627 | Low | WebLogic clear-text passwords |
| 11626 | Medium | Owl Login bypass |
| 11623 | High | miniPortail Cookie Admin Access |
| 11622 | Low | mod_ssl wildcard DNS cross site scripting vulnerability |
| 11621 | High | Snitz Forums Cmd execution |
| 11617 | Medium | Horde and IMP test disclosure |
| 11615 | High | ttforum multiple flaws |
| 11611 | Low | counter.php file overwrite |
| 11610 | Low | testcgi.exe Cross Site Scripting |
| 11609 | High | mod_survey ENV tags SQL injection |
| 11608 | Medium | Neoteris IVE XSS |
| 11605 | High | IkonBoard arbitrary command execution |
| 11604 | Medium | BEA WebLogic Scripts Server scripts Source Disclosure (3) |
| 11602 | High | HappyMall Command Execution |
| 11601 | Low | MailMaxWeb Path Disclosure |
| 11599 | Medium | Ocean12 Database Download |
| 11597 | High | Snitz Forums 2000 Password Reset and XSS |
| 11596 | High | SLMail WebMail overflows |
| 11590 | High | MPC SoftWeb Guestbook database disclosure |
| 11589 | High | PT News Unauthorized Administrative Access |
| 11588 | High | YaBB SE command execution |
| 11587 | Medium | XMB SQL Injection |
| 11582 | High | TrueGalerie admin access |
| 11581 | High | album.pl Command Execution |
| 11569 | High | StockMan Shopping Cart Command Execution |
| 11568 | Low | StockMan Shopping Cart Path disclosure |
| 11558 | Low | Macromedia ColdFusion MX Path Disclosure Vulnerability |
| 11557 | High | ideabox code injection |
| 11555 | High | AN HTTPd count.pl file truncation |
| 11553 | Medium | Bugzilla XSS and insecure temporary filenames |
| 11550 | High | OpenBB SQL injection |
| 11549 | High | readfile.tcl |
| 11548 | High | bttlxeForum SQL injection |
| 11542 | High | Web Wiz Forums database disclosure |
| 11538 | Medium | ezPublish config disclosure |
| 11537 | Medium | Ocean12 Guestbook XSS |
| 11536 | Low | Super Guestbook config disclosure |
| 11533 | High | Web Wiz Site News / Compulsize Media CNU5 database disclosure |
| 11532 | High | Instaboard SQL injection |
| 11531 | Low | PHPay Information Disclosure |
| 11527 | Medium | XMB Cross Site Scripting |
| 11526 | Medium | Vignette StoryServer Information Disclosure |
| 11516 | High | AutomatedShops WebC.cgi buffer overflows |
| 11515 | Low | AutomatedShops WebC.cgi installed |
| 11509 | High | GTcatalog password disclosure |
| 11508 | Medium | Xoops XSS |
| 11505 | Medium | Ecartis Username Spoofing |
| 11503 | Low | cc_guestbook.pl XSS |
| 11502 | Low | ScozBook flaws |
| 11501 | Low | Justice guestbook |
| 11500 | Low | Beanwebb's guestbook |
| 11498 | High | Alexandria-dev upload spoofing |
| 11497 | High | E-Theni code injection |
| 11492 | Medium | Sambar XSS |
| 11491 | Low | Sambar default CGI info disclosure |
| 11489 | Low | myguestbk admin access |
| 11488 | High | IMP SQL injection |
| 11487 | Low | Advanced Poll info.php |
| 11486 | High | WebLogic management servlet |
| 11482 | Low | Post-Nuke information disclosure |
| 11479 | Medium | paFileDB XSS |
| 11478 | High | paFileDB SQL injection |
| 11477 | Low | DCP-Portal Path Disclosure |
| 11476 | High | DCP-Portal Code Injection |
| 11472 | High | viewpage.php arbitrary file reading |
| 11471 | Low | VChat information disclosure |
| 11470 | Medium | WebChat XSS |
| 11469 | Low | SimpleChat information disclosure |
| 11467 | High | JWalk server traversal |
| 11465 | High | args.bat |
| 11464 | High | ad.cgi |
| 11463 | High | Bugzilla Multiple Flaws |
| 11461 | High | Adcycle Password Disclosure |
| 11455 | High | Passwordless frontpage installation |
| 11453 | High | Kebi Academy Directory Traversal |
| 11452 | High | Oracle 9iAS web admin |
| 11451 | High | textcounter.pl |
| 11444 | Medium | PHP Mail Function Header Spoofing Vulnerability |
| 11440 | High | Bonsai Mutiple Flaws |
| 11439 | Medium | Xoops path disclosure |
| 11438 | High | Apache Tomcat Directory Listing and File disclosure |
| 11436 | Low | guestbook tr3 password storage |
| 11417 | Medium | MyAbraCadaWeb Cross Site Scripting |
| 11416 | High | openwebmail command execution |
| 11411 | Other | Backup CGIs download |
| 11401 | Low | texi.exe path disclosure |
| 11400 | Medium | texi.exe information disclosure |
| 11399 | Medium | ClearTrust XSS |
| 11397 | Medium | vpopmail.php command execution |
| 11395 | Medium | Microsoft Frontpage XSS |
| 11394 | Medium | Lotus Domino XSS |
| 11393 | Low | ColdFusion Path Disclosure |
| 11377 | Medium | smb2www installed |
| 11375 | High | smb2www remote command execution |
| 11370 | High | fpcount.exe overflow |
| 11368 | High | Cross-Referencing Linux (lxr) file reading |
| 11365 | Medium | Auction Deluxe XSS |
| 11362 | Medium | Simple File Manager Filename Script Injection |
| 11361 | High | Mambo Site Server Cookie Validation |
| 11360 | High | Wordit Logbook |
| 11359 | High | UploadLite cgi |
| 11345 | High | SimpleBBS users disclosure |
| 11344 | High | Domino traversal |
| 11334 | High | popper_mod |
| 11333 | High | webwho plus |
| 11328 | High | Kietu code injection |
| 11324 | High | phpping code execution |
| 11319 | High | GTcatalog code injection |
| 11315 | High | webchat code injection |
| 11310 | High | myphpPageTool code injection |
| 11303 | High | mod_frontpage installed |
| 11298 | High | axis2400 webcams |
| 11284 | High | typo3 arbitrary file reading |
| 11282 | High | Nuked-Klan function execution |
| 11281 | High | cpanel remote command execution |
| 11276 | High | CuteNews code injection |
| 11275 | High | GOsa code injection |
| 11274 | High | WihPhoto file reading |
| 11273 | High | Invision PowerBoard code injection |
| 11238 | Other | Anti Nessus defenses |
| 11236 | High | PHP-Nuke is installed on the remote host |
| 11233 | High | N/X Web Content Management code injection |
| 11230 | Low | Stronghold Swish |
| 11229 | Low | phpinfo.php |
| 11227 | High | Oracle 9iAS SOAP Default Configuration Vulnerability |
| 11226 | Other | Oracle 9iAS default error information disclosure |
| 11225 | High | Oracle 9iAS OWA UTIL access |
| 11224 | Medium | Oracle 9iAS SOAP configuration file retrieval |
| 11223 | Low | Oracle 9iAS access to SOAP documentation |
| 11221 | High | Pages Pro CD directory traversal |
| 11190 | High | overflow.cgi detection |
| 11182 | High | DB4Web directory traversal |
| 11180 | High | DB4Web TCP relay |
| 11179 | High | vBulletin's Calender Command Execution Vulnerability |
| 11176 | High | Tomcat 4.x JSP Source Exposure |
| 11173 | High | Savant cgitest.exe buffer overflow |
| 11166 | High | KF Web Server /%00 bug |
| 11165 | High | vpasswd.cgi |
| 11163 | Low | msmmask.exe |
| 11161 | High | RDS / MDAC Vulnerability Content-Type overflow |
| 11139 | High | wpoison (nasl version) |
| 11117 | High | phpPgAdmin arbitrary files reading |
| 11115 | High | gallery code injection |
| 11109 | High | Achievo code injection |
| 11107 | High | viralator |
| 11106 | High | NetTools command execution |
| 11104 | High | Directory Manager's edit_image.php |
| 11102 | High | Awol code injection |
| 11101 | High | PHPAdsNew code injection |
| 11095 | High | webcart.cgi |
| 11083 | Low | ibillpm.pl |
| 11079 | High | Snapstream PVS web directory traversal |
| 11074 | Low | OfficeScan configuration file disclosure |
| 11073 | Low | readmsg.php detection |
| 11072 | Low | Basilix Webmail Dummy Request Vulnerability |
| 11071 | High | ASP source using %20 trick |
| 11070 | High | PGPMail.pl detection |
| 11066 | High | SunSolve CD CGI user input validation |
| 11048 | Low | Resin DOS device path disclosure |
| 11043 | High | iPlanet Search Engine File Viewing |
| 11037 | Medium | WEB-INF folder accessible |
| 11027 | High | AlienForm CGI script |
| 11020 | High | NetCommerce SQL injection |
| 11018 | High | MS Site Server Information Leak |
| 11017 | High | directory.php |
| 11010 | Medium | WebSphere Cross Site Scripting |
| 11009 | Low | Lotus Domino Banner Information Disclosure Vulnerability |
| 11008 | Low | PHP4 Physical Path Disclosure Vulnerability |
| 11007 | High | ActiveState Perl directory traversal |
| 11001 | High | MRTG mrtg.cgi File Disclosure |
| 10997 | High | JRun directory traversal |
| 10993 | High | IIS ASP.NET Application Trace Enabled |
| 10991 | High | IIS Global.asa Retrieval |
| 10968 | High | ping.asp |
| 10960 | Low | ServletExec 4.1 ISAPI Physical Path Disclosure |
| 10959 | Medium | ServletExec 4.1 ISAPI File Reading |
| 10958 | High | ServletExec 4.1 / JRun ISAPI DoS |
| 10949 | Medium | BEA WebLogic Scripts Server scripts Source Disclosure (2) |
| 10932 | High | IIS .HTR ISAPI filter applied |
| 10924 | High | csSearch.cgi |
| 10922 | Medium | CVS/Entries |
| 10888 | High | mod_ssl overflow |
| 10880 | High | AdMentor Login Flaw |
| 10877 | High | GroupWise Web Interface 'HELP' hole |
| 10875 | High | Avenger's News System Command Execution |
| 10874 | Medium | Rich Media E-Commerce Stores Sensitive Information Insecurely |
| 10873 | High | GroupWise Web Interface 'HTMLVER' hole |
| 10872 | High | BadBlue Directory Traversal Vulnerability |
| 10867 | High | php POST file uploads |
| 10855 | High | Oracle XSQLServlet XSQLConfig.xml File |
| 10854 | High | Oracle 9iAS mod_plsql directory traversal |
| 10852 | Medium | Oracle 9iAS Jsp Source File Reading |
| 10851 | High | Oracle 9iAS Java Process Manager |
| 10850 | Medium | Oracle 9iAS Globals.jsa access |
| 10849 | High | Oracle 9iAS DAD Admin interface |
| 10848 | High | Oracle 9iAS Dynamic Monitoring Services |
| 10847 | Medium | SilverStream database structure |
| 10846 | Medium | SilverStream directory listing |
| 10844 | Medium | ASP.NET Cross Site Scripting |
| 10843 | Low | ASP.NET path disclosure |
| 10840 | High | Oracle 9iAS mod_plsql Buffer Overflow |
| 10839 | High | PHP.EXE / Apache Win32 Arbitrary File Reading Vulnerability |
| 10837 | High | FAQManager Arbitrary File Reading Vulnerability |
| 10831 | High | PHP Rocket Add-in File Traversal |
| 10830 | Medium | zml.cgi Directory Traversal |
| 10819 | Medium | PIX Firewall Manager Directory Traversal |
| 10818 | High | Alchemy Eye HTTP Command Execution |
| 10817 | High | Interactive Story Directory Traversal Vulnerability |
| 10814 | Medium | Allaire JRun directory browsing vulnerability |
| 10811 | High | ActivePerl perlIS.dll Buffer Overflow |
| 10810 | High | PHP-Nuke Gallery Add-on File View |
| 10807 | Low | Jakarta Tomcat Path Disclosure |
| 10803 | Medium | Redhat Stronghold File System Disclosure |
| 10801 | High | IMP Session Hijacking Bug |
| 10799 | High | IBM-HTTP-Server View Code |
| 10797 | Medium | ColdFusion Debug Mode |
| 10795 | Medium | Lotus Notes ?OpenServer Information Disclosure |
| 10789 | High | Novell Groupwise WebAcc Information Disclosure |
| 10784 | High | ht://Dig's htsearch potential exposure/dos |
| 10783 | High | PCCS-Mysql User/Password Exposure |
| 10781 | Medium | Outlook Web anonymous access |
| 10779 | High | CGIEmail's CGICso (Send CSO via CGI) Command Execution Vulnerability |
| 10778 | High | Unprotected SiteScope Service |
| 10776 | High | Power Up Information Disclosure |
| 10775 | High | E-Shopping Cart Arbitrary Command Execution (WebDiscount) |
| 10774 | High | ShopPlus Arbitrary Command Execution |
| 10773 | Medium | MacOS X Finder reveals contents of Apache Web files |
| 10772 | High | PHP-Nuke copying files security vulnerability (admin.php) |
| 10770 | High | sglMerchant Information Disclosure Vulnerability |
| 10769 | High | Checks for listrec.pl |
| 10767 | High | Tests for Nimda Worm infected HTML files |
| 10765 | Medium | SQLQHit Directory Structure Disclosure |
| 10756 | Medium | MacOS X Finder reveals contents of Apache Web directories |
| 10750 | High | phpMyExplorer dir traversal |
| 10739 | High | Novell Web Server NDS Tree Browsing |
| 10733 | High | InterScan VirusWall Remote Configuration Vulnerability |
| 10725 | High | SIX Webboard's generate.cgi |
| 10721 | High | ncbook/book.cgi |
| 10720 | High | sdbsearch.cgi |
| 10716 | Medium | OmniPro HTTPd 2.08 scripts source full disclosure |
| 10715 | Medium | BEA WebLogic Scripts Server scripts Source Disclosure |
| 10712 | High | quickstore traversal |
| 10711 | High | Sambar webserver pagecount hole |
| 10702 | High | Zope DoS |
| 10696 | High | ttawebtop |
| 10686 | Low | BroadVision Physical Path Disclosure Vulnerability |
| 10679 | High | directory pro web traversal |
| 10672 | Other | Unknown CGIs arguments torture |
| 10670 | Low | PHP3 Physical Path Disclosure Vulnerability |
| 10669 | High | A1Stats Traversal |
| 10665 | Low | tektronix's _ncl_items.shtml |
| 10664 | High | perlcal |
| 10662 | Other | Web mirroring |
| 10656 | High | Resin traversal |
| 10655 | High | PHP-Nuke' opendir |
| 10650 | High | VirusWall's catinfo overflow |
| 10649 | Medium | processit |
| 10645 | High | ustorekeeper |
| 10644 | High | anacondaclip CGI vulnerability |
| 10641 | High | mailnews.cgi |
| 10639 | High | store.cgi |
| 10630 | Medium | PHP-Nuke security vulnerability (bb_smilies.php) |
| 10627 | High | ROADS' search.pl |
| 10623 | High | Savant original form CGI access |
| 10618 | High | Pi3Web tstisap.dll overflow |
| 10616 | Medium | webspirs.cgi |
| 10614 | High | sendtemp.pl |
| 10613 | Low | Oracle XSQL Sample Application Vulnerability |
| 10612 | High | commerce.cgi |
| 10611 | High | pals-cgi |
| 10610 | High | way-board |
| 10609 | Low | empower cgi path |
| 10606 | Low | HSWeb document path |
| 10604 | Medium | Allaire JRun Directory Listing |
| 10602 | High | hsx directory traversal |
| 10601 | High | Basilix includes download |
| 10597 | High | wwwwais |
| 10594 | High | Oracle XSQL Stylesheet Vulnerability |
| 10593 | High | phorum's common.cgi |
| 10592 | High | webdriver |
| 10591 | High | pagelog.cgi |
| 10589 | High | iPlanet Directory Server traversal |
| 10586 | High | news desk |
| 10584 | High | technote's main.cgi |
| 10583 | High | dcforum |
| 10581 | High | Cold Fusion Administration Page Overflow |
| 10574 | High | PHPix directory traversal vulnerability |
| 10570 | High | Unify eWave ServletExec 3.0C file upload |
| 10569 | High | Zope Image updating Method |
| 10566 | High | mmstdod.cgi |
| 10564 | High | IIS phonebook |
| 10562 | High | Master Index directory traversal vulnerability |
| 10552 | High | cgiforum |
| 10542 | High | UltraSeek 3.1.x Remote DoS |
| 10541 | High | KW whois |
| 10526 | Low | IIS : Directory listing through WebDAV |
| 10521 | High | Extent RBS ISP |
| 10518 | High | /doc/packages directory browsable ? |
| 10516 | High | multihtml cgi |
| 10514 | Low | Directory listing through Sambar's search.dll |
| 10512 | High | YaBB |
| 10511 | Low | /perl directory browsable ? |
| 10507 | High | Sun's Java Web Server remote command execution |
| 10506 | High | calendar_admin.pl |
| 10505 | Low | Directory listing through WebDAV |
| 10503 | High | Reading CGI script sources using /cgi-bin-sdb |
| 10495 | High | htgrep |
| 10494 | High | Netauth |
| 10493 | High | SWC Overflow |
| 10491 | High | ASP/ASA source using Microsoft Translate f: bug |
| 10489 | High | AnalogX web server traversal |
| 10484 | High | Read any file thanks to ~nobody/ |
| 10480 | High | Apache::ASP source.asp |
| 10479 | High | Roxen Server /%00/ bug |
| 10478 | Low | Tomcat's snoop servlet gives too much information |
| 10477 | High | Tomcat's /admin is world readable |
| 10476 | High | WebsitePro buffer overflow |
| 10475 | High | Buffer overflow in WebSitePro webfind.exe |
| 10473 | High | MiniVend Piped command |
| 10470 | Low | WebActive world readable log file |
| 10468 | Medium | Netscape Administration Server admin password |
| 10467 | Medium | ftp.pl shows the listing of any dir |
| 10465 | High | CVSWeb 1.80 gives a shell to cvs committers |
| 10460 | High | bb-hostsvc.sh |
| 10459 | High | Poll It v2.0 cgi |
| 10447 | High | Zope DocumentTemplate package problem |
| 10444 | High | JRun's viewsource.jsp |
| 10417 | High | Sambar /cgi-bin/mailit.pl installed ? |
| 10416 | High | Sambar /sysadmin directory 2 |
| 10415 | High | Sambar sendmail /session/sendmail |
| 10405 | Low | shtml.exe reveals full path |
| 10403 | Medium | DBMan CGI server information leakage |
| 10402 | Low | CVSWeb detection |
| 10393 | High | spin_client.cgi buffer overrun |
| 10386 | Other | No 404 check |
| 10385 | Low | ht://Dig's htsearch reveals web server path |
| 10383 | High | bizdb1-search.cgi located |
| 10376 | High | htimage.exe overflow |
| 10373 | Low | TalentSoft Web+ version detection |
| 10372 | High | /scripts/repost.asp |
| 10371 | High | /iisadmpwd/aexp2.htr |
| 10370 | High | IIS dangerous sample files |
| 10369 | High | Microsoft Frontpage dvwssr.dll backdoor |
| 10367 | Medium | TalentSoft Web+ Input Validation Bug Vulnerability |
| 10365 | High | Windmail.exe allows any user to execute arbitrary commands |
| 10364 | Medium | netscape publishingXpert 2 PSUser problem |
| 10363 | High | ASP source using %2e trick |
| 10362 | High | ASP source using ::$DATA trick |
| 10360 | High | newdsn.exe check |
| 10359 | High | ctss.idc check |
| 10358 | High | /iisadmin is world readable |
| 10356 | High | Microsoft's Index server reveals ASP source code |
| 10352 | Medium | Netscape Server ?wp bug |
| 10349 | High | sojourn.cgi |
| 10348 | High | ows-bin |
| 10340 | Low | rpm_query CGI |
| 10327 | High | Zeus shows the content of the cgi scripts |
| 10321 | Medium | wwwboard passwd.txt |
| 10317 | Low | wrap |
| 10306 | High | whois_raw |
| 10304 | High | WebSpeed remote configuration |
| 10303 | Low | WebSite pro reveals the physical file path of web directories |
| 10301 | High | websendmail |
| 10300 | High | webgais |
| 10299 | High | webdist.cgi |
| 10298 | High | Webcart misconfiguration |
| 10297 | High | Web server traversal |
| 10296 | High | w3-msql overflow |
| 10295 | Medium | OmniHTTPd visadmin exploit |
| 10294 | High | view_source |
| 10291 | High | uploader.exe |
| 10290 | High | Upload cgi |
| 10282 | High | test-cgi |
| 10277 | High | AnyForm |
| 10253 | High | Cobalt siteUserMod cgi |
| 10252 | High | Shells in /cgi-bin |
| 10246 | High | Sambar Web Server CGI scripts |
| 10207 | High | Roxen counter module |
| 10188 | Medium | printenv |
| 10187 | Medium | Cognos Powerplay WE Vulnerability |
| 10181 | High | PlusMail vulnerability |
| 10178 | High | php.cgi buffer overrun |
| 10177 | High | php.cgi |
| 10176 | High | phf |
| 10174 | High | pfdispaly |
| 10173 | High | perl interpreter can be launched as a CGI |
| 10165 | High | nph-test-cgi |
| 10164 | High | nph-publish.cgi |
| 10156 | Medium | Netscape FastTrack 'get' |
| 10153 | Medium | Netscape Server ?PageServices bug |
| 10143 | High | MSQL CGI overflow |
| 10142 | High | MS Personal WebServer ... |
| 10140 | High | MediaHouse Statistic Server Buffer Overflow |
| 10131 | High | jj cgi |
| 10128 | High | infosrch.cgi |
| 10127 | High | info2www |
| 10122 | High | imagemap.exe |
| 10121 | Medium | /scripts directory browsable |
| 10120 | Low | IIS perl.exe problem |
| 10115 | High | idq.dll directory traversal |
| 10112 | High | icat |
| 10106 | High | Htmlscript |
| 10105 | High | htdig |
| 10101 | High | Home Free search.cgi directory traversal |
| 10100 | High | Handler |
| 10099 | High | guestbook.pl |
| 10098 | High | guestbook.cgi |
| 10095 | High | glimpse |
| 10078 | Medium | Microsoft Frontpage 'authors' exploits |
| 10077 | High | Microsoft Frontpage exploits |
| 10076 | High | formmail.pl |
| 10075 | High | FormHandler.cgi |
| 10071 | High | Finger cgi |
| 10067 | High | Faxsurvey |
| 10065 | High | EZShopper 3.0 |
| 10064 | High | Excite for WebServers |
| 10060 | Low | Dumpenv |
| 10058 | Low | Domino HTTP server exposes the set up of the filesystem |
| 10056 | High | /doc directory browsable ? |
| 10049 | High | Count.cgi |
| 10041 | Medium | Cobalt RaQ2 cgiwrap |
| 10040 | High | cgitest.exe buffer overrun |
| 10039 | Medium | /cgi-bin directory browsable ? |
| 10037 | Low | CERN httpd problem |
| 10035 | High | Campas |
| 10034 | High | RedHat 6.0 cachemgr.cgi |
| 10027 | High | bigconf |
| 10025 | High | bb-hist.sh |
| 10023 | High | Bypass Axis Storpoint CD authentication |
| 10016 | High | AN-HTTPd tests CGIs |
| 10015 | High | AltaVista Intranet Search |
| 10014 | High | tst.bat CGI vulnerability |
| 10013 | High | alibaba.pl |
| 10011 | High | get32.exe vulnerability |
| 10007 | High | ShowCode possible |
| 10004 | High | IIS possible DoS using ExAir's search |
| 10003 | High | IIS possible DoS using ExAir's query |
| 10002 | High | IIS possible DoS using ExAir's advsearch |
| 10001 | High | ColdFusion Vulnerability |