If Telnet or FTP is enabled, The Vulnerability Assessment Engine will
test
| Family |
Name |
CVE ID |
Summary |
| Aix local security checks |
Aix maintenance level |
|
Check for maintenance level patch |
| Backdoors |
4553 parasite mothership detect |
|
Detects the presence of 4553 parasite's mothership |
| Backdoors |
Agobot.fo backdoor detection |
|
Determines the presence of agobot.fo |
| Backdoors |
Alcatel omniswitch 7700/7800 switches backdoor |
Cve-2002-1272 |
Checks for the presence of backdoor in alcatel 7700/7800 switches |
| Backdoors |
Apache mod_rootme backdoor |
Can-1999-0660 |
Detect mod_rootme backdoor |
| Backdoors |
Backorifice |
Cve-1999-0660 |
Determines the presence of backorifice |
| Backdoors |
Bofra virus detection |
Cve-2004-1050 |
Determines the presence of a bofra virus infection resulting from an iframe exploit |
| Backdoors |
Bugbear worm |
Cve-2001-0154 |
Detect bugbear worm |
| Backdoors |
Bugbear.b web backdoor |
|
Checks for bugbear.b web backdoor |
| Backdoors |
Bugbear.b worm |
|
Detect bugbear.b worm |
| Backdoors |
Cdk detect |
Cve-1999-0660 |
Detects the presence of cdk |
| Backdoors |
Cart32 changeadminpassword |
Cve-2000-0429 |
Determines the presence of cart32 |
| Backdoors |
Check for vnc http |
|
Detects the presence of vnc http |
| Backdoors |
Codered version x detection |
Cve-2001-0500 |
Codered version x detection |
| Backdoors |
Dabber worm detection |
|
Dabber worm detection |
| Backdoors |
Dansie shopping cart backdoor |
Cve-2000-0252 |
Determines the presence of dansie shopping cart |
| Backdoors |
Deepthroat |
Cve-1999-0660 |
Checks for the presence of deepthroat |
| Backdoors |
Default web account on zyxel |
Cve-2001-1135, cve-1999-0571 |
Logs into the zyxel web administration |
| Backdoors |
Desktop orbiter server detection |
|
Checks for the presence desktop orbiter |
| Backdoors |
Finger backdoor |
Cve-1999-0660 |
Finger cmd_root@host backdoor |
| Backdoors |
Fluxay sensor detection |
|
Determines the presence of fluxay sensor |
| Backdoors |
Fssniffer detection |
|
Determines the presence of fssniffer |
| Backdoors |
Gatecrasher |
Cve-1999-0660 |
Checks for the presence of gatecrasher |
| Backdoors |
Girlfriend |
Cve-1999-0660 |
Checks for the presence of girlfriend |
| Backdoors |
Hacker defender finder |
|
Hacker defender finder (all versions) |
| Backdoors |
Iis download.ject trojan detection |
|
Iis download.ject trojan detection |
| Backdoors |
Iis possible compromise |
|
Searches for traces of a system compromise. |
| Backdoors |
Irc bot detection |
|
Fake ident server (irc bot) |
| Backdoors |
Irc bot ident server detection |
|
Determines the presence of a malicious ident server |
| Backdoors |
Jrun sample files |
Cve-2000-0539 |
Checks for the presence of jrun sample files |
| Backdoors |
Kibuv worm detection |
|
Detect the kibuv.b worm ftp server banner |
| Backdoors |
Korgo worm detection |
|
Korgo worm detection |
| Backdoors |
Kuang2 the virus |
Cve-1999-0660 |
Checks for kuang2 the virus |
| Backdoors |
Lion worm |
|
Determines the presence of lion |
| Backdoors |
Mpei/x default accounts |
Cve-1999-0502 |
Checks for open accounts |
| Backdoors |
Moonlit virus backdoor |
|
Detect moonlit virus |
| Backdoors |
Mydoom virus backdoor |
|
Detect mydoom worm |
| Backdoors |
Netbus 1.x |
Cve-1999-0660 |
Checks for the presence of netbus 1.x |
| Backdoors |
Netbus 2.x |
Cve-1999-0660 |
Determines the presence of netbus pro |
| Backdoors |
Netsphere backdoor |
Cve-1999-0660 |
Checks for the presence of netsphere |
| Backdoors |
Port tcp:0 |
|
Open a tcp connection to port 0 |
| Backdoors |
Portal of doom |
Cve-1999-0660 |
Checks for the presence of portal of doom |
| Backdoors |
Post-nuke trojan horse |
|
Determines if post-nuke is trojaned |
| Backdoors |
Remote pc access server detection |
|
Checks for the presence pc anywhere |
| Backdoors |
Remotenc detection |
|
Determines the presence of remotenc |
| Backdoors |
Remotelyanywhere ssh detection |
|
Detect remotelyanywhere ssh server |
| Backdoors |
Remotelyanywhere www detection |
|
Detect remotelyanywhere www server |
| Backdoors |
Smtp server on a strange port |
|
An smtp server is running on a non standard port |
| Backdoors |
Sasser virus detection |
|
Sasser virus detection |
| Backdoors |
Shaft detect |
Cve-2000-0138 |
Detects the presence of shaft |
| Backdoors |
Stacheldraht detect |
Cve-2000-0138 |
Detects the presence of stacheldraht |
| Backdoors |
Subseven |
Cve-1999-0660 |
Determines the presence of subseven |
| Backdoors |
Sygate backdoor |
Cve-2000-0113 |
Detects whether sygate remote controller is running |
| Backdoors |
Tfn detect |
Cve-2000-0138 |
Detects the presence of tfn |
| Backdoors |
Tftp backdoor |
|
Retrieve an executable file through tftp |
| Backdoors |
The remote host is infected by the zotob worm |
|
Connects to port 8888 |
| Backdoors |
Trin00 detect |
Cve-2000-0138 |
Detects the presence of trin00 |
| Backdoors |
Trin00 for windows detect |
Cve-2000-0138 |
Detects the presence of trin00 |
| Backdoors |
Trinity v3 detect |
Cve-2000-0138 |
Detects the presence of trinity v3 |
| Backdoors |
Trojan horses |
|
Look for potential trojan horses |
| Backdoors |
Urcs server detection |
|
Determines the presence of the urcs server |
| Backdoors |
Unpassworded bash account |
|
Logs into the remote host with bash account |
| Backdoors |
Winsatan |
|
Checks for the presence of winsatan |
| Backdoors |
Wollf backdoor detection |
|
Determines the presence of wollf |
| Backdoors |
Xampp default ftp account |
Cve-2005-1078 |
Attempts to log in via ftp as nobody/xampp |
| Backdoors |
Xerox microserver unauthorized access vulnerabilities |
Cve-2005-0703, cve-2005-1179 |
Checks for unauthorized access vulnerabilities in xerox microserver |
| Backdoors |
Zincite.a (mydoom.m) backdoor |
|
Detect mydoom worm |
| Backdoors |
Alya.cgi |
|
Detects /cgi-bin/alya.cgi |
| Backdoors |
Lovgate virus is installed |
|
Checks for the presence of luvgate |
| Backdoors |
Mstream agent detect |
Cve-2000-0138 |
Detects the presence of a mstream agent |
| Backdoors |
Mstream handler detect |
Cve-2000-0138 |
Detects the presence of a mstream agent |
| Backdoors |
Radmin detection |
|
Detect radmin |
| Backdoors |
Radmin on port 10002 - possible gdi compromise |
Cve-2004-0200 |
Detect radmin |
| Backdoors |
W32.spybot.fcd worm infection |
|
Detects if w32.spybot.fcd is installed on the remote host |
| Cgi abuses |
'les visiteurs' script injection |
Cve-2003-1148 |
Les visiteurs inc file upload |
| Cgi abuses |
/cgi-bin directory browsable ? |
|
Is /cgi-bin browsable ? |
| Cgi abuses |
/doc directory browsable ? |
Cve-1999-0678 |
Is /doc browsable ? |
| Cgi abuses |
/doc/packages directory browsable ? |
Cve-2000-1016 |
Is /doc/packages browseable ? |
| Cgi abuses |
/perl directory browsable ? |
Cve-2000-0883 |
Is /perl browsable ? |
| Cgi abuses |
2bgal sql injection |
Cve-2004-1415 |
Sql injection |
| Cgi abuses |
3com nbx voip netset detection |
Can-2004-1977 |
Tests for 3com nbx voip netset detection |
| Cgi abuses |
3com network supervisor directory traversal vulnerability |
Cve-2005-2020 |
Checks for directory traversal vulnerability in 3com network supervisor |
| Cgi abuses |
4images <= 1.7.1 directory traversal vulnerability |
Cve-2006-0899 |
Check if 4images is vulnerable to directory traversal flaws |
| Cgi abuses |
@lex guestbook remote file include |
Cve-2004-1554 |
Checks for @lex guestbook |
| Cgi abuses |
A1stats traversal |
Cve-2001-0561 |
Checks if a1stats reads any file |
| Cgi abuses |
Acal path parameter remote file include vulnerability |
Cve-2006-2261 |
Tries to read /etc/passwd using acal |
| Cgi abuses |
Adodb do command execution vulnerability |
|
Checks for do parameter command execution vulnerability in adodb |
| Cgi abuses |
Adodb sql parameter sql injection vulnerability |
Cve-2006-0146 |
Checks for sql parameter sql injection vulnerability in adodb |
| Cgi abuses |
Amember config[root_dir] parameter file include vulnerability |
|
Checks for config[root_dir] parameter file include vulnerability in amember |
| Cgi abuses |
An httpd count.pl file truncation |
|
Creates a file on the remote server |
| Cgi abuses |
An-httpd tests cgis |
Cve-1999-0947 |
Checks for the presence of several cgis |
| Cgi abuses |
Asp inline corporate calendar sql injection |
|
Checks for the presence of an sql injection in defer.asp |
| Cgi abuses |
Asp portalapp sql injection |
Cve-2005-0948, cve-2005-0949 |
Sql injection |
| Cgi abuses |
Asp source using %20 trick |
Cve-2001-1248 |
Downloads the source of asp scripts |
| Cgi abuses |
Asp source using %2e trick |
Cve-1999-0253 |
Downloads the source of asp scripts |
| Cgi abuses |
Asp source using ::$data trick |
Cve-1999-0278 |
Downloads the source of asp scripts |
| Cgi abuses |
Asp-rider sql injection |
Cve-2004-1401 |
Sql injection |
| Cgi abuses |
Asp.net path disclosure |
|
Tests for asp.net path disclosure vulnerability |
| Cgi abuses |
Asp/asa source using microsoft translate f: bug |
Cve-2000-0778 |
Downloads the source of iis scripts such as asa,asp |
| Cgi abuses |
Asp/asa source using microsoft translate f: bug (iis 5.1) |
|
Downloads the source of iis scripts such as asa,asp |
| Cgi abuses |
Aspjar guestbook sql injection |
Can-2005-0423 |
Checks for the presence of an sql injection in login.asp |
| Cgi abuses |
Atutor < 1.5.1-pl1 multiple flaws |
Cve-2005-3403, cve-2005-3404, cve-2005-3405 |
Checks for remote arbitrary command in atutor |
| Cgi abuses |
Atutor password reminder sql injection |
Cve-2005-2954 |
Checks for sql injection in password_reminder.php |
| Cgi abuses |
Awstats debug remote information disclosure and code execution vulnerabilities |
|
Determines the presence of a debug output in awstats |
| Cgi abuses |
Awstats referrer arbitrary command execution vulnerability |
Cve-2005-1527 |
Checks for referrer arbitrary command execution vulnerability in awstats |
| Cgi abuses |
Awstats configdir parameter arbitrary cmd exec |
|
Determines the presence of awstats awstats.pl flaws |
| Cgi abuses |
Awstats migrate parameter remote file include vulnerability |
Cve-2006-2237 |
Tries to run a command using awstats |
| Cgi abuses |
Awstats rawlog plugin logfile parameter input validation vulnerability |
|
Determines the presence of awstats awstats.pl |
| Cgi abuses |
Aardvark topsites config[path] parameter remote file inclusion vulnerability |
Cve-2006-2149 |
Checks for a file include using config[path] in aardvark topsites |
| Cgi abuses |
Aborior command execution |
Cve-2004-1888 |
Detects display.cgi |
| Cgi abuses |
Achievo code injection |
Cve-2002-1435 |
Checks for the presence of achievo |
| Cgi abuses |
Activeauction multiple vulnerabilities |
Cve-2005-1029, cve-2005-1030 |
Checks the version of vbulletin |
| Cgi abuses |
Activeperl perlis.dll buffer overflow |
Cve-2001-0815 |
Determines if arbitrary commands can be executed thanks to activeperl's perlis.dll |
| Cgi abuses |
Activestate perl directory traversal |
|
Determines if activeperl is vulnerable |
| Cgi abuses |
Actualanalyzer rf parameter remote file include vulnerability |
Cve-2006-1959 |
Tries to read /etc/passwd using actualanalyzer |
| Cgi abuses |
Admentor login flaw |
Can-2002-0308 |
Admentor login flaw |
| Cgi abuses |
Adcycle password disclosure |
Cve-2000-1161 |
Checks for the presence of /cgi-bin/build.cgi |
| Cgi abuses |
Admbook php code injection flaw |
Cve-2006-0852 |
Checks for remote php code injection in admbook |
| Cgi abuses |
Adobe document server default credentials |
|
Checks for default credentials in adobe document server |
| Cgi abuses |
Adobe document server file uri resource access vulnerability |
Cve-2006-1182 |
Tries to write to a file using adobe document server |
| Cgi abuses |
Adobe document server for reader extensions < 6.1 multiple vulnerabilities |
Cve-2006-1627, cve-2006-1785, cve-2006-1786, cve-2006-1787, cve-2006-1788 |
Tries to exploit an xss flaw in adobe document server for reader extensions |
| Cgi abuses |
Advanced guestbook index.php sql injection vulnerability |
Cve-2005-1548 |
Checks for an sql injection attack in advanced guestbook |
| Cgi abuses |
Advanced guestbook phpbb_root_path parameter remote file include vulnerability |
Cve-2006-2152 |
Tries to read /etc/passwd using advanced guestbook |
| Cgi abuses |
Advanced poll info.php |
|
Checks for the presence of info.php |
| Cgi abuses |
Alchemy eye http command execution |
Cve-2001-0871 |
Determines if arbitrary commands can be executed by alchemy eye |
| Cgi abuses |
Alexandria-dev upload spoofing |
|
Checks for the presence of patch/index.php and docman/new.php |
| Cgi abuses |
Alienform cgi script |
Cve-2002-0934 |
Checks if the alienform cgi script is vulnerable |
| Cgi abuses |
Alkalay.net multiple scripts arbitrary command execution vulnerabilities |
|
Checks for arbitrary command execution vulnerabilities in multiple scripts from alkalay.net |
| Cgi abuses |
Allaire jrun directory listing |
Cve-2000-1050 |
Make a request like http://www.example.com/./web-inf |
| Cgi abuses |
Allaire jrun directory browsing vulnerability |
Cve-2001-1510 |
Allaire jrun directory browsing vulnerability |
| Cgi abuses |
Alt-n webadmin multiple remote vulnerabilities |
Cve-2005-0317, cve-2005-0318, cve-2005-0319 |
Checks for the version of alt-n webadmin |
| Cgi abuses |
Altavista intranet search |
Cve-2000-0039 |
Checks if query?mss=... reads arbitrary files |
| Cgi abuses |
Analogx web server traversal |
Cve-2000-0664 |
%2e%2e/%2e%2e/file.txt |
| Cgi abuses |
Angelinecms installpath remote file include vulnerability |
Cve-2006-1653 |
Tries to read /etc/passwd using angelinecms |
| Cgi abuses |
Anti nessus defenses |
|
Detects anti nessus features |
| Cgi abuses |
Anyform |
Cve-1999-0066 |
Checks for the presence of anyform2 |
| Cgi abuses |
Apache tomcat directory listing and file disclosure |
Cve-2003-0042 |
Apache tomcat directory listing and file disclosure bugs |
| Cgi abuses |
Apache tomcat source.jsp malformed request information disclosure |
|
Checks for the tomcat source.jsp malformed request vulnerability |
| Cgi abuses |
Apache for windows cgi source code disclosure vulnerability |
|
Tries to read source of print-env.pl with apache for windows |
| Cgi abuses |
Appserv appserv_root parameter remote file include vulnerability |
Cve-2006-0125 |
Checks for appserv_root parameter remote file include vulnerability in appserv |
| Cgi abuses |
Argosoft mail server directory traversal vulnerability |
|
Gets the version of the remote argosoft server |
| Cgi abuses |
Argosoft mail server multiple flaws |
|
Gets the version of the remote argosoft server |
| Cgi abuses |
Argosoft mail server multiple flaws(2) |
|
Gets the version of the remote argosoft server |
| Cgi abuses |
Artmedic kleinanzeigen file inclusion vulnerability |
|
Checks for artmedic kleinanzeigen's php inclusion vulnerability |
| Cgi abuses |
Ashnews code injection |
Cve-2006-0524 |
Checks for the presence of ashnews.php |
| Cgi abuses |
Aspupload vulnerability |
Cve-2001-0938 |
Checks for the aspupload software |
| Cgi abuses |
Asterisk recording interface configuration file disclosure vulnerability |
Cve-2006-2020 |
Tries to read ari's configuration file |
| Cgi abuses |
Asterisk recording interface recording parameter information disclosure vulnerability |
Cve-2006-2021 |
Requests a file using ari's misc/audio.php |
| Cgi abuses |
Athena web registration remote command execution flaw |
Cve-2004-1782 |
Checks for athena web registration remote command execution flaw |
| Cgi abuses |
Atomic photo album apa_module_basedir variable file include vulnerability |
Cve-2005-2413 |
Checks for apa_module_basedir variable file include vulnerability in atomic photo album |
| Cgi abuses |
Atomicboard file reading |
|
Checks for the presence of remotehtmlview.php |
| Cgi abuses |
Autolinks pro alpath parameter file include vulnerability |
Cve-2005-2782 |
Checks for alpath parameter file include vulnerability in autolinks pro |
| Cgi abuses |
Autotheme postnuke module multiple unspecified vulnerabilities |
Cve-2005-1608 |
Checks for multiple unspecified vulnerabilities in autotheme postnuke module |
| Cgi abuses |
Automatedshops webc.cgi buffer overflows |
|
Checks for the presence of webc.cgi |
| Cgi abuses |
Automatedshops webc.cgi installed |
|
Checks for the presence of webc.cgi |
| Cgi abuses |
Avenger's news system command execution |
Can-2002-0307 |
Avenger's news system command execution |
| Cgi abuses |
Awol code injection |
Cve-2001-1048 |
Checks for the presence of includes/awol-condensed.inc.php |
| Cgi abuses |
Base base_path parameter remote file include vulnerability |
Cve-2006-2685 |
Tries to read a local file using base |
| Cgi abuses |
Base base_maintenance authentication bypass vulnerability |
Cve-2006-1505 |
Tries to bypass authentication in base |
| Cgi abuses |
Bbs e-market file disclosure |
|
Directory traversal attempt |
| Cgi abuses |
Bdpdt arbitrary code execution vulnerabilities |
|
Tries to executes a command via bdpdt's cmd.aspx |
| Cgi abuses |
Bea weblogic operator/admin password disclosure vulnerability |
Cve-2004-1757 |
Checks the version of weblogic |
| Cgi abuses |
Bea weblogic scripts server scripts source disclosure |
|
Bea weblogic may be tricked into revealing the source code of jsp scripts. |
| Cgi abuses |
Bea weblogic scripts server scripts source disclosure (2) |
|
Bea weblogic may be tricked into revealing the source code of jsp scripts. |
| Cgi abuses |
Bea weblogic scripts server scripts source disclosure (3) |
Cve-2000-0683 |
Bea weblogic may be tricked into revealing the source code of jsp scripts. |
| Cgi abuses |
Blnews code injection |
Cve-2003-0394 |
Checks for the presence of objects.inc.php4 |
| Cgi abuses |
Brt copperexport xp_publish.php sql injection vulnerability |
|
Sql injection in copperexport |
| Cgi abuses |
Backup cgis download |
|
Attempts to download the remote cgis |
| Cgi abuses |
Barracuda networks spam firewall multiple vulnerabilities |
Cve-2006-4000, cve-2006-4001 |
Tries to authenticate to barracuda networks spam firewall |
| Cgi abuses |
Barracuda spam firewall firmware < 3.1.18 multiple vulnerabilities |
Cve-2005-2847, cve-2005-2848 |
Checks for multiple vulnerabilities in barracuda spam firewall firmware < 3.1.18 |
| Cgi abuses |
Basilix arbitrary command execution vulnerability |
|
Checks for arbitrary command execution vulnerability in basilix |
| Cgi abuses |
Basilix arbitrary file disclosure vulnerability |
Cve-2002-1710 |
Checks for arbitrary file disclosure vulnerability in basilix |
| Cgi abuses |
Basilix attachment disclosure vulnerability |
Cve-2002-1711 |
Checks for attachment disclosure vulnerability in basilix |
| Cgi abuses |
Basilix detection |
|
Checks for the presence of basilix |
| Cgi abuses |
Basilix message content script injection vulnerability |
Cve-2002-1708 |
Checks for message content script injection vulnerability in basilix |
| Cgi abuses |
Basilix sql injection vulnerability |
Cve-2002-1709 |
Checks for sql injection vulnerability in basilix |
| Cgi abuses |
Basilix webmail dummy request vulnerability |
Cve-2001-1045 |
Checks for the presence of basilix.php3 |
| Cgi abuses |
Basilix includes download |
Cve-2001-1044 |
Checks for the presence of include files |
| Cgi abuses |
Bitboard img bbcode tag javascript injection vulnerability |
Cve-2005-0374 |
Determines the version of bitboard |
| Cgi abuses |
Bizmail.cgi mail from unauthorized mail relay vulnerability |
|
Checks the version of bizmail.cgi |
| Cgi abuses |
Blackboard internet newsboard system remote file include flaw |
Cve-2004-1582 |
Checks blackboard internet newsboard system version |
| Cgi abuses |
Blazix web server jsp source disclosure |
Cve-2002-1451 |
Attempts to read the source of a jsp page |
| Cgi abuses |
Blog torrent remote directory traversal |
Cve-2004-1212 |
Looks for a directory traversal vulnerability in blog torrent. |
| Cgi abuses |
Bluedragon 6.2.1 multiple vulnerabilities |
Cve-2006-2310, cve-2006-2311 |
Checks for an xss flaw in bluedragon server |
| Cgi abuses |
Bonsai mutiple flaws |
Cve-2003-0152, cve-2003-0153, cve-2003-0154, cve-2003-0155 |
Determine if bonsai is vulnerable to xss attack |
| Cgi abuses |
Brio unix directory traversal |
|
Brio unix directory traversal |
| Cgi abuses |
Broadboard sql injection |
Cve-2004-1555 |
Sql injection |
| Cgi abuses |
Broadvision physical path disclosure vulnerability |
Cve-2001-0031 |
Tests for broadvision physical path disclosure vulnerability |
| Cgi abuses |
Brooky cubecart < 2.0.5 |
Cve-2005-0442, cve-2005-0443 |
Checks brooky cubecart language xss |
| Cgi abuses |
Buffer overflow in website professional's webfind.exe |
Cve-2000-0622 |
Buffer overflow attempt |
| Cgi abuses |
Bugport unspecified attachment handling flaw |
|
Checks for bugport version |
| Cgi abuses |
Bugzilla <= 2.18.1 / 2.19.3 multiple vulnerabilities |
|
Checks for multiple vulnerabilities in bugzilla <= 2.18.1 / 2.19.3 |
| Cgi abuses |
Bugzilla authentication bypass and information disclosure |
Cve-2004-1634, cve-2004-1635 |
Checks for the presence of bugzilla |
| Cgi abuses |
Bugzilla detection |
|
Checks for the presence of bugzilla |
| Cgi abuses |
Bugzilla information disclosure vulnerabilities |
Cve-2005-1563, cve-2005-1564, cve-2005-1565 |
Checks for information disclosure vulnerabilities in bugzilla |
| Cgi abuses |
Bugzilla multiple flaws |
Cve-2003-0012, cve-2003-0013, cve-2002-1198, cve-2002-1197, cve-2002-1196 |
Checks for the presence of bugzilla |
| Cgi abuses |
Bugzilla multiple flaws (2) |
Cve-2004-0702, cve-2004-0703, cve-2004-0704, cve-2004-0705, cve-2004-0706, cve-2004-0707 |
Checks for the presence of bugzilla |
| Cgi abuses |
Bugzilla sql flaws |
Cve-2003-1042, cve-2003-1043, cve-2003-1044, cve-2003-1045, cve-2003-1046 |
Checks for the presence of bugzilla |
| Cgi abuses |
Bugzilla xss and insecure temporary filenames |
Cve-2003-0603 |
Checks for the presence of bugzilla |
| Cgi abuses |
Bugzilla remote arbitrary command execution |
Cve-2000-0421, cve-2001-0329 |
Checks for the version of bugzilla |
| Cgi abuses |
Bulletscript maillist bsml.pl information disclosure |
|
Determine if minibb can be used to execute arbitrary commands |
| Cgi abuses |
Burning board detection |
|
Checks for presence of burning board |
| Cgi abuses |
Burning board modcp.php sql injection vulnerabilities |
Cve-2005-2673 |
Checks for sql injection vulnerabilities in burning board modcp.php script |
| Cgi abuses |
Burning board verify_email sql injection vulnerability |
Cve-2005-1642 |
Checks for verify_email sql injection vulnerability in burning board |
| Cgi abuses |
Bypass axis storpoint cd authentication |
Cve-2000-0191 |
Requests /cd/../config/html/cnf_gi.htm |
| Cgi abuses |
Cgiemail's cgicso (send cso via cgi) command execution vulnerability |
Can-2002-1652 |
Determine if a remote host is vulnerable to the cgicso vulnerability |
| Cgi abuses |
Cms made simple nls parameter file include vulnerability |
Cve-2005-2846 |
Checks for nls parameter file include vulnerability in cms made simple |
| Cgi abuses |
Csnews.cgi vulnerability |
Cve-2002-0923 |
Checks for the csnews.cgi file |
| Cgi abuses |
Cvs/entries |
|
Requests cvs/entries |
| Cgi abuses |
Cvstrac cvsroot/passwd arbitrary account deletion |
|
Checks for cvstrac version |
| Cgi abuses |
Cvstrac detection |
|
Detects the presence of cvstrac |
| Cgi abuses |
Cvstrac cgi.c multiple overflows |
|
Checks for cvstrac version |
| Cgi abuses |
Cvstrac chdir() chroot jail escape |
|
Checks for cvstrac version |
| Cgi abuses |
Cvstrac database plaintext password storage |
|
Checks for cvstrac version |
| Cgi abuses |
Cvstrac filediff vulnerability |
Cve-2004-1456 |
Checks for cvstrac version |
| Cgi abuses |
Cvstrac history.c history_update function overflow |
|
Checks for cvstrac version |
| Cgi abuses |
Cvstrac invalid ticket dos |
|
Checks for cvstrac version |
| Cgi abuses |
Cvstrac malformed uri infinite loop dos |
|
Checks for cvstrac version |
| Cgi abuses |
Cvstrac ticket title arbitrary command execution |
|
Checks for cvstrac version |
| Cgi abuses |
Cvstrac timeline.c timeline_page function overflow |
|
Checks for cvstrac version |
| Cgi abuses |
Cvsweb 1.80 gives a shell to cvs committers |
Cve-2000-0670 |
Checks if cvsweb is present and gets its version |
| Cgi abuses |
Cvsweb detection |
|
Determines whether cvsweb.cgi is installed on the remote host |
| Cgi abuses |
Cwmail.exe vulnerability |
Cve-2002-0273 |
Checks for the cwmail.exe file |
| Cgi abuses |
Cacti < 0.8.6e multiple vulnerabilities |
Cve-2005-1524, cve-2005-1525, cve-2005-1526 |
Checks for multiple vulnerabilities in cacti < 0.8.6e |
| Cgi abuses |
Cacti < 0.8.6f multiple vulnerabilities |
Cve-2005-2148, cve-2005-2149 |
Checks for multiple vulnerabilities in cacti < 0.8.6f |
| Cgi abuses |
Cactushop xss and sql injection flaws |
Cve-2004-1881, cve-2004-1882 |
Checks cactushop flaws |
| Cgi abuses |
Cafe wordpress sql injection |
|
Checks for the presence of cafe wordpress |
| Cgi abuses |
Calendar express multiple flaws |
|
Checks calendar express xss and sql flaws |
| Cgi abuses |
Calendarix sql injection vulnerability |
Cve-2005-1865 |
Checks for multiple vulnerabilities in calendarix |
| Cgi abuses |
Calendarix id parameter sql injection vulnerabilities |
|
Checks for id parameter sql injection in calendarix |
| Cgi abuses |
Campas |
Cve-1999-0146 |
Checks for the presence of /cgi-bin/campas |
| Cgi abuses |
Carello detection |
|
Checks for the presence of carello.dll |
| Cgi abuses |
Cerberus helpdesk gui agent < 2.7.1 multiple vulnerabilities |
Cve-2005-4427 |
Checks for multiple vulnerabilities in cerberus helpdesk gui agent < 2.7.1 |
| Cgi abuses |
Cerberus support center multiple vulnerabilities |
Cve-2005-4427, cve-2005-4428 |
Checks for multiple vulnerabilities in cerberus support center |
| Cgi abuses |
Cgimail.exe vulnerability |
Cve-2000-0726 |
Checks for the cgimail.exe file |
| Cgi abuses |
Checks for listrec.pl |
Cve-2001-0997 |
Checks for the listrec.pl cgi |
| Cgi abuses |
Cherrypy staticfilter directory traversal vulnerability |
Cve-2006-0847 |
Checks for staticfilter directory traversal vulnerability in cherrypy |
| Cgi abuses |
Chipmonk cmscore sql injection |
Cve-2005-0368 |
Checks if chipmonk cmscore is vulnerable to a sql injection attack |
| Cgi abuses |
Chipmonk forum sql injection |
|
Checks if chipmonk forum is vulnerable to a sql injection attack |
| Cgi abuses |
Chora remote code execution vulnerability |
|
Checks for remote code execution vulnerability in chora |
| Cgi abuses |
Citrusdb remote authentication bypass vulnerability |
|
Determines the presence of citrusdb |
| Cgi abuses |
Claroline < 1.5.4 / 1.6.0 multiple input validation vulnerabilities |
Cve-2005-1374, cve-2005-1375, cve-2005-1376, cve-2005-1377 |
Checks for multiple input validation vulnerabilities in claroline < 1.5.4 / 1.6.0 |
| Cgi abuses |
Claroline multiple vulnerabilities (2) |
Cve-2006-1594, cve-2006-1595, cve-2006-1596 |
Tries to read /etc/passwd using claroline |
| Cgi abuses |
Claroline multiple vulnerabilities (3) |
Cve-2006-2284 |
Tries to read a local file using claroline |
| Cgi abuses |
Claroline includepath parameter remote file include vulnerability |
|
Tries to read a local file using claroline |
| Cgi abuses |
Clever copy connect.inc information disclosure vulnerability |
Cve-2006-1718 |
Reads clever copy's admin/connect.inc file |
| Cgi abuses |
Cobalt raq2 cgiwrap |
Cve-1999-1530, cve-2000-0431 |
Checks for the presence of /cgi-bin/cgiwrap |
| Cgi abuses |
Cobalt siteusermod cgi |
Cve-2000-0117 |
Checks for the presence of /.cobalt/siteusermod/siteusermod.cgi |
| Cgi abuses |
Codegrrl applications remote file inclusion vulnerabilities |
Cve-2005-3571 |
Checks for remote file inclusion vulnerabilities in codegrrl applications |
| Cgi abuses |
Codethatshoppingcart input validation vulnerabilities |
Cve-2005-1593, cve-2005-1594, cve-2005-1595 |
Checks for an sql injection in codethatshoppingcart |
| Cgi abuses |
Cognos powerplay we vulnerability |
|
Checks for the ppdscgi.exe cgi |
| Cgi abuses |
Cold fusion administration page overflow |
Cve-2000-0538 |
Checks for the presence of /cfide/administrator/index.cfm |
| Cgi abuses |
Coldfusion debug mode |
|
Get coldfusion debug information |
| Cgi abuses |
Coldfusion path disclosure |
Cve-2002-0576 |
Checks for a coldfusion vulnerability |
| Cgi abuses |
Coldfusion vulnerability |
Cve-1999-0455, cve-1999-0477 |
Checks for a coldfusion vulnerability |
| Cgi abuses |
Comersus backoffice administrator authentication bypass vulnerability |
|
Checks for administrator authentication bypass vulnerability in comersus backoffice |
| Cgi abuses |
Comersus backoffice lite administrative bypass |
|
Checks for the presence of a backoffice lite administrative bypass |
| Cgi abuses |
Comersus cart customer database disclosure vulnerability |
|
Checks for customer database vulnerability in comersus cart |
| Cgi abuses |
Comersus cart multiple vulnerabilities |
Cve-2005-2190, cve-2005-2191 |
Checks for multiple vulnerabilities in comersus cart |
| Cgi abuses |
Comersus login sql injection |
Cve-2004-0681, cve-2004-0682 |
Checks for comersus |
| Cgi abuses |
Commerce server 2002 authentication bypass vulnerability |
Cve-2006-1257 |
Checks version of commerce server 2002 |
| Cgi abuses |
Community link pro webeditor login.cgi remote command execution |
|
Checks for community link pro webeditor login.cgi remote execution flaw |
| Cgi abuses |
Contenido cfg parameter remote file include vulnerability |
Cve-2005-4132 |
Checks for cfg parameter remote file include vulnerability in contenido |
| Cgi abuses |
Coolforum sql injection flaw |
|
Checks for the presence of coolforum |
| Cgi abuses |
Coolforum xss and sql injection vulnerabilities |
Cve-2005-0857, cve-2005-0858 |
Checks for cross-site scripting and sql injection vulnerabilities in coolforum |
| Cgi abuses |
Coppermine gallery detection |
|
Checks for the presence of coppermine gallery |
| Cgi abuses |
Coppermine gallery remote command execution |
|
Checks for the presence of db_input.php |
| Cgi abuses |
Coppermine gallery sql injection |
|
Checks for the presence of db_input.php |
| Cgi abuses |
Coppermine gallery voting restriction failure |
|
Checks for the presence of db_input.php |
| Cgi abuses |
Coppermine photo gallery < 1.3.2 multiple vulnerabilities |
Cve-2005-1225, cve-2005-1226 |
Checks for version of coppermine photo gallery |
| Cgi abuses |
Coppermine photo gallery f parameter remote file include vulnerability |
Cve-2006-0873 |
Checks for f parameter remote file include vulnerability in coppermine photo gallery |
| Cgi abuses |
Coppermine photo gallery file parameter local file include vulnerability |
Cve-2006-1909 |
Tries to read a local file using coppermine photo gallery |
| Cgi abuses |
Count.cgi |
Cve-1999-0021 |
Checks count.cgi version |
| Cgi abuses |
Credit card data disclosure in citrusdb |
Can-2005-0229 |
Checks for the presence of io directory of citrusdb |
| Cgi abuses |
Cross-referencing linux (lxr) file reading |
|
Checks for the presence of /cgi-bin/source |
| Cgi abuses |
Crystal report virtual directory traversal |
Cve-2004-0204 |
Crystal report virtual directory traversal |
| Cgi abuses |
Cubecart 2.0.6 and earlier multiple sql injection vulnerabilities |
Cve-2005-1033 |
Checks for multiple sql injection vulnerabilities in cubecart 2.0.6 and earlier |
| Cgi abuses |
Cubecart < 3.0.12 multiple vulnerabilities |
|
Checks for a xss flaw in cubecart |
| Cgi abuses |
Cubecart detection |
|
Checks for the presence of cubecart |
| Cgi abuses |
Cubecart fckeditor arbitrary file upload vulnerability |
Cve-2006-0922 |
Tries to use cubecart to upload a file with php code |
| Cgi abuses |
Cubecart sql injection |
Cve-2004-1580 |
Sql injection in cubecart |
| Cgi abuses |
Cutenews <= 1.3.6 multiple vulnerabilities |
Cve-2005-0645 |
Checks for multiple vulnerabilities in cutenews <= 1.3.6 |
| Cgi abuses |
Cutenews client-ip header code injection vulnerability |
Cve-2005-3010 |
Checks for client-ip header code injection vulnerability in cutenews |
| Cgi abuses |
Cutenews debug info disclosure |
|
Checks for the presence of cutenews |
| Cgi abuses |
Cutenews detection |
|
Checks for presence of cutenews |
| Cgi abuses |
Cutenews archive parameter information disclosure vulnerability |
Cve-2006-1339, cve-2006-1340 |
Tries to read a file via archive parameter of cutenews |
| Cgi abuses |
Cutenews code injection |
Cve-2003-1240 |
Checks for the presence of search.php |
| Cgi abuses |
Cutenews directory traversal flaw |
Cve-2005-3507 |
Checks for cutenews dir traversal |
| Cgi abuses |
Cyberstrong eshop sql injection vulnerabilities |
Cve-2003-0509 |
Checks for an sql injection in cyberstrong eshop v4.2 |
| Cgi abuses |
Db4web tcp relay |
|
Db4web debug page allow bounce scan |
| Cgi abuses |
Db4web directory traversal |
|
Read any file through db4web |
| Cgi abuses |
Dbman cgi server information leakage |
Cve-2000-0381 |
Checks if webplus reads local files |
| Cgi abuses |
Dcp-portal multiple sql injection vulnerabilities |
Cve-2005-0454, cve-2005-3365, cve-2005-4227 |
Determines the presence of dcp-portal |
| Cgi abuses |
Dcp-portal path disclosure |
Cve-2002-0282 |
Determine if dcp-portal displays its physical path |
| Cgi abuses |
Duportal/duportal pro multiple sql injection vulnerabilities |
Cve-2005-1236 |
Checks for sql injection vulnerability in duportal |
| Cgi abuses |
Duamazon pro multiple sql injection vulnerabilities |
Cve-2005-2046 |
Checks for multiple sql injection vulnerabilities in duamazon pro |
| Cgi abuses |
Duclassmate multiple sql injection vulnerabilities |
Cve-2005-2049 |
Checks for multiple sql injection vulnerabilities in duclassmate |
| Cgi abuses |
Duforum multiple sql injection vulnerabilities |
Cve-2005-2048 |
Checks for multiple sql injection vulnerabilities in duforum |
| Cgi abuses |
Dupaypal pro multiple sql injection vulnerabilities |
Cve-2005-2047 |
Checks for multiple sql injection vulnerabilities in dupaypal pro |
| Cgi abuses |
Duportal pro multiple sql injection vulnerabilities |
Cve-2005-2045 |
Checks for multiple sql injection vulnerabilities in duportal pro |
| Cgi abuses |
Duware itype parameter sql injection vulnerability |
Cve-2005-3976 |
Checks for itype parameter sql injection vulnerability in duware |
| Cgi abuses |
Duware multiple vulnerabilities |
Cve-2004-2198, cve-2004-2199, cve-2004-2200, cve-2004-2201, cve-2004-2202 |
Determines if the remote asp scripts are vulnerable to sql injection |
| Cgi abuses |
Deluxebb multiple sql injection flaws |
Cve-2005-2989 |
Checks deluxebb version |
| Cgi abuses |
Desknow mail and collaboration server directory traversal vulnerabilities |
Can-2005-0332 |
Checks for the presence of an old version of desknow |
| Cgi abuses |
Detects ldu version |
|
Ldu detection |
| Cgi abuses |
Detects xaraya version |
|
Xaraya detection |
| Cgi abuses |
Digital scribe login.php sql injection flaw |
Cve-2005-2987 |
Checks for sql injection flaw in digital scribe |
| Cgi abuses |
Directory manager's edit_image.php |
Cve-2001-1020 |
Detects edit_image.php |
| Cgi abuses |
Directory listing through sambar's search.dll |
Cve-2000-0835 |
Checks the presence of search.dll |
| Cgi abuses |
Docebo globals variable overwrite vulnerability |
Cve-2006-2576, cve-2006-2577 |
Checks for file inclusions errors in multiple docebo applications |
| Cgi abuses |
Dokeos < 1.6.4 / 2.0.3 remote file include vulnerabilities |
|
Tries to read /etc/passwd using dokeos |
| Cgi abuses |
Dokuwiki spellcheck arbitrary code execution vulnerability |
Cve-2006-2878 |
Executes arbitrary php code via docuwiki spellcheck |
| Cgi abuses |
Dragonfly cms currentlang parameter local file include vulnerability |
Cve-2006-0644 |
Checks for currentlang parameter local file include vulnerability in dragonfly cms |
| Cgi abuses |
Dream4 koobi cms index.php sql injection vulnerability |
Cve-2005-1373 |
Checks for an sql injection in the koobi cms |
| Cgi abuses |
Drupal arbitrary php code execution vulnerability |
Cve-2005-2106 |
Checks version of drupal |
| Cgi abuses |
Drupal detection |
|
Detects drupal |
| Cgi abuses |
Drupal privilege escalation vulnerability |
Cve-2005-1871 |
Checks version of drupal |
| Cgi abuses |
Drupal xml-rpc for php remote code injection vulnerability |
Cve-2005-1921 |
Checks for xml-rpc for php remote code injection vulnerability in drupal |
| Cgi abuses |
Dumpenv |
Cve-1999-1178 |
Checks for the presence of /cgi-bin/dumpenv |
| Cgi abuses |
Dune web server overflow |
|
Checks for dune overflow |
| Cgi abuses |
Dwarf http server < 1.3.3 multiple vulnerabilities |
Cve-2006-0819, cve-2006-0820 |
Checks version of dwarf http server |
| Cgi abuses |
E-shopping cart arbitrary command execution (webdiscount) |
Can-2001-1014 |
E-shopping cart arbitrary command execution (webdiscount) |
| Cgi abuses |
E-theni code injection |
Cve-2003-1256 |
Checks for the presence of aff_list_langue.php |
| Cgi abuses |
Egroupware detection |
|
Detects the presence of egroupware |
| Cgi abuses |
Egroupware multiple vulnerabilitie |
Cve-2005-1129, cve-2005-1202, cve-2005-1203 |
Checks for the version of egroupware |
| Cgi abuses |
Elog < 2.6.1 multiple vulnerabilities |
Cve-2006-0347, cve-2006-0348 |
Checks for multiple vulnerabilities in elog < 2.6.1 |
| Cgi abuses |
Elog web logbook multiple remote vulnerabilities |
Cve-2005-0439, cve-2005-0440 |
Determines the presence of elog web logbook |
| Cgi abuses |
Ezshopper 3.0 |
Cve-2000-0187 |
Checks for the presence of ezshopper's cgis |
| Cgi abuses |
Ezsite forum discloses passwords to remote users |
|
Checks for ezsiteforum.mdb password database |
| Cgi abuses |
Easy file sharing web server acl bypass |
Cve-2004-1743 |
Checks /disk_c |
| Cgi abuses |
Easy message board command execution |
Can-2005-1549, can-2005-1550 |
Checks for easy message board |
| Cgi abuses |
Easydynamicpages code injection |
|
Checks for the presence of easydynamicpages |
| Cgi abuses |
Easyphpcalendar serverpath remote file include vulnerabilities |
Cve-2005-2155 |
Checks for serverpath remote file include vulnerabilities in easyphpcalendar |
| Cgi abuses |
Easyweb filemanager directory traversal |
Cve-2004-2047 |
Determines if easyweb filemanager is present |
| Cgi abuses |
Ecartis username spoofing |
Cve-2003-0162 |
Checks for the presence of lsg2.cgi |
| Cgi abuses |
Edgewall software trac sql injection flaw |
Cve-2005-3980 |
Checks for sql injection flaw in trac |
| Cgi abuses |
Edimax ap hidden password check |
|
Edimax hidden password check |
| Cgi abuses |
Emulive server4 authentication bypass |
Cve-2004-1695, cve-2004-1696 |
Requests the admin page of the remote emulive server4 |
| Cgi abuses |
Emumail webmail multiple vulnerabilities |
Cve-2004-2334, cve-2004-2385 |
Version test for emumail |
| Cgi abuses |
Episodex guestbook unauthorized access and html injection vulnerability |
Cve-2005-1684 |
Checks for unathentication access to admin.asp |
| Cgi abuses |
Exbb netsted bbcode remote script injection |
|
Checks exbb's version |
| Cgi abuses |
Excite for webservers |
Cve-1999-0279 |
Checks for the presence of /cgi-bin/ews |
| Cgi abuses |
Exhibit engine list.php sql injection vulnerabilities |
Cve-2005-1875 |
Checks for sql injection vulnerability in exhibit engine's list.php |
| Cgi abuses |
Exponent cms < 0.96.4 multiple vulnerabilities |
Cve-2005-3762, cve-2005-3763, cve-2005-3764, cve-2005-3765, cve-2005-3766, cve-2005-3767 |
Checks for multiple vulnerabilities in exponent cms < 0.96.4 |
| Cgi abuses |
Exponent cms multiple cross-site scripting vulnerabilities |
Cve-2005-0309 |
Checks for the version of exponent |
| Cgi abuses |
Extent rbs isp |
Cve-2000-1036 |
Checks for the presence of extent rbs isp 2.5 |
| Cgi abuses |
F-secure policy manager path disclosure |
Cve-2004-1223 |
Checks for /fsms/fsmsh.dll |
| Cgi abuses |
Faqmanager arbitrary file reading vulnerability |
Cve-2002-2033 |
Tests for faqmanager arbitrary file reading vulnerability |
| Cgi abuses |
Fckeditor arbitrary file upload vulnerability |
Cve-2006-2529 |
Tries to use upload a file with php code using fckeditor |
| Cgi abuses |
Fckeditor for php-nuke arbitrary file upload vulnerability |
Cve-2005-0613 |
Detects arbitrary file upload vulnerability in fckeditor for php-nuke |
| Cgi abuses |
Fudforum < 2.7.1 avatar upload vulnerability |
Cve-2005-2781 |
Checks for avatar upload vulnerability in fudforum < 2.7.1 |
| Cgi abuses |
Faxsurvey |
Cve-1999-0262 |
Checks if faxsurvey is vulnerable |
| Cgi abuses |
File disclosure in owl's workshop |
Can-2004-0302, can-2004-0303 |
Detect owls file disclosure |
| Cgi abuses |
File disclosure in php manpage |
|
Detect php manpage file disclosure |
| Cgi abuses |
File inclusion vulnerability in jaws |
Cve-2005-2179 |
Detect jaws file inclusion vulnerability |
| Cgi abuses |
File inclusion vulnerability in pivot |
|
Detect pivot file inclusion vulnerability |
| Cgi abuses |
Finger cgi |
|
Checks for the presence of /cgi-bin/finger |
| Cgi abuses |
Fingerprint web server with favicon.ico |
|
Attempt to fingerprint web server with favicon.ico |
| Cgi abuses |
Fishcart sql injections |
Can-2005-1486, can-2005-1487 |
Checks for the presence of an sql injection in upstnt.asp |
| Cgi abuses |
Flatnuke < 2.5.6 multiple vulnerabilities |
Cve-2005-2539, cve-2005-2540 |
Checks for multiple vulnerabilities in flatnuke < 2.5.6 |
| Cgi abuses |
Flatnuke form submission input validation vulnerability |
Cve-2005-0267, cve-2005-0268 |
Determines if flatnuke is installed |
| Cgi abuses |
Flatnuke id parameter directory traversal vulnerability |
Cve-2005-2813, cve-2005-4208, cve-2005-4448 |
Checks for id parameter directory traversal vulnerability in flatnuke |
| Cgi abuses |
Flexcast server terminal authentication vulnerability |
Cve-2005-1897 |
Checks for terminal authentication vulnerability in flexcast server |
| Cgi abuses |
Flyspray adodbpath parameter remote file include vulnerability |
Cve-2006-0714 |
Checks for adodbpath parameter remote file include vulnerability in flyspray |
| Cgi abuses |
Formhandler.cgi |
Cve-1999-1051 |
Attempts to read /etc/passwd |
| Cgi abuses |
Forum51/board51/news51 users disclosure |
|
Checks for the presence of user.idx |
| Cgi abuses |
Free articles directory remote file inclusion vulnerability |
Cve-2006-1350 |
Checks for file includes in free articles directory |
| Cgi abuses |
Ftplocate fsite parameter command execution vulnerability |
Cve-2005-2420 |
Checks for fsite parameter command execution vulnerability in ftplocate |
| Cgi abuses |
Fusion news x-forwarded-for code injection vulnerability |
|
Checks for x-forwarded-for code injection vulnerability in fusion news |
| Cgi abuses |
Fusion sbx password bypass and command execution |
|
Checks for the presence of a fusion sbx password bypass |
| Cgi abuses |
Gforge information disclosure |
Cve-2005-0299 |
Checks for a flaw in gforge |
| Cgi abuses |
Gnu mailman multiple unspecified remote vulnerabilities |
|
Gnu mailman unspecified vulnerabilities |
| Cgi abuses |
Gnump3d < 2.9.6 multiple vulnerabilities |
Cve-2005-3123, cve-2005-3424, cve-2005-3425 |
Checks for multiple vulnerabilities in gnump3d < 2.9.6 |
| Cgi abuses |
Gosa code injection |
|
Checks for the presence of remotehtmlview.php |
| Cgi abuses |
Gtcatalog code injection |
|
Checks for the presence of index.php |
| Cgi abuses |
Gtcatalog password disclosure |
|
Checks for the presence of password.inc |
| Cgi abuses |
Gallery < 2.0.3 multiple vulnerabilities |
Cve-2006-1127 |
Checks for ip spoofing in gallery |
| Cgi abuses |
Gallery install log information disclosure vulnerability |
Cve-2005-4021 |
Checks for gallery install log |
| Cgi abuses |
Gallery multiple vulnerabilities |
|
Checks for the presence of login.php |
| Cgi abuses |
Gallery postnuke integration access validation vulnerability |
Cve-2005-2596 |
Checks for postnuke integration access validation vulnerability in gallery |
| Cgi abuses |
Gallery script execution |
Cve-2004-1466 |
Checks for the version of gallery |
| Cgi abuses |
Gallery unspecified html injection vulnerability |
Cve-2004-1106 |
Checks for the version of gallery |
| Cgi abuses |
Gallery zipcart file retrieval vulnerability |
Cve-2005-4023 |
Tries to retrieve a file using gallery's zipcart module |
| Cgi abuses |
Gallery g2_itemid parameter directory traversal vulnerability |
|
Checks for g2_itemid parameter directory traversal vulnerability in gallery |
| Cgi abuses |
Gallery steporder parameter local file include vulnerabilities |
Cve-2006-1219 |
Tries to read a file using gallery steporder parameter |
| Cgi abuses |
Geeklog sql vulns |
Cve-2002-0962, cve-2002-0096, cve-2002-0097 |
Sends a rotten cookie to the remote host |
| Cgi abuses |
Geeklog < 1.3.11sr4 / 1.4.0sr1 multiple vulnerabilities |
Cve-2006-0823, cve-2006-0824 |
Checks for multiple vulnerabilities in geeklog < 1.3.11sr4 / 1.4.0sr1 |
| Cgi abuses |
Geeklog admin authentication sql injection vulnerability |
Cve-2006-2700 |
Tries to bypass administrative authentication in geeklog |
| Cgi abuses |
Geeklog fckeditor arbitrary file upload vulnerability |
Cve-2006-3362 |
Tries to upload a file with php code using geeklog's fckeditor |
| Cgi abuses |
Geeklog user comment retrieval sql injection vulnerability |
Cve-2005-2152 |
Checks for user comment retrieval sql injection vulnerability in geeklog |
| Cgi abuses |
Geeklog _conf[path] parameter remote file include vulnerability |
|
Tries to read a local file using geeklog |
| Cgi abuses |
Geeklog session cookie authentication bypass vulnerability |
Cve-2006-1069 |
Tries to bypass authentication in geeklog |
| Cgi abuses |
Geronimo console default credentials |
|
Checks for default credentials in geronimo console |
| Cgi abuses |
Google search appliance proxystylesheet parameter multiple vulnerabilities |
Cve-2005-3754, cve-2005-3755, cve-2005-3756, cve-2005-3757, cve-2005-3758 |
Checks for proxystylesheet parameter multiple vulnerabilities in google search appliance |
| Cgi abuses |
Goscript command execution |
|
Goscript command execution detection |
| Cgi abuses |
Grandstream budgetone default password |
|
Checks for the presence of a grandstream budgetone default password |
| Cgi abuses |
Gravity board x <= 1.1 multiple vulnerabilities |
Cve-2005-2562, cve-2005-2563, cve-2005-2564, cve-2005-2565 |
Checks for multiple vulnerabilities in gravity board x <= 1.1 |
| Cgi abuses |
Groupwise web interface 'help' hole |
Cve-1999-1005, can-1999-1006 |
Groupwise web interface 'help' hole |
| Cgi abuses |
Groupwise web interface 'htmlver' hole |
Can-2002-0341 |
Groupwise web interface 'htmlver' hole |
| Cgi abuses |
Guestbook script include_files parameter remote file include vulnerability |
Cve-2006-2158 |
Tries to read /etc/passwd using guestbook script |
| Cgi abuses |
Guppy <= 4.5.9 multiple vulnerabilities |
Cve-2005-3926, cve-2005-3927 |
Checks for multiple vulnerabilities in guppy <= 4.5.9 |
| Cgi abuses |
Guppy pg parameter vulnerability |
Cve-2005-2853 |
Checks for pg parameter flaw in guppy |
| Cgi abuses |
Guppy request header injection vulnerabilities |
Cve-2005-2853 |
Checks for request header injection vulnerabilities in guppy |
| Cgi abuses |
Hfs+ 'data fork' file access |
|
Downloads the source of a remote script |
| Cgi abuses |
Hp openview network node manager multiple remote command execution vulnerabilities |
Cve-2005-2773 |
Checks for multiple remote command execution vulnerabilities in hp openview network node manager |
| Cgi abuses |
Hp systems insight manager namazu lang directory traversal vulnerability |
Cve-2006-0656 |
Checks for namazu lang parameter directory traversal vulnerability in hp systems insight manager |
| Cgi abuses |
Hp systems management homepage namazu lang directory traversal vulnerability |
Cve-2006-1023 |
Checks for namazu lang parameter directory traversal vulnerability in hp systems management homepage |
| Cgi abuses |
Hsweb document path |
Cve-2001-0200 |
Retrieve the real path using /cgi |
| Cgi abuses |
Handler |
Cve-1999-0148 |
Checks for the presence of /cgi-bin/handler |
| Cgi abuses |
Happymall command execution |
Cve-2003-0243 |
Checks for happymall |
| Cgi abuses |
Hastymail html attachement script execution |
|
Checks for version of hastymail |
| Cgi abuses |
Help center live multiple vulnerabilities |
Cve-2004-2602, cve-2004-2603 |
Determines if help center live can include third-party files |
| Cgi abuses |
Help center live multiple vulnerabilities (2) |
Cve-2005-1672, cve-2005-1673, cve-2005-1674 |
Checks for multiple vulnerabilities (2) in help center live |
| Cgi abuses |
Help center live module.php local file include flaw |
Cve-2005-3639 |
Checks hcl local file include flaw |
| Cgi abuses |
Help center live osticket module multiple sql injection vulnerabilities |
Cve-2006-2039 |
Tries to bypass authentication with a sql injection attack |
| Cgi abuses |
Home free search.cgi directory traversal |
Cve-2000-0054 |
Attempts get /cgi-bin/search.cgi?\\..\\..\\file.txt |
| Cgi abuses |
Horde default admin password vulnerability |
Cve-2005-3344 |
Checks for default admin password vulnerability in horde |
| Cgi abuses |
Horde help viewer code execution vulnerability |
Cve-2006-1491 |
Tries to run a command using horde's help viewer |
| Cgi abuses |
Horde and imp test disclosure |
|
Checks if test.php is available in horde or imp |
| Cgi abuses |
Horde url parameter file disclosure vulnerability |
Cve-2006-1260 |
Tries to read arbitrary files using horde |
| Cgi abuses |
Hosting controller < 6.1 hotfix 2.1 multiple vulnerabilities |
Cve-2005-1784, cve-2005-1788, cve-2005-2077 |
Checks for multiple vulnerabilities in hosting controller < 6.1 hotfix 2.1 |
| Cgi abuses |
Hosting controller < 6.1 hotfix 2.2 multiple vulnerabilities |
|
Checks for multiple vulnerabilities in hosting controller < 6.1 hotfix 2.2 |
| Cgi abuses |
Hosting controller <= 6.1 hotfix 2.2 multiple vulnerabilities |
|
Checks for multiple vulnerabilities in hosting controller <= 6.1 hotfix 2.2 |
| Cgi abuses |
Hosting controller <= 6.1 hotfix 2.3 information disclosure vulnerabilities |
Cve-2005-3038 |
Checks for information disclosure vulnerability in hosting controller <= 6.1 hotfix 2.3 |
| Cgi abuses |
Hosting controller <= 6.1 hotfix 3.1 privilege escalation vulnerability |
Cve-2006-3147 |
Checks version of hosting controller |
| Cgi abuses |
Hosting controller detection |
|
Detects hosting controller |
| Cgi abuses |
Hosting controller multiple information disclosure vulnerability |
|
Downloads hcdiskquoteservice.csv |
| Cgi abuses |
Hosting controller addsubsite.asp security bypass |
Cve-2005-1654 |
Checks for addsubsite.asp security bypass in hosting controller |
| Cgi abuses |
Hosting controller vulnerable asp pages |
Cve-2002-0466 |
Checks for the vulnerable instances of hosting controller |
| Cgi abuses |
Hotnews code injection |
|
Checks for the presence of hotnews |
| Cgi abuses |
Hotopentickets privilege escalation |
|
Checks for hotopenticket |
| Cgi abuses |
Htmlscript |
Cve-1999-0264 |
Checks for the presence of /cgi-bin/htmlscript |
| Cgi abuses |
Ibm websphere application server source disclosure |
Cve-2005-1112 |
Attempts to read the source of a jsp page |
| Cgi abuses |
Ibm websphere commerce remote information disclosure vulnerability |
|
Checks for remote information disclosure vulnerability in ibm websphere application server |
| Cgi abuses |
Ibm websphere default user information leak |
|
Detects websphere default user information leak |
| Cgi abuses |
Ibm-http-server view code |
|
Ibm-http-server view code |
| Cgi abuses |
Ibproarcade index.php sql injection |
Cve-2004-1430 |
Checks for the presence of an sql injection in index.php |
| Cgi abuses |
Icecast filesystem disclosure |
Cve-2002-1982 |
Determines if the error code is the same when requesting inexisting and existing dirs |
| Cgi abuses |
Iis asp.net application trace enabled |
|
Checks for asp.net application tracing |
| Cgi abuses |
Iis global.asa retrieval |
|
Tries to retrieve the global.asa file |
| Cgi abuses |
Iis phonebook |
Cve-2000-1089 |
Determines whether phonebook server is installed |
| Cgi abuses |
Iis possible dos using exair's advsearch |
Cve-1999-0449 |
Determines the presence of an exair asp |
| Cgi abuses |
Iis possible dos using exair's query |
Cve-1999-0449 |
Determines the presence of an exair asp |
| Cgi abuses |
Iis possible dos using exair's search |
Cve-1999-0449 |
Determines the presence of an exair asp |
| Cgi abuses |
Imp sql injection |
|
Checks imp version |
| Cgi abuses |
Imp session hijacking bug |
Cve-2001-0857 |
Checks imp version |
| Cgi abuses |
Inl ulog-php sql injection |
|
Checks for the presence of a sql injection vulnerability in ulog |
| Cgi abuses |
Ipcheck server monitor directory traversal vulnerability |
|
Checks for directory traversal vulnerability in ipcheck server monitor |
| Cgi abuses |
Ita forum multiple sql injection vulnerabilities |
|
Sql injection in ita forum |
| Cgi abuses |
Icewarp web mail multiple flaws |
Cve-2004-1669, cve-2004-1670, cve-2004-1671, cve-2004-1672, cve-2004-1673, cve-2004-1674 |
Check the version of icewarp webmail |
| Cgi abuses |
Icewarp web mail multiple flaws (2) |
|
Check the version of icewarp webmail |
| Cgi abuses |
Icewarp web mail multiple flaws (3) |
Cve-2005-0320 |
Check the version of icewarp webmail |
| Cgi abuses |
Icewarp web mail multiple flaws (4) |
Cve-2005-3131, cve-2005-3132, cve-2005-3133 |
Check the version of icewarp webmail |
| Cgi abuses |
Icewarp lang_settings remote file include vulnerabilities |
Cve-2006-0817, cve-2006-0818 |
Tries to read a local file using icewarp |
| Cgi abuses |
Icecast xsl parser multiple vulnerabilities |
Cve-2005-0837, cve-2005-0838 |
Checks for xsl parser vulnerabilities in icecast |
| Cgi abuses |
Ideal bb < 1.5.4b multiple vulnerabilities |
Cve-2006-2317, cve-2006-2318, cve-2006-2319, cve-2006-2320, cve-2006-2321 |
Checks version of ideal bb |
| Cgi abuses |
Idealbb multiple flaws |
Cve-2004-2207, cve-2004-2208, cve-2004-2209 |
Checks idealbb version |
| Cgi abuses |
Ikonboard sql injection vulnerabilties |
Cve-2004-1406 |
Checks for ikonboard.cgi |
| Cgi abuses |
Ikonboard arbitrary command execution |
|
Checks for ikonboard.cgi |
| Cgi abuses |
Ilohamail attachment upload vulnerability |
|
Checks for attachment upload vulnerability in ilohamail |
| Cgi abuses |
Ilohamail contacts deletion vulnerability |
|
Checks for contacts deletion vulnerability in ilohamail |
| Cgi abuses |
Ilohamail external programs vulnerabilities |
|
Checks for external programs vulnerabilities in ilohamail |
| Cgi abuses |
Ilohamail insecure install |
|
Checks for the presence of conf/conf.inc |
| Cgi abuses |
Ilohamail password disclosure vulnerability |
|
Checks for password disclosure vulnerability in ilohamail |
| Cgi abuses |
Ilohamail unspecified vulnerability |
Cve-2004-2500 |
Checks the version if ilohamail |
| Cgi abuses |
Ilohamail user parameter vulnerability |
|
Checks for user parameter vulnerability in ilohamail |
| Cgi abuses |
Imagefolio default password |
|
Logs in as admin/imagefolio |
| Cgi abuses |
Infinite mobile delivery webmail multiple vulnerabilities |
Cve-2005-0323, cve-2005-0324 |
Checks for the presence of infinite mobile delivery |
| Cgi abuses |
Inktomi search physical path disclosure |
Cve-2004-0050 |
Checks for a inktomi search vulnerability |
| Cgi abuses |
Instaboard sql injection |
|
Checks for sql insertion in instaboad |
| Cgi abuses |
Interscan viruswall remote configuration vulnerability |
Cve-2001-0432 |
Check if the remote interscan is vulnerable to remote reconfiguration. |
| Cgi abuses |
Interactive story directory traversal vulnerability |
Cve-2001-0804 |
Checks for the presence of /cgi-bin/story.pl |
| Cgi abuses |
Interchange < 5.0.2 / 5.2.1 multiple vulnerabilities |
|
Checks for multiple vulnerabilities in interchange < 5.0.2 / 5.2.1 |
| Cgi abuses |
Interspire articlelive multiple remote vulnerabilities |
Cve-2005-1482, cve-2005-1483 |
Checks for multiple vulnerabilities in interspire articlelive |
| Cgi abuses |
Invision community blog multiple input validation vulnerabilities |
Cve-2005-1945, cve-2005-1946 |
Checks for multiple input validation vulnerabilities in invision community blog |
| Cgi abuses |
Invision community blog sql injection |
Cve-2005-0217 |
Sql injection |
| Cgi abuses |
Invision gallery multiple input validation vulnerabilities |
Cve-2005-1948 |
Checks for multiple input validation vulnerabilities in invision gallery |
| Cgi abuses |
Invision gallery st parameter sql injection vulnerability |
Cve-2005-3395 |
Checks for st parameter sql injection vulnerability in invision gallery |
| Cgi abuses |
Invision power board 2.x.x < 04-25-06 multiple vulnerabilities |
Cve-2006-2059, cve-2006-2060, cve-2006-2061 |
Checks for ck parameter sql injection vulnerability in ipb |
| Cgi abuses |
Invision power board < 2.0.4 multiple vulnerabilities |
Cve-2005-1597, cve-2005-1598 |
Checks for multiple vulnerabilities in invision power board < 2.0.4 |
| Cgi abuses |
Invision power board arcade sql injection vulnerability |
Cve-2004-1536 |
Detect invision power board arcade sql injection |
| Cgi abuses |
Invision power board client_ip sql injection vulnerability |
|
Checks version of ipb |
| Cgi abuses |
Invision power board calendar sql injection vulnerability |
|
Detect invision power board calender sql injection |
| Cgi abuses |
Invision power board dragoran portal plugin site parameter sql injection vulnerability |
Cve-2006-0520 |
Checks for site parameter sql injection vulnerability in invision power board dragoran portal plugin |
| Cgi abuses |
Invision power board post sql injection vulnerability |
Cve-2004-1531 |
Detect invision power board post sql injection |
| Cgi abuses |
Invision power board privilege escalation vulnerability / sql injection |
Cve-2005-1816 |
Checks for privilege escalation vulnerability in invision power board |
| Cgi abuses |
Invision power board ssi.php sql injection vulnerability |
|
Detect invision power board ssi.php sql injection |
| Cgi abuses |
Invision power board st parameter sql injection vulnerability |
Cve-2005-1070 |
Checks for st parameter sql injection vulnerability in invision power board |
| Cgi abuses |
Invision powerboard code injection |
|
Checks for root_path include flaw in ipchat.php |
| Cgi abuses |
Ipswitch whatsup professional authentication bypass detection |
Cve-2006-2531 |
Checks for ipswitch whatsup professional authentication bypass |
| Cgi abuses |
Ipswitch whatsup professional login.asp sql injection vulnerability |
Cve-2005-1250 |
Checks for sql injection vulnerability in ipswitch whatsup professional's login.asp |
| Cgi abuses |
Ipswitch whatsup professional multiple vulnerabilities |
Cve-2006-2351, cve-2006-2352, cve-2006-2353, cve-2006-2354, cve-2006-2355, cve-2006-2356, cve-2006-2357 |
Checks for ipswitch whatsup professional information disclosure |
| Cgi abuses |
Jaws multiple input validation vulnerabilities |
Cve-2004-2443, cve-2004-2444, cve-2004-2445 |
Checks for a file reading flaw in jaws |
| Cgi abuses |
Jboss malformed http request remote information disclosure |
Cve-2005-2006, cve-2006-0656 |
Attempts to read security policy of a remote jboss server |
| Cgi abuses |
Jboss source disclosure |
|
Attempts to read the source of a jsp page |
| Cgi abuses |
Jbrowser multiple flaws |
|
Checks jbrowser |
| Cgi abuses |
Jgs-portal multiple xss and sql injection vulnerabilities |
|
Jgs-portal multiple xss and sql injection vulnerabilities |
| Cgi abuses |
Jrun directory traversal |
Cve-2001-1544 |
Attempts directory traversal attack |
| Cgi abuses |
Jrun's viewsource.jsp |
Cve-2000-0540 |
Determines the presence of the jrun flaw |
| Cgi abuses |
Jwalk server traversal |
|
Reads a file outside the web root |
| Cgi abuses |
Jakarta tomcat path disclosure |
Cve-2000-0759 |
Tests for tomcat path disclosure vulnerability |
| Cgi abuses |
Jammail jammail.pl remote arbitrary command execution vulnerability |
Cve-2005-1959 |
Determines the presence of jammail.pl remote command execution |
| Cgi abuses |
Jave source code disclosure |
|
Jave source code disclosure check |
| Cgi abuses |
Jinzora include_path variable file include vulnerabilities |
Cve-2005-2249 |
Checks for include_path variable file include vulnerabilities in jinzora |
| Cgi abuses |
Joomla! < 1.0.8 multiple vulnerabilities |
Cve-2006-1028, cve-2006-1030, cve-2006-1047, cve-2006-1048, cve-2006-1049 |
Checks for path disclosure issue in joomla! |
| Cgi abuses |
Joomla! detection |
|
Checks for presence of joomla! |
| Cgi abuses |
K-collect csv-db csv_db.cgi remote command execution vulnerability |
|
Checks for k-collect csv-db remote command execution flaw |
| Cgi abuses |
Kf web server /%00 bug |
|
Make a request like http://www.example.com/%00 |
| Cgi abuses |
Kw whois |
Cve-2000-0941 |
Checks for the presence of /cgi-bin/whois.cgi |
| Cgi abuses |
Kayako liveresponse multiple input validation vulnerabilities |
Cve-2005-2460, cve-2005-2461, cve-2005-2462, cve-2005-2463 |
Checks for multiple input validation vulnerabilities in kayako liveresponse |
| Cgi abuses |
Kebi academy directory traversal |
|
Kebi academy is vulnerable to an exploit which lets an attacker view any file that the cgi/httpd user has access to. |
| Cgi abuses |
Kietu code injection |
|
Checks for the presence of hit.php |
| Cgi abuses |
Korweblog remote directory listing vulnerability |
Cve-2004-1426, cve-2004-1427, cve-2004-1543 |
Checks the version of the remote korweblog |
| Cgi abuses |
Land down under <= 800 multiple vulnerabilities |
Cve-2005-2674, cve-2005-2675, cve-2005-2780 |
Checks for sql injection in ldu's index.php |
| Cgi abuses |
Land down under <= 801 multiple vulnerabilities |
Cve-2005-2788, cve-2005-2884 |
Checks for sql injection in ldu's list.php |
| Cgi abuses |
Land down under http referer sql injection vulnerability |
|
Checks for http referer sql injection vulnerability in land down under |
| Cgi abuses |
Leifwright's blog.cgi command execution |
Cve-2004-2347 |
Checks for command execution in leifwright's blog.cgi |
| Cgi abuses |
Lifetype articleid parameter sql injection vulnerability |
Cve-2006-2857 |
Tries to exploit sql injection issue in lifetype |
| Cgi abuses |
Lifetype date parameter sql injection vulnerability |
Cve-2006-3577 |
Tries to exploit sql injection issue in lifetype |
| Cgi abuses |
Limbo cms itemid arbitrary code execution vulnerability |
Cve-2006-1662 |
Injects arbitrary php code via itemid parameter in limbo cms |
| Cgi abuses |
Limbo cms multiple vulnerabilities |
Cve-2005-4317, cve-2005-4318, cve-2005-4319, cve-2005-4320 |
Checks for multiple vulnerabilities in limbo |
| Cgi abuses |
Limbo cms classes_dir parameter remote file include vulnerability |
Cve-2006-2142 |
Tries to read /etc/passwd using limbo cms |
| Cgi abuses |
Limbo catid parameter sql injection vulnerability |
|
Tries to affect db queries in limbo cms |
| Cgi abuses |
Linpha <= 1.0 multiple vulnerabilities |
Cve-2006-0713 |
Checks for multiple vulnerabilities in linpha <= 1.0 |
| Cgi abuses |
Listmanager < 8.9b multiple vulnerabilities |
Cve-2005-4143, cve-2005-4144, cve-2005-4146, cve-2005-4147, cve-2005-4148 |
Checks for multiple vulnerabilities in listmanager < 8.9b |
| Cgi abuses |
Listmanager administrative command injection vulnerability |
Cve-2005-4142 |
Checks for administrative command injection vulnerability in listmanager |
| Cgi abuses |
Listmanager error message information disclosure vulnerability |
Cve-2005-4148, cve-2005-4149 |
Checks for error message information disclosure vulnerability in listmanager |
| Cgi abuses |
Listserv < 14.3-2005a multiple vulnerabilities |
Cve-2005-1773 |
Checks for multiple vulnerabilities in listserv < 14.3-2005a |
| Cgi abuses |
Listserv < 14.5 multiple buffer overflow vulnerabilities |
Cve-2006-1044 |
Checks version number of listserv |
| Cgi abuses |
Litecommerce sql injection vulnerabilities |
Cve-2005-1032 |
Checks litecommerce |
| Cgi abuses |
Looking glass multiple vulnerabilities |
Cve-2005-2776, cve-2005-2777 |
Checks for multiple vulnerabilities in looking glass |
| Cgi abuses |
Lotus notes ?openserver information disclosure |
|
Lotus notes ?openserver information disclosure |
| Cgi abuses |
Loudblog < 0.42 multiple vulnerabilities |
Cve-2006-1113, cve-2006-1114 |
Tries to read loudblog's config file |
| Cgi abuses |
Loudblog backend_settings.php remote file include vulnerability |
Cve-2006-0565 |
Checks for remote file include vulnerability in loudblog's backend_settings.php |
| Cgi abuses |
Loudblog id parameter sql injection vulnerability |
|
Checks for id parameter sql injection flaw in loudblog |
| Cgi abuses |
Modx < 0.9.1a multiple vulnerabilities |
Cve-2006-1820, cve-2006-1821 |
Tries to exploit a xss flaw in modx |
| Cgi abuses |
Mpm guestbook file reading |
|
Determines mpm guestbook is installed |
| Cgi abuses |
Mrtg mrtg.cgi file disclosure |
Cve-2002-0232 |
Checks for mrtg.cgi |
| Cgi abuses |
Ms personal webserver ... |
Cve-1999-0386 |
......../file.txt |
| Cgi abuses |
Ms site server information leak |
Cve-2002-1769 |
Determine if the remote host is vulnerable to a disclosure vuln. |
| Cgi abuses |
Msql cgi overflow |
Cve-1999-0753 |
Overflows the remote cgi buffer |
| Cgi abuses |
Macos x finder reveals contents of apache web directories |
|
Checks for .ds_store |
| Cgi abuses |
Macos x finder reveals contents of apache web files |
Can-2001-1446 |
Macos x finder reveals contents of apache web files |
| Cgi abuses |
Macallan mail solution multiple http vulnerabilities |
|
Checks for macallan mail solution version |
| Cgi abuses |
Macromedia coldfusion mx path disclosure vulnerability |
|
Macromedia coldfusion mx path disclosure vulnerability |
| Cgi abuses |
Mailenable httpmail service authorization header dos vulnerability |
|
Checks for authorization header dos vulnerability in mailenable httpmail service |
| Cgi abuses |
Mailenable httpmail service content-length overflow vulnerability |
|
Checks for content-length overflow vulnerability in mailenable httpmail service |
| Cgi abuses |
Mailgust sql injection vulnerability |
Cve-2005-3063 |
Check if mailgust is vulnerable to sql injection. |
| Cgi abuses |
Mailmaxweb path disclosure |
|
Checks for mailmaxweb |
| Cgi abuses |
Mailwatch authenticate function sql injection vulnerability |
Cve-2005-3470 |
Checks for authentication function sql injection vulnerability in mailwatch |
| Cgi abuses |
Mailman detection |
|
Checks for the presence of mailman |
| Cgi abuses |
Mambo / joomla component / module mosconfig_absolute_path parameter remote file include vulnerability |
Cve-2006-3396, cve-2006-3530, cve-2006-3556, cve-2006-3748, cve-2006-3749, cve-2006-3750, cve-2006-3751, cve-2006-3773, cve-2006-3947, cve-2006-3949, cve-2006-3980, cve-2006-3995 |
Tries to read a local file using mambo / joomla components and modules |
| Cgi abuses |
Mambo code injection vulnerability |
|
Detect mambo code injection vuln |
| Cgi abuses |
Mambo global variables unauthorized access |
|
Checks for index.php malformed request vulnerability |
| Cgi abuses |
Mambo open source / joomla! globals variable remote file include vulnerability |
Cve-2005-3738 |
Tries to read a file using mambo open source / joomla! |
| Cgi abuses |
Mambo open source / mambo cms detection |
|
Checks for presence of mambo open source / mambo cms |
| Cgi abuses |
Mambo open source < 4.5.2.3 multiple vulnerabilities |
Cve-2005-2002 |
Checks for multiple vulnerabilities in mambo open source < 4.5.2.3 |
| Cgi abuses |
Mambo open source multiple vulnerabilities |
Cve-2006-0871, cve-2006-1794 |
Tries to change mos_user_template cookie in mambo open source |
| Cgi abuses |
Mambo open source tar.php remote file include vulnerability |
Cve-2005-0512 |
Detect tar.php remote file include vulnerability in mambo open source |
| Cgi abuses |
Mambo site server cookie validation |
Cve-2003-1245 |
Checks for the presence of mambo's flaw |
| Cgi abuses |
Mantis detection |
|
Checks for the presence of mantis |
| Cgi abuses |
Mantis file inclusion and sql injection flaws |
Cve-2005-3335 |
Checks for flaws in mantis < 0.19.3 |
| Cgi abuses |
Mantis multiple flaws |
Cve-2002-1110, cve-2002-1111, cve-2002-1112, cve-2002-1113, cve-2002-1114, cve-2002-1115 |
Checks for the version of mantis |
| Cgi abuses |
Mantis multiple flaws (2) |
Cve-2004-1730, cve-2004-1731, cve-2004-1734 |
Checks for the version of mantis |
| Cgi abuses |
Mantis multiple flaws (3) |
|
Checks for the version of mantis |
| Cgi abuses |
Mantis multiple flaws (4) |
Cve-2005-2556, cve-2005-2557, cve-2005-3090, cve-2005-3091 |
Checks for the version of mantis |
| Cgi abuses |
Master index directory traversal vulnerability |
Cve-2000-0924 |
Attempts get /cgi-bin/search/search.cgi?keys=*&prc=any&catigory=../../../../etc |
| Cgi abuses |
Maxwebportal <= 1.33 multiple vulnerabilities |
Cve-2005-1016, cve-2005-1017 |
Checks for multiple vulnerabilities in maxwebportal <= 1.33 |
| Cgi abuses |
Maxwebportal <= 1.35 multiple vulnerabilities |
Cve-2005-1561, cve-2005-1562 |
Checks for multiple vulnerabilities in maxwebportal <= 1.35 |
| Cgi abuses |
Maxwebportal memkey parameter sql injection vulnerability |
Cve-2005-1779 |
Checks for sql injection vulnerability in maxwebportal's password.asp |
| Cgi abuses |
Mcafee common management agent directory traversal vulnerability |
Cve-2006-3623 |
Checks version of common management agent |
| Cgi abuses |
Mediahouse statistic server buffer overflow |
Cve-1999-0931 |
Overflow of /ss? |
| Cgi abuses |
Mediawiki < 1.3.17 / 1.4.11 / 1.5.0 multiple vulnerabilities |
Cve-2005-3167 |
Checks for multiple vulnerabilities in mediawiki < 1.3.17 / 1.4.11 / 1.5.0 |
| Cgi abuses |
Mediawiki detection |
|
Detects mediawiki |
| Cgi abuses |
Mediawiki multiple remote vulnerabilities |
Cve-2004-1405, cve-2004-2185, cve-2004-2186, cve-2004-2187 |
Test for the version of medawiki |
| Cgi abuses |
Mediawiki multiple remote vulnerabilities (2) |
Cve-2005-4031 |
Attempts to execute phpinfo() remotely |
| Cgi abuses |
Mensajeitor tag board admin bypass |
|
Mensajeitor test |
| Cgi abuses |
Mercuryboard user-agent sql injection vulnerability |
Cve-2005-2028 |
Checks for user-agent remote sql injection vulnerability in mercuryboard |
| Cgi abuses |
Metacart e-shop productsbycategory.asp sql and xss injection vulnerabilities |
|
Metacart e-shop productsbycategory.asp xss and sql injection vulnerabilities |
| Cgi abuses |
Minivend piped command |
Cve-2000-0635 |
Checks for the presence of /cgi-bin/simple/view_page |
| Cgi abuses |
Minis remote file access |
Cve-2005-0293 |
Checks for a file reading flaw in minis |
| Cgi abuses |
Mnemo detection |
|
Checks for presence of mnemo |
| Cgi abuses |
Mnogosearch overflows |
Cve-2003-0436, cve-2003-0437 |
Checks for search.cgi |
| Cgi abuses |
Modernbill 4.3.0 and older multiple vulnerabilities |
Cve-2005-1053, cve-2005-1054 |
Checks for multiple vulnerabilities in modernbill 4.3.0 and older |
| Cgi abuses |
Monster top list remote file include |
Cve-2006-1781 |
Checks for file includes in sources/functions.php |
| Cgi abuses |
Moodle < 1.5.1 multiple vulnerabilities |
|
Checks for multiple vulnerabilities in moodle < 1.5.1 |
| Cgi abuses |
Moodle < 1.5.3 multiple sql injection vulnerabilities |
Cve-2005-3648 |
Checks for multiple sql vulnerabilities in moodle < 1.5.3 |
| Cgi abuses |
Moodle detection |
|
Detects moodle |
| Cgi abuses |
Moodle sql injection flaws |
Cve-2004-1424, cve-2004-1425, cve-2004-2232 |
Determines if moodle is older than 1.4.3 |
| Cgi abuses |
Movable type < 3.2 multiple vulnerabilities |
Cve-2005-3101, cve-2005-3102, cve-2005-3103, cve-2005-3104 |
Checks for multiple vulnerabilities in movable type < 3.2 |
| Cgi abuses |
Movable type config file |
|
Checks for the presence of /mt/mt.cfg |
| Cgi abuses |
Movable type initialization script found |
|
Checks for the existence of /mt/mt-load.cgi |
| Cgi abuses |
Multiple cross-site scripting vulnerabilities in phpbb2 plus <= 1.52 |
Cve-2005-1113 |
Checks for multiple cross-site scripting vulnerabilities in phpbb plus <= 1.52 |
| Cgi abuses |
Multiple dotnetnuke html injection vulnerabilities |
Cve-2005-0040 |
Checks version of dotnetnuke |
| Cgi abuses |
Multiple local file include vulnerabilities in phpmyadmin |
Cve-2005-0567 |
Detect multiple local file include vulnerabilities in phpmyadmin |
| Cgi abuses |
Multiple remote vulnerabilities in photopost php 5.0 rc3 and older |
Cve-2005-0774, cve-2005-0775, cve-2005-0776, cve-2005-0777, cve-2005-0778, cve-2005-1629 |
Checks for multiple remote vulnerabilities in photopost php 5.0 rc3 and older |
| Cgi abuses |
Multiple remote vulnerabilities in zorum <= 3.5 |
Cve-2005-0675, cve-2005-0676, cve-2005-0677, cve-2005-2651, cve-2005-4619, cve-2006-3332 |
Checks for multiple remote vulnerabilities in zorum <= 3.5 |
| Cgi abuses |
Multiple remote vulnerabilities in myevent |
Cve-2006-1890, cve-2006-1907, cve-2006-1908 |
Checks for file includes in myevent.php |
| Cgi abuses |
Multiple sql injection vulnerabilities in phpcoin <= 1.2.2 |
Cve-2005-1384 |
Checks for multiple sql injection vulnerabilities in phpcoin <= 1.2.2 |
| Cgi abuses |
Multiple vulnerabilities in active webcam webserver 5.5 and older |
Cve-2005-0730, cve-2005-0731, cve-2005-0732, cve-2005-0733, cve-2005-0734 |
Checks for multiple remote vulnerabilities in active webcam webserver 5.5 and older |
| Cgi abuses |
Multiple vulnerabilities in argosoft mail server pro <= 1.8.7.6 |
Cve-2005-1282, cve-2005-1284 |
Checks for multiple vulnerabilities in argosoft mail server pro <= 1.8.7.6 |
| Cgi abuses |
Multiple vulnerabilities in merak webmail / icewarp web mail |
Cve-2004-1719, cve-2004-1720, cve-2004-1721, cve-2004-1722 |
Checks for multiple vulnerabilities in merak webmail / icewarp web mail |
| Cgi abuses |
Multiple vulnerabilities in mercuryboard |
Can-2005-0306, can-2005-0307, can-2005-0414, can-2005-0460, can-2005-0462, can-2005-0662, can-2005-0663 |
Checks for the presence of an old version of mercuryboard |
| Cgi abuses |
Multiple vulnerabilities in phplist <= 2.6.3 |
|
Checks version of phplist |
| Cgi abuses |
Multiple vulnerabilities in postnuke 0.760 rc2 and older |
Cve-2005-0615, cve-2005-0616, cve-2005-0617 |
Detects multiple vulnerabilities in postnuke 0.760 rc2 and older |
| Cgi abuses |
Multiple vulnerabilities in postnuke <= 0.760 rc4a |
Cve-2005-1621, cve-2005-1697, cve-2005-1698, cve-2005-1699, cve-2005-1700 |
Detects multiple vulnerabilities in postnuke <= 0.760 rc4a |
| Cgi abuses |
Multiple vulnerabilities in postnuke <= 0.760 rc4b |
Cve-2005-2689, cve-2005-2690 |
Detects multiple vulnerabilities in postnuke <= 0.760 rc4b |
| Cgi abuses |
Multiple vulnerabilities in xampp |
Cve-2005-1077, cve-2005-1078, cve-2005-2043 |
Checks for the version of xampp |
| Cgi abuses |
Multiple vulnerabilities in pafiledb 3.1 and older |
Cve-2004-1219, cve-2004-1551, cve-2005-0326, cve-2005-0327, cve-2005-0723, cve-2005-0724 |
Checks for multiple vulnerabilities in pafiledb 3.1 and older |
| Cgi abuses |
Multiple vulnerabilities in pafiledb 3.1 and older (2) |
Cve-2004-1219, cve-2004-1551, cve-2005-0326, cve-2005-0327, cve-2005-0723, cve-2005-0724 |
Checks for multiple vulnerabilities in pafiledb 3.1 and older |
| Cgi abuses |
Multiple vulnerabilities in phpcoin 1.2.1b and older |
Cve-2005-0669, cve-2005-0670, cve-2005-0932, cve-2005-0933, cve-2005-0946, cve-2005-0947 |
Detects multiple vulnerabilities in phpcoin 1.2.1b and older |
| Cgi abuses |
Multiple vulnerabilities in yappa-ng < 2.3.2 |
Cve-2005-1311, cve-2005-1312 |
Checks for multiple vulnerabilities in yappa-ng < 2.3.2 |
| Cgi abuses |
Multiple phpshop vulnerabilities |
|
Detect phpshop sql injection |
| Cgi abuses |
Multiple vulnerabilities in clever copy |
Cve-2005-2324, cve-2005-2325, cve-2005-2326 |
Checks for xss in results.php |
| Cgi abuses |
Multiple vulnerabilities in openconnect webconnect < 6.5.1 |
Cve-2004-0465, cve-2004-0466 |
Checks for multiple vulnerabilities in openconnect webconnect < 6.5.1 |
| Cgi abuses |
Multiple vulnerabilities in php surveyor |
Cve-2005-2380, cve-2005-2381, cve-2005-2398, cve-2005-2399 |
Checks for sql injection in admin.php |
| Cgi abuses |
Multiple vulnerabilities in php topsites |
|
Tries to access setup.php without authentication |
| Cgi abuses |
Multiple vulnerabilities in phpbb 2.0.11 and older |
Cve-2005-0259 |
Multiple vulnerabilities in phpbb version 2.0.11 and older |
| Cgi abuses |
Multiple vulnerabilities in phpbb 2.0.13 and older |
Cve-2005-0659, cve-2005-0673, cve-2005-1026 |
Checks for multiple vulnerabilities in phpbb 2.0.13 and older |
| Cgi abuses |
Multiple vulnerabilities in phpbb 2.0.14 and older |
Cve-2005-1193, cve-2005-1290 |
Checks for multiple vulnerabilities in phpbb 2.0.14 and older |
| Cgi abuses |
Multiple vulnerabilities in phpbb <= 2.0.12 |
Cve-2005-0603, cve-2005-0614 |
Checks for multiple vulnerabilities in phpbb version <= 2.0.12 |
| Cgi abuses |
Mybb < 1.0 multiple sql injection vulnerabilities |
Cve-2005-4199, cve-2005-4200 |
Checks for multiple sql injection vulnerabilities in mybb < 1.0 |
| Cgi abuses |
Mybb < 1.01 sql injection vulnerabilities |
Cve-2005-4602 |
Checks for sql injection vulnerabilities in mybb < 1.01 |
| Cgi abuses |
Mybb < 1.04 multiple vulnerabilities |
Cve-2006-0959 |
Checks for multiple vulnerabilities in mybb < 1.04 |
| Cgi abuses |
Mybb <= rc4 multiple sql injection vulnerabilities |
Cve-2005-2580, cve-2005-2778 |
Checks for multiple sql injection vulnerabilities in mybb <= rc4 |
| Cgi abuses |
Mybb client-ip sql injection vulnerability |
|
Checks for client-ip sql injection vulnerability in mybb |
| Cgi abuses |
Mybb detection |
|
Checks for presence of mybb |
| Cgi abuses |
Mybb global variable overwrite vulnerability |
|
Checks for globals.php sql injection vulnerability in mybb |
| Cgi abuses |
Mybb comma parameter sql injection vulnerability |
|
Checks for comma parameter sql injection vulnerability in mybb |
| Cgi abuses |
Mybb fid parameter sql injection vulnerability (2) |
|
Checks for fid parameter sql injection vulnerability in mybb (2) |
| Cgi abuses |
Mybb finduser sql injection |
|
Checks for the presence of a sql injection in mybb |
| Cgi abuses |
Mybb forums parameter sql injection vulnerability |
|
Checks for forums parameter sql injection vulnerability in mybb |
| Cgi abuses |
Mybb member.php sql injection vulnerability |
Cve-2005-0282 |
Checks for sql injection vulnerability in mybb's member.php script |
| Cgi abuses |
Mybb referrer parameter sql injection vulnerability |
Cve-2006-1974 |
Checks for referrer parameter sql injection vulnerability in mybb |
| Cgi abuses |
Mybbb rating parameter sql injection vulnerability |
|
Checks for rating parameter sql injection vulnerability in mybb |
| Cgi abuses |
Mydms sql injection and directory traversal |
Cve-2004-1732, cve-2004-1733 |
Sql injection against the remote mydms installation |
| Cgi abuses |
My_egallery code execution |
|
Checks for the version of my_egallery |
| Cgi abuses |
N/x web content management code injection |
Cve-2003-1251 |
Checks for the presence of menu.inc.php |
| Cgi abuses |
Netfile default admin user / password vulnerability |
|
Checks for default admin user / password vulnerability in netfile ftp/web server |
| Cgi abuses |
Netfile ftp/web server directory traversal vulnerabilities |
|
Checks for directory traversal vulnerabilities in netfile ftp/web server |
| Cgi abuses |
Nocc <= 1.0 multiple vulnerabilities |
Cve-2006-0891, cve-2006-0892, cve-2006-0893, cve-2006-0894, cve-2006-0895 |
Checks for a local file include flaw in nocc |
| Cgi abuses |
Nabopoll path parameter remote file include vulnerability |
Cve-2005-2157 |
Checks for path parameter remote file include vulnerability in nabopoll |
| Cgi abuses |
Nag detection |
|
Checks for presence of nag |
| Cgi abuses |
Namazu multiple flaws |
Cve-2004-1318 |
Checks for the version of namazu |
| Cgi abuses |
Neomail session id validation vulnerability |
Cve-2006-0711 |
Checks for session id validation vulnerability in neomail |
| Cgi abuses |
Netgear hidden password check |
Cve-2004-2556, cve-2004-2557 |
Netgear hidden password check |
| Cgi abuses |
Nettools command execution |
Cve-2001-0899 |
Executed 'id' through index.php |
| Cgi abuses |
Netauth |
Cve-2000-0782 |
Checks for the presence of /cgi-bin/netauth.cgi |
| Cgi abuses |
Netquery <= 3.1 multiple vulnerabilities |
|
Checks for multiple vulnerabilities in netquery <= 3.1 |
| Cgi abuses |
Netquery <= 3.11 arbitrary command execution vulnerability |
Cve-2005-2684 |
Checks for arbitrary command execution vulnerability in netquery <= 3.11 |
| Cgi abuses |
Netref cat_for_gen.php remote php script injection vulnerability |
|
Netref cat_for_gen.php remote php script injection vulnerability |
| Cgi abuses |
Networkactiv web server script source disclosure vulnerability |
Cve-2006-0815 |
Checks version of networkactiv web server |
| Cgi abuses |
Newsscript access validation vulnerability |
Cve-2005-0735 |
Checks for access validation vulnerability in newsscript |
| Cgi abuses |
Noah's classifieds <= 1.3 multiple vulnerabilities |
Cve-2006-0879, cve-2006-0880, cve-2006-0881, cve-2006-0882 |
Checks for search page sql injection flaw in noah's classifieds |
| Cgi abuses |
Non-existant page physical path disclosure vulnerability |
Cve-2003-0456, cve-2001-1372 |
Tests for a generic physical path disclosure vulnerability |
| Cgi abuses |
Novell groupwise webaccess authentication bypass |
Cve-2005-0296 |
Checks groupware auth bypass |
| Cgi abuses |
Novell groupwise webacc information disclosure |
Can-2001-1458 |
Novell groupwise webacc information disclosure |
| Cgi abuses |
Novell web server nds tree browsing |
Can-1999-1020 |
Novell web server nds tree browsing |
| Cgi abuses |
Nucleus cms dir_libs parameter remote file include vulnerability |
Cve-2006-2583 |
Tries to read a local file using nucleus cms |
| Cgi abuses |
Nucleus cms sql injection |
|
Nucleus version check |
| Cgi abuses |
Nucleus multiple vulnerabilities |
|
Nucleus version check |
| Cgi abuses |
Nuked-klan file include |
Cve-2004-1937 |
Determine if nuked-klan is vulnerable to a file include attack |
| Cgi abuses |
Odbc tools check |
|
Checks for the presence of odbc tools |
| Cgi abuses |
Ocean12 asp calendar administrative access |
Cve-2004-1400 |
Auth bypass test |
| Cgi abuses |
Ocean12 database download |
|
Checks for ocean12 guestbook |
| Cgi abuses |
Officescan configuration file disclosure |
|
Checks for the presence of /officescan/hotdownload/ofscan.ini |
| Cgi abuses |
Omnihttpd visadmin exploit |
Cve-1999-0970 |
Checks for the visadmin.exe cgi |
| Cgi abuses |
Omnipro httpd 2.08 scripts source full disclosure |
|
Check the presence of omnipro httpd 2.08 scripts source disclosure. |
| Cgi abuses |
Oneorzero sql injection |
Cve-2003-0303 |
Determines oneorzero is installed |
| Cgi abuses |
Open webmail detection |
|
Checks for the presence of open webmail |
| Cgi abuses |
Openbb sql injection |
|
Tests for sql injection |
| Cgi abuses |
Openbb xss and sql injection flaws |
Cve-2005-1612, cve-2005-1613 |
Detects openbb version |
| Cgi abuses |
Openca html injection |
Cve-2004-0787 |
Checks for the version of openca |
| Cgi abuses |
Openca multiple signature validation bypass |
Cve-2003-0960 |
Checks for the version of openca |
| Cgi abuses |
Openca signature verification flaw |
Cve-2004-0004 |
Checks for the version of openca |
| Cgi abuses |
Opencms < 6.22 multiple vulnerabilities |
|
Checks the version of opencms |
| Cgi abuses |
Opendocman access control bypass |
|
Determines if opendocman is present |
| Cgi abuses |
Openemr fileroot parameter remote file include vulnerability |
|
Tries to read a local file using openemr |
| Cgi abuses |
Oracle 9ias dad admin interface |
|
Tests for presence of oracle9ias dad admin interface |
| Cgi abuses |
Oracle 9ias dynamic monitoring services |
Cve-2002-0563 |
Tests for presence of oracle9ias dynamic monitoring services |
| Cgi abuses |
Oracle 9ias globals.jsa access |
Cve-2002-0562 |
Tests for oracle9ias globals.jsa access |
| Cgi abuses |
Oracle 9ias java process manager |
Cve-2002-0563 |
Tests for oracle9ias java process manager |
| Cgi abuses |
Oracle 9ias jsp source file reading |
Cve-2002-0562 |
Test for oracle 9ias jsp source file reading |
| Cgi abuses |
Oracle 9ias owa util access |
Cve-2002-0560 |
Attempts to access the owa_util program directly |
| Cgi abuses |
Oracle 9ias portal_demo org_chart |
|
Tests for presence of oracle9ias portal_demo.org_chart |
| Cgi abuses |
Oracle 9ias soap default configuration vulnerability |
Cve-2001-1371 |
Tests for oracle9ias default soap installation |
| Cgi abuses |
Oracle 9ias soap configuration file retrieval |
Cve-2002-0568 |
Tries to retrieve oracle9ias soap configuration file |
| Cgi abuses |
Oracle 9ias access to soap documentation |
|
Tries to retrieve oracle9ias soap documentation |
| Cgi abuses |
Oracle 9ias default error information disclosure |
Cve-2001-1372 |
Tries to retrieve the phisical path of files through oracle9ias |
| Cgi abuses |
Oracle 9ias mod_plsql buffer overflow |
Cve-2001-1216 |
Oracle 9ias mod_plsql overflow |
| Cgi abuses |
Oracle 9ias mod_plsql directory traversal |
Cve-2001-1217 |
Tests for oracle9ias mod_plsql directory traversal |
| Cgi abuses |
Oracle 9ias web admin |
Cve-2002-0561 |
Oracle 9ias mod_plsql admin page |
| Cgi abuses |
Oracle application server 9i webcache < 9.0.4.0 multiple vulnerabilities |
Cve-2005-1381, cve-2005-1382 |
Checks for multiple vulnerabilities in oracle application server 9i webcache < 9.0.4.0 |
| Cgi abuses |
Oracle http server mod_access restriction bypass vulnerability |
Cve-2005-1383 |
Checks for mod_access restriction bypass vulnerability in oracle http server |
| Cgi abuses |
Oracle xsql sample application vulnerability |
|
Tests for oracle xsql sample application vulnerability |
| Cgi abuses |
Oracle xsql stylesheet vulnerability |
Cve-2001-0126 |
Tests for oracle xsql stylesheet vulnerability |
| Cgi abuses |
Oracle xsqlservlet xsqlconfig.xml file |
Cve-2002-0568 |
Tests for presence of xsqlconfig.xml |
| Cgi abuses |
Orion application server jsp script source disclosure vulnerability |
Cve-2006-0816 |
Checks version of orion |
| Cgi abuses |
Outlook web access version |
|
Outlook web access version check |
| Cgi abuses |
Outlook web anonymous access |
Cve-2001-0660 |
Outlook web anonymous access |
| Cgi abuses |
Owl intranet engine <= 0.91 multiple vulnerabilities |
|
Checks for sql injection flaw in owl intranet engine |
| Cgi abuses |
Owl intranet engine xrms_file_root parameter remote file include vulnerability |
Cve-2006-1149 |
Tries to read /etc/passwd via owl |
| Cgi abuses |
Owl login bypass |
|
Determines owl is installed |
| Cgi abuses |
Owl multiple vulnerabilities |
Cve-2005-0264, cve-2005-0265 |
Determines owl is installed |
| Cgi abuses |
P-synch multiple issues |
|
P-synch issues |
| Cgi abuses |
Pafiledb error message path disclosure vulnerability |
|
Checks for psfiledb path disclosure |
| Cgi abuses |
Pajax < 0.5.2 multiple vulnerabilities |
Cve-2006-1551, cve-2006-1789 |
Tries to execute code using pajax |
| Cgi abuses |
Pblang < 4.66z multiple vulnerabilities |
|
Checks for multiple vulnerabilities in pblang < 4.66z |
| Cgi abuses |
Pblang bbs <= 4.65 multiple vulnerabilities |
Cve-2005-0526, cve-2005-0630, cve-2005-0631 |
Checks for multiple vulnerabilities in pblang bbs <= 4.65 |
| Cgi abuses |
Pblang multiple vulnerabilities |
Cve-2005-2892, cve-2005-2893, cve-2005-2894, cve-2005-2895 |
Checks for multiple vulnerabilities in pblang |
| Cgi abuses |
Pccs-mysql user/password exposure |
Cve-2000-0707 |
Checks for dbconnect.inc |
| Cgi abuses |
Pd9 megabbs multiple vulnerabilities |
|
Checks for the presence of megabbs |
| Cgi abuses |
Pdgsoft shopping cart vulnerability |
Cve-2000-0401 |
Checks for pdgsoft shopping cart executables |
| Cgi abuses |
Pgpmail.pl detection |
Cve-2001-0937 |
Checks for the presence of pgpmail.pl |
| Cgi abuses |
Php < 4.4.1 / 5.0.6 multiple vulnerabilities |
Cve-2005-2491, cve-2005-3388, cve-2005-3389, cve-2005-3390 |
Checks for multiple vulnerabilities in php < 4.4.1 / 5.0.6 |
| Cgi abuses |
Php advanced transfer manager <= 1.21 multiple vulnerabilities |
Cve-2005-1604 |
Checks for multiple vulnerabilities in php advanced transfer manager <= 1.21 |
| Cgi abuses |
Php advanced transfer manager <= 1.30 multiple vulnerabilities |
|
Checks for multiple vulnerabilities in php advanced transfer manager <= 1.30 |
| Cgi abuses |
Php doc system show parameter local file include vulnerability |
Cve-2005-3878 |
Checks for show parameter local file include vulnerability in php doc system |
| Cgi abuses |
Php live helper multiple remote file include vulnerabilities |
Cve-2006-4051 |
Tries to read /etc/passwd using php live helper |
| Cgi abuses |
Php live! remote configuration file include |
Cve-2004-2485 |
Checks for a flaw in php live! < 2.8.2 |
| Cgi abuses |
Php mail function header spoofing vulnerability |
Cve-2002-0985, cve-2002-0986 |
Checks for version of php |
| Cgi abuses |
Php multiple unspecified vulnerabilities |
|
Checks for version of php |
| Cgi abuses |
Php rocket add-in file traversal |
Cve-2001-1204 |
Looks for a directory traversal vulnerability in the php rocket add-in for frontpage. |
| Cgi abuses |
Php support tickets sql injection vulnerability |
Cve-2005-4264 |
Checks for sql injection vulnerability in php support tickets |
| Cgi abuses |
Php upload center filename parameter directory traversal vulnerability |
Cve-2005-3947 |
Checks for filename parameter directory traversal vulnerability in php upload center |
| Cgi abuses |
Php icalendar arbitrary file upload vulnerability |
Cve-2006-1291 |
Tries to upload php code using php icalendar |
| Cgi abuses |
Php icalendar cookie data local file include vulnerability |
Cve-2006-1292 |
Tries to read a file using php icalendar |
| Cgi abuses |
Php icalendar remote file inclusion vulnerability |
Cve-2005-3366 |
Checks for remote file inclusion vulnerability in php icalendar |
| Cgi abuses |
Php icalendar getdate parameter remote file include vulnerability |
Cve-2006-0648 |
Checks for getdate parameter remote file include vulnerability in php icalendar |
| Cgi abuses |
Php mylog.html/mlog.html read arbitrary file |
Cve-1999-0068 |
Checks php mylog.html/mlog.html arbitrary file access |
| Cgi abuses |
Php-calendar remote file include vulnerability |
Cve-2004-1423 |
Determines if php-calendar can include third-party files |
| Cgi abuses |
Php-calendar search.php sql injection vulnerability |
Cve-2005-1397 |
Checks for sql injection vulnerability in php-calendar search.php |
| Cgi abuses |
Php-fusion < 6.00.110 multiple sql injection vulnerabilities |
Cve-2005-3157, cve-2005-3158, cve-2005-3160, cve-2005-3161 |
Checks for sql injection in php-fusion's register.php |
| Cgi abuses |
Php-fusion <= 6.00.105 multiple vulnerabilities |
Cve-2005-2074, cve-2005-2075 |
Checks for multiple vulnerabilities in php-fusion <= 6.00.105 |
| Cgi abuses |
Php-fusion <= 6.00.106 multiple vulnerabilities |
Cve-2005-2401, cve-2005-3159 |
Checks for multiple vulnerabilities in php-fusion <= 6.00.106 |
| Cgi abuses |
Php-fusion database backup disclosure |
Cve-2004-1724 |
Checks the version of the remote php-fusion |
| Cgi abuses |
Php-fusion detection |
|
Checks the location of the remote php-fusion |
| Cgi abuses |
Php-fusion viewthread.php information disclosure vulnerability |
Cve-2005-0345 |
Checks the version of the remote php-fusion |
| Cgi abuses |
Php-fusion members.php sql injection |
Cve-2004-2437, cve-2004-2438 |
Checks the version of the remote php-fusion |
| Cgi abuses |
Php-kit multiple flaws |
Cve-2004-1537, cve-2004-1538, cve-2005-2683, cve-2005-3552, cve-2005-3553, cve-2005-3554, cve-2005-4424, cve-2006-0785, cve-2006-0786, cve-2006-1507, cve-2006-1773 |
Check for sql injection in phpkit |
| Cgi abuses |
Php-nuke gallery add-on file view |
Cve-2001-0900 |
Determine if a remote host is vulnerable to the gallery vulnerability |
| Cgi abuses |
Php-nuke copying files security vulnerability (admin.php) |
Cve-2001-1032 |
Determine if a remote host is vulnerable to the admin.php vulnerability |
| Cgi abuses |
Php-nuke is installed on the remote host |
Cve-2001-0292, cve-2001-0320, cve-2001-0854, cve-2001-0911, cve-2001-1025, cve-2002-0206, cve-2002-0483, cve-2002-1242 |
Determines if php-nuke is installed on the remote host |
| Cgi abuses |
Php-nuke security vulnerability (bb_smilies.php) |
Can-2001-0320 |
Determine if a remote host is vulnerable to the bb_smilies.php vulnerability |
| Cgi abuses |
Php-nuke' opendir |
Cve-2001-0321 |
Determine if a remote host is vulnerable to the opendir.php vulnerability |
| Cgi abuses |
Php.exe / apache win32 arbitrary file reading vulnerability |
Cve-2002-2029 |
Tests for php.exe / apache win32 arbitrary file reading vulnerability |
| Cgi abuses |
Php3 physical path disclosure vulnerability |
|
Tests for php3 physical path disclosure vulnerability |
| Cgi abuses |
Php4 physical path disclosure vulnerability |
Cve-2002-0249 |
Tests for php4 physical path disclosure vulnerability |
| Cgi abuses |
Phpadsnew code injection |
Cve-2001-1054 |
Checks for the presence of remotehtmlview.php |
| Cgi abuses |
Phpcatalog sql injection |
|
Sql injection |
| Cgi abuses |
Phpfm arbitrary file upload vulnerability |
Cve-2005-4423 |
Checks for arbitrary file upload vulnerability in phpfm |
| Cgi abuses |
Phplinks multiple input validation vulnerabilities |
|
Checks for the presence of phplinks |
| Cgi abuses |
Phpmyadmin subform file inclusion vulnerability |
Cve-2005-3299 |
Checks for subform file inclusion vulnerability in phpmyadmin |
| Cgi abuses |
Phpmybackuppro input validation issues |
|
Fetches the version of phpmybackuppro |
| Cgi abuses |
Phpmywebhosting sql injection vulnerability |
Cve-2004-2218 |
Checks for the presence of phpmywebhosting |
| Cgi abuses |
Phpnews auth.php remote file include vulnerability |
Cve-2005-0632 |
Detects remote file include vulnerability in auth.php in phpnews |
| Cgi abuses |
Phpnews auth.php sql injection vulnerability |
Cve-2005-2383 |
Checks for auth.php sql injection vulnerability in phpnews |
| Cgi abuses |
Phpnews prevnext parameter sql injection vulnerability |
Cve-2005-2156 |
Checks for prevnext parameter sql injection vulnerability in phpnews |
| Cgi abuses |
Phpnews sendtofriend.php sql injection |
Cve-2004-2474 |
Makes a request to the remote host by supplying the mid paramter in the url |
| Cgi abuses |
Phpsurveyor sid sql injection flaw |
Cve-2005-4586 |
Checks for phpsurveyor sid sql injection flaw |
| Cgi abuses |
Phpwind board remote file include vulnerability |
|
Checks for the presence of phpwind board. |
| Cgi abuses |
Phpx username parameter sql injection vulnerability |
Cve-2005-3968 |
Checks for username parameter sql injection vulnerability in phpx |
| Cgi abuses |
Phpix directory traversal vulnerability |
Cve-2000-0919 |
Phpix directory traversal vulnerability |
| Cgi abuses |
Phplist detection |
|
Checks for presence of phplist |
| Cgi abuses |
Phplist database_module parameter local file include vulnerability |
Cve-2006-1746 |
Tries to read /etc/passwd using phplist |
| Cgi abuses |
Phprojekt unspecified authentication bypass vulnerability |
|
Uses a form-post method to enter the configuration page |
| Cgi abuses |
Phprojekt path_pre parameter remote file include vulnerability |
|
Tries to read /etc/passwd using phprojekt |
| Cgi abuses |
Pix firewall manager directory traversal |
Cve-1999-0158 |
\..\..\file.txt |
| Cgi abuses |
Pjreview_neo.cgi arbitrary file reading |
Cve-2004-2132 |
Checks aprox portal |
| Cgi abuses |
Ppa ppa_root_path variable file include vulnerability |
Cve-2005-2199 |
Checks for ppa_root_path variable file include vulnerability in ppa |
| Cgi abuses |
Pt news unauthorized administrative access |
|
Determine if ptnews grants administrative access to everyone |
| Cgi abuses |
Pwsphp xss |
Cve-2005-1509 |
Checks xss in pwsphp |
| Cgi abuses |
Pafiledb pafiledbcookie sql injection vulnerability |
Cve-2005-2723 |
Checks for pafiledbcookie sql injection vulnerability in pafiledb |
| Cgi abuses |
Pages pro cd directory traversal |
|
Pages pro cd directory traversal |
| Cgi abuses |
Patchlink update server nwupload.asp directory traversal vulnerability |
Cve-2006-3426 |
Tries to write a file using patchlink update server |
| Cgi abuses |
Patchlink update server proxyreg.asp authentication bypass vulnerability |
Cve-2006-3425 |
Tries to list registered proxy server in patchlink update server |
| Cgi abuses |
Patchlink update checkid sql injection vulnerability |
Cve-2006-3430 |
Tries to exploit sql injection issue in patchlink update |
| Cgi abuses |
Paypal store front code injection |
|
Checks for the presence of index.php |
| Cgi abuses |
Perldesk file inclusion |
Cve-2004-1678 |
Determines if perldesk is vulnerable to a file inclusion |
| Cgi abuses |
Perldesk sql injection vulnerability |
Cve-2005-0343 |
Checks if perldesk is vulnerable to a sql injection attack |
| Cgi abuses |
Philboard database access |
|
Downloads philboard.mdb |
| Cgi abuses |
Philboard philboard_admin.asp authentication bypass |
|
Try to bypass philboard philboard_admin.asp authentication |
| Cgi abuses |
Phorum detection |
|
Checks for presence of phorum |
| Cgi abuses |
Photopost multiple input validation vulnerabilities |
Cve-2005-0928, cve-2005-0929 |
Checks for multiple input validation vulnerabilities in photopost php |
| Cgi abuses |
Photopost php detection |
|
Checks for presence of photopost php |
| Cgi abuses |
Photopost showgallery.php sql injection |
Can-2005-0273, can-2005-0274 |
Checks for the presence of an sql injection in showgallery.php |
| Cgi abuses |
Phpgedview pgv_base_directory parameter remote file include vulnerability |
Cve-2005-4467, cve-2005-4468, cve-2005-4469 |
Checks for pgv_base_directory parameter remote file include vulnerability in phpgedview |
| Cgi abuses |
Phpgroupware addressbook < 0.9.16 unspecified flaw |
|
Checks for phpgroupware version |
| Cgi abuses |
Phpgroupware detection |
|
Checks for phpgroupware |
| Cgi abuses |
Phpgroupware arbitrary command execution |
Cve-2001-0043 |
Checks for phpgroupware version |
| Cgi abuses |
Phpgroupware calendar server side script execution |
Cve-2004-0016 |
Checks for phpgroupware version |
| Cgi abuses |
Phpgroupware index.php html injection vulnerabilities |
Cve-2004-2574 |
Checks for phpgroupware version |
| Cgi abuses |
Phpgroupware multiple html injection vulnerabilities |
Cve-2003-0504 |
Checks for phpgroupware version |
| Cgi abuses |
Phpgroupware multiple module sql injection vulnerabilities |
Cve-2004-0017 |
Checks for phpgroupware version |
| Cgi abuses |
Phpgroupware plaintext cookie authentication credentials vulnerability |
Cve-2004-2578 |
Checks for phpgroupware version |
| Cgi abuses |
Phpgroupware unspecified remote file include vulnerability |
|
Checks for phpgroupware version |
| Cgi abuses |
Phpauction <= 2.5 multiple vulnerabilities |
Cve-2005-2252, cve-2005-2253, cve-2005-2254, cve-2005-2255 |
Checks for multiple vulnerabilities in phpauction <= 2.5 |
| Cgi abuses |
Pi3web tstisap.dll overflow |
Cve-2001-0302 |
Checks for the presence of /isapi/tstisapi.dll |
| Cgi abuses |
Pinnacle showcenter skin dos |
Cve-2004-1699 |
Checks skin dos in pinnacle showcenter |
| Cgi abuses |
Pixelpost < 1.5 rc1 multiple vulnerabilities |
Cve-2006-1104, cve-2006-1105, cve-2006-1106 |
Tries to inject sql code via pixelpost's showimage parameter |
| Cgi abuses |
Pixelpost category parameter sql injection vulnerability |
Cve-2006-2889, cve-2006-2890 |
Tries to exploit sql injection issue in pixelpost |
| Cgi abuses |
Playsms cookie sql injection |
|
Tests for the playsms sql injection |
| Cgi abuses |
Plogger config parameter remote file include vulnerability |
Cve-2005-4573 |
Checks for config parameter remote file include vulnerability in plogger |
| Cgi abuses |
Plone unprotected membershiptool methods vulnerability |
Cve-2006-1711 |
Tries to change profiles using plone |
| Cgi abuses |
Plume cms <= 1.0.2 remote file inclusion vulnerability |
Cve-2006-0725 |
Check if plume cms is vulnerable to a file inclusion flaw |
| Cgi abuses |
Plusmail vulnerability |
Cve-2000-0074 |
Checks for the presence of /cgi-bin/plusmail |
| Cgi abuses |
Pmwiki < 2.1 beta 21 multiple vulnerabilities |
Cve-2006-0479 |
Checks for multiple vulnerabilities in pmwiki < 2.1 beta 21 |
| Cgi abuses |
Polar helpdesk authentication bypass |
|
Checks for polarhelpdesk |
| Cgi abuses |
Poll it v2.0 cgi |
Cve-2000-0590 |
Checks for the presence of /cgi-bin/pollit/poll_it_ssi_v2.0.cgi |
| Cgi abuses |
Post-nuke multiple xss |
|
Determines if post-nuke is vulnerable to xss |
| Cgi abuses |
Post-nuke rating system denial of service |
|
Determine if a remote host is vulnerable to the postnuke rating dos vulnerability |
| Cgi abuses |
Post-nuke information disclosure |
|
Determine if a remote host is vulnerable to the opendir.php vulnerability |
| Cgi abuses |
Post-nuke information disclosure (2) |
|
Determine if a remote host is vulnerable to the opendir.php vulnerability |
| Cgi abuses |
Post-nuke pntresmailer directory traversal |
Cve-2004-1205, cve-2004-1206 |
Determines if pntresmailer is vulnerable to a directory traversal |
| Cgi abuses |
Postnuke < 0.762 multiple vulnerabilities |
Cve-2006-0800, cve-2006-0801, cve-2006-0802 |
Checks for admin access bypass issue in postnuke |
| Cgi abuses |
Postnuke detection |
|
Detects the presence of postnuke |
| Cgi abuses |
Postnuke install script |
|
Determines if post-nuke's install.php is readable |
| Cgi abuses |
Postnuke pnphpbb2 phpbb_root_path parameter remote file include vulnerability |
|
Tries to read a file with pnphpbb2 module |
| Cgi abuses |
Poster version.two privilege escalation |
|
Determines owl is installed |
| Cgi abuses |
Power up information disclosure |
Can-2001-1138 |
Power up information disclosure |
| Cgi abuses |
Powerportal path dislcosure |
Can-2004-0662, can-2004-0664 |
Checks for the presence of an path disclosure bug in powerportal |
| Cgi abuses |
Powerportal private message html injection |
Cve-2004-2514 |
Checks the version of the remote powerportal installation |
| Cgi abuses |
Powerportal sql injection |
|
Checks the version of the remote powerportal installation |
| Cgi abuses |
Productcart multiple input validation vulnerabilities |
Cve-2005-0994, cve-2005-0995 |
Checks for multiple input validation vulnerabilities in productcart |
| Cgi abuses |
Productcart multiple sql injection vulnerabilities (2) |
Cve-2005-1967, cve-2005-2445 |
Checks for multiple sql injection vulnerabilities (2) in productcart |
| Cgi abuses |
Productcart sql injection |
Cve-2003-0522, cve-2003-0523, cve-2003-1304 |
Determine if productcart is vulnerable to a sql injection attack |
| Cgi abuses |
Psunami.cgi command execution |
|
Checks for psunami.cgi |
| Cgi abuses |
Punbb < 1.2.6 multiple vulnerabilities |
Cve-2005-2193 |
Detects multiple vulnerabilities in punbb < 1.2.6 |
| Cgi abuses |
Punbb < 1.2.7 multiple vulnerabilities |
Cve-2005-4665 |
Checks for multiple vulnerabilities in punbb < 1.2.7 |
| Cgi abuses |
Punbb < 1.2.8 multiple vulnerabilities |
Cve-2005-3078, cve-2005-3079 |
Checks for multiple vulnerabilities in punbb < 1.2.8 |
| Cgi abuses |
Punbb input validation vulnerabilities |
Cve-2005-0569, cve-2005-0570, cve-2005-0571 |
Detects input validation vulnerabilities in punbb |
| Cgi abuses |
Punbb detection |
|
Checks for presence of punbb |
| Cgi abuses |
Punbb old_searches parameter sql injection vulnerability |
Cve-2005-3518 |
Checks for old_searches parameter sql injection vulnerability in punbb |
| Cgi abuses |
Punbb profile.php sql injection vulnerability |
Cve-2005-1051 |
Checks for sql injection vulnerability in punbb's profile.php |
| Cgi abuses |
Punbb search dropdown information disclosure |
|
Checks for punbb version for information disclosure |
| Cgi abuses |
Qwikiwiki directory traversal vulnerability |
Can-2005-0283 |
Checks for the presence of a file inclusion vulnerability |
| Cgi abuses |
Qualiteam x-cart remote command execution |
Cve-2004-0241 |
Checks qualiteam x-cart |
| Cgi abuses |
Quicktime/darwin remote admin exploit |
Cve-2003-0050, cve-2003-0051, cve-2003-0052, cve-2003-0053, cve-2003-0054, cve-2003-0055 |
Checks quicktime/darwin server for parse_xml.cgi |
| Cgi abuses |
Rcblog post parameter directory traversal vulnerability |
Cve-2006-0370, cve-2006-0371 |
Checks for directory transversal in rcblog index.php script |
| Cgi abuses |
Rm safetynet plus xss |
|
Checks rm safetynet plus xss |
| Cgi abuses |
Roads' search.pl |
Cve-2001-0215 |
Checks for the presence of /cgi-bin/search.pl |
| Cgi abuses |
Raidenhttpd script source disclosure vulnerability |
Cve-2006-0949 |
Checks version of raidenhttpd |
| Cgi abuses |
Raidenhttpd directory traversal |
|
Raidenhttpd directory traversal |
| Cgi abuses |
Read any file thanks to ~nobody/ |
|
Checks for the presence of /~nobody/etc/passwd |
| Cgi abuses |
Reading cgi script sources using /cgi-bin-sdb |
Cve-2000-0868 |
Checks for the presence of /cgi-bin-sdb/ |
| Cgi abuses |
Realserver default.cfg file search |
|
Realserver default.cfg file search |
| Cgi abuses |
Redhat 6.0 cachemgr.cgi |
Cve-1999-0710 |
Checks whether the cachemgr.cgi is installed and accessible. |
| Cgi abuses |
Redhat stronghold file system disclosure |
Cve-2001-0868 |
Redhat stronghold file system disclosure |
| Cgi abuses |
Remote code execution in ezcontents |
Cve-2004-0070 |
Detect ezcontents code execution |
| Cgi abuses |
Resin dos device path disclosure |
Cve-2002-2090 |
Tests for resin path disclosure vulnerability |
| Cgi abuses |
Resin directory traversal vulnerability |
Cve-2006-1953 |
Tries to retrieve boot.ini using resin |
| Cgi abuses |
Resin traversal |
Cve-2001-0304 |
\..\..\file.txt |
| Cgi abuses |
Resin viewfile servlet file disclosure vulnerability |
Cve-2006-2437, cve-2006-2438 |
Tries to get the absolute installation path of resin |
| Cgi abuses |
Risearch arbitrary file access |
Cve-2004-2061 |
Determines the presence of risearch show.pl |
| Cgi abuses |
Rich media e-commerce stores sensitive information insecurely |
|
Rich media e-commerce stores sensitive information insecurely |
| Cgi abuses |
Robots.txt information disclosure |
|
Checks for a web server's robots.txt |
| Cgi abuses |
Roxen server /%00/ bug |
Cve-2000-0671 |
Make a request like http://www.example.com/%00/ |
| Cgi abuses |
Roxen counter module |
|
Roxen counter module installed ? |
| Cgi abuses |
Ruby on rails routing denial of service vulnerability |
|
Tries to hang ruby on rails |
| Cgi abuses |
Runcms <= 1.2 multiple vulnerabilities |
Cve-2005-2691, cve-2005-2692 |
Checks for multiple vulnerabilities in runcms <= 1.2 |
| Cgi abuses |
Runcms remote arbitrary file upload vulnerability |
Cve-2005-1031 |
Checks for remote arbitrary file upload vulnerability in runcms |
| Cgi abuses |
Runcms bbpath parameter remote file include vulnerability |
|
Checks for bbpath parameter remote file include vulnerability in runcms |
| Cgi abuses |
Sap internet graphics server directory traversal vulnerability |
|
Attempts to read /etc/passwd |
| Cgi abuses |
Saxopress url parameter directory traversal vulnerability |
Cve-2006-1771 |
Tries to retrieve a file using saxopress |
| Cgi abuses |
Sgallery idimage sql injection |
Can-2005-0377 |
Checks for the presence of an sql injection in idimage parameter |
| Cgi abuses |
Sir gnuboard remote file inclusion |
Cve-2004-1403 |
Checks for the presence of index.php |
| Cgi abuses |
Six webboard's generate.cgi |
Cve-2001-1115 |
Checks for the presence of /cgi-bin/webboard/generate.cgi |
| Cgi abuses |
Slmail webmail overflows |
Cve-2003-0266, cve-2003-0267, cve-2003-0268 |
Determines if the remote slwebmail server is flawed |
| Cgi abuses |
Spip < 1.8.2-g sql injection and xss flaws |
Cve-2006-0517, cve-2006-0518, cve-2006-0519 |
Checks for spip sql injection flaw |
| Cgi abuses |
Spid lang_path variable file include vulnerability |
Cve-2005-2198 |
Checks for lang_path variable file include vulnerability in spid |
| Cgi abuses |
Sql disclosure in invision power board |
|
Detect ipb sql disclosure |
| Cgi abuses |
Sql injection in antiboard |
Cve-2004-2062, cve-2004-2063 |
Sql injection |
| Cgi abuses |
Sql injection in jportal |
Cve-2004-2036 |
Sql injection |
| Cgi abuses |
Sql injection in reviewpost php pro |
Cve-2004-2175 |
Sql injection |
| Cgi abuses |
Sql injection in xpression software |
|
Sql injection |
| Cgi abuses |
Sql injection in xtreme asp photo gallery |
|
Sql injection in xtreme asp photo gallery |
| Cgi abuses |
Sql injection in phpbb |
Cve-2003-0486 |
Sql injection |
| Cgi abuses |
Sql injection in phpbb (2) |
Cve-2003-1215, cve-2003-1216 |
Sql injection |
| Cgi abuses |
Sql injection in phpbb (3) |
|
Sql injection |
| Cgi abuses |
Sql injection in phpbb login form |
|
Sql injection |
| Cgi abuses |
Sql injections in photopost php pro |
Cve-2004-0239, cve-2004-0250 |
Sql injection |
| Cgi abuses |
Sqlqhit directory structure disclosure |
Can-2001-0986 |
Sqlqhit directory stracture disclosure |
| Cgi abuses |
Swc overflow |
|
Checks for the presence of /cgi-bin/swc |
| Cgi abuses |
Sambar /cgi-bin/mailit.pl installed ? |
|
Checks for the presence of /cgi-bin/mailit |
| Cgi abuses |
Sambar /sysadmin directory 2 |
|
Sambar webserver installed ? |
| Cgi abuses |
Sambar cgis path disclosure |
|
Some cgis reveal the web server installation directory |
| Cgi abuses |
Sambar web server cgi scripts |
Cve-2000-0213 |
Checks for the presence of /cgi-bin/{hello,echo}.bat |
| Cgi abuses |
Sambar default cgi info disclosure |
|
Tests for testcgi.exe and environ.pl |
| Cgi abuses |
Sambar sendmail /session/sendmail |
|
Sambar /session/sendmail mailer installed ? |
| Cgi abuses |
Sambar webserver pagecount hole |
Cve-2001-1010 |
Make a request like http://www.example.com/session/pagecount |
| Cgi abuses |
Sandsurfer user authentication vulnerability |
Cve-2004-2087 |
Checks for sandsurfer |
| Cgi abuses |
Savant cgitest.exe buffer overflow |
Cve-2002-2146 |
Savant cgitest.exe buffer overflow |
| Cgi abuses |
Savant original form cgi access |
Cve-2000-0521 |
Determine if a remote host is savant web server, and whether it is vulnerable to attack |
| Cgi abuses |
Savewebportal <= 3.4 multiple vulnerabilities |
|
Checks for savewebportal arbitrary file inclusion |
| Cgi abuses |
Sawmill < 7.1.6 multiple vulnerabilities |
Cve-2005-1900, cve-2005-1901 |
Checks for multiple vulnerabilities in sawmill < 7.1.6 |
| Cgi abuses |
Scanmail file check |
|
Checks for the presence scanmail files |
| Cgi abuses |
Scout portal toolkit forumid parameter sql injection vulnerability |
Cve-2006-3309 |
Checks for forumid parameter sql injection in scount portal toolkit |
| Cgi abuses |
Sendcard sql injection |
Cve-2005-2404 |
Checks for sql injection in the id field in sendcard.php |
| Cgi abuses |
Serendipity < 0.8.1 multiple vulnerabilities |
Cve-2005-1712, cve-2005-1713 |
Checks for multiple vulnerabilities in serendipity < 0.8.1 |
| Cgi abuses |
Serendipity detection |
|
Checks for presence of serendipity |
| Cgi abuses |
Serendipity sql injections |
Cve-2004-2157, cve-2004-2158 |
Checks for sql injection vulnerability in serendipity |
| Cgi abuses |
Serendipity xml-rpc for php remote code injection vulnerability |
Cve-2005-1921 |
Checks for xml-rpc for php remote code injection vulnerability in serendipity |
| Cgi abuses |
Serendipity exit.php sql injection vulnerabilities |
Cve-2005-1134 |
Checks for sql injection vulnerabilities in serendipity exit.php |
| Cgi abuses |
Servletexec 4.1 / jrun isapi dos |
Cve-2002-0894, cve-2000-0681 |
Tests for servletexec 4.1 isapi dos |
| Cgi abuses |
Servletexec 4.1 isapi file reading |
Cve-2002-0893 |
Tests for servletexec file reading |
| Cgi abuses |
Servletexec 4.1 isapi physical path disclosure |
Cve-2002-0892 |
Tests for servletexec 4.1 isapi path disclosure |
| Cgi abuses |
Shells in /cgi-bin |
Cve-1999-0509 |
Checks for the presence of various shells in /cgi-bin |
| Cgi abuses |
Shopcartcgi arbitrary file reading |
Cve-2004-0293 |
Checks shopcart |
| Cgi abuses |
Shopplus arbitrary command execution |
Can-2001-0992 |
Shopplus arbitrary command execution |
| Cgi abuses |
Shopadmin.asp has a poor security history |
|
Checks for the presence of shopadmin.asp |
| Cgi abuses |
Showcode possible |
Cve-1999-0736 |
Determines the presence of showcode.asp |
| Cgi abuses |
Silent-storm portal multiple input validation vulnerabilities |
Cve-2004-1566, cve-2004-1567 |
Checks for vulnerabilities in silent-storm portal |
| Cgi abuses |
Silvernews < 2.0.4 multiple vulnerabilities |
Cve-2005-2478 |
Checks for multiple vulnerabilities in silvernews < 2.0.4 |
| Cgi abuses |
Silverstream database structure |
|
Checks if silverstream database structure is visible. |
| Cgi abuses |
Silverstream directory listing |
|
Checks if silverstream directory listings are disabled. |
| Cgi abuses |
Simpgb guestbook.php sql injection vulnerability |
Cve-2005-0786 |
Checks for sql injection in simpgb |
| Cgi abuses |
Simple form mail relaying vulnerability |
|
Checks for mail relaying vulnerability in simple form |
| Cgi abuses |
Simple form mail relaying via subject tags vulnerability |
|
Checks for mail relaying via subject tags vulnerability in simple form |
| Cgi abuses |
Simple machines forum avatar information disclosure vulnerability |
Cve-2005-2817 |
Checks for avatar code execution vulnerability in simple machines forum |
| Cgi abuses |
Simple machines forum msg parameter sql injection vulnerability |
|
Checks for msg parameter sql injection vulnerability in simple machines forum |
| Cgi abuses |
Simple php blog <= 0.4.0 multiple vulnerabilities |
Cve-2005-2733, cve-2005-2787 |
Checks for multiple vulnerabilities in simple php blog <= 0.4.0 |
| Cgi abuses |
Simple php blog blog_language parameter local file include vulnerability |
Cve-2006-1243 |
Tries to read a file using simple php blog |
| Cgi abuses |
Simplebbs name parameter arbitrary command execution vulnerability |
Cve-2005-4135 |
Checks for name parameter arbitrary command execution vulnerability in simplebbs |
| Cgi abuses |
Simplebbs users disclosure |
|
Checks for the presence of users.php |
| Cgi abuses |
Simpleboard / joomlaboard sbp parameter remote file include vulnerabilities |
Cve-2006-3528 |
Tries to read a local file using simpleboard / joomlaboard |
| Cgi abuses |
Simplechat information disclosure |
|
Checks for the presence of data/usr |
| Cgi abuses |
Simplicity of upload language parameter file include vulnerability |
Cve-2005-2607 |
Checks for language parameter file include vulnerability in simplicity of upload |
| Cgi abuses |
Simplog <= 0.9.2 multiple vulnerabilities |
Cve-2006-1776, cve-2006-1777, cve-2006-1778, cve-2006-1779 |
Tries to read /etc/passwd using simplog |
| Cgi abuses |
Singapore gallery multiple flaws |
Cve-2004-1407, cve-2004-1408, cve-2004-1409 |
The presence of singapore gallery |
| Cgi abuses |
Singapore md5 administrative password disclosure |
|
Checks adminusers.csv presence |
| Cgi abuses |
Sitebuilder-fx admindir parameter remote file include vulnerability |
Cve-2006-3395 |
Tries to read a local file using sitebuilder-fx |
| Cgi abuses |
Siteenable xss and sql injection vulnerabilities |
Cve-2005-1011 |
Checks for xss and sql injection vulnerabilities in siteenable |
| Cgi abuses |
Siteminder html page injection vulnerability |
|
Checks for a flaw in siteminder |
| Cgi abuses |
Siteframe local_path remote file include vulnerability |
Cve-2005-1965 |
Checks for local_path remote file include vulnerability in siteframe |
| Cgi abuses |
Siteman page user database privilege escalation vulnerability |
Cve-2005-0305 |
Checks siteman's version |
| Cgi abuses |
Skull-splitter guestbook multiple html injection vulnerabilities |
|
Skull-splitter guestbook multiple html injection vulnerabilities |
| Cgi abuses |
Snapstream pvs web directory traversal |
Cve-2001-1108 |
Snapstream web directory traversal |
| Cgi abuses |
Snif file disclosure |
|
Checks for the version of snif |
| Cgi abuses |
Snitz forums 2000 sql injection |
Cve-2003-0286 |
Determine snitz forums version |
| Cgi abuses |
Snitz forums cmd execution |
|
Determine if snitz forums is vulnerable to a cmd exec flaw |
| Cgi abuses |
Sonicwall soho web interface xss |
Cve-2005-1006 |
Checks sonicwall soho web interface xss |
| Cgi abuses |
Sparkleblog sql injection |
|
Checks for the presence of an sql injection in id parameter |
| Cgi abuses |
Sphider settings_dir parameter remote file include vulnerability |
Cve-2006-1784 |
Tries to read /etc/passwd using sphider |
| Cgi abuses |
Spidersales shopping cart sql injection |
Cve-2004-0348 |
Checks for the presence of spidersales shopping cart |
| Cgi abuses |
Spyke flaws |
|
Checks for the presence of info.dat |
| Cgi abuses |
Squirrelcart sql injection |
Cve-2005-0962 |
Sql injection in squirrelcart |
| Cgi abuses |
Squirrelmail < 1.4.6 multiple vulnerabilities |
Cve-2006-0188, cve-2006-0195, cve-2006-0377 |
Checks for imap command injection in squirrelmail |
| Cgi abuses |
Squirrelmail < 1.45 multiple vulnerabilities |
Cve-2005-1769, cve-2005-2095 |
Checks for multiple vulnerabilities in squirrelmail < 1.45 |
| Cgi abuses |
Squirrelmail detection |
|
Checks for the presence of squirrelmail |
| Cgi abuses |
Squirrelmail s/mime plug-in remote command execution vulnerability |
Cve-2005-0239 |
Checks for remote command execution vulnerability in squirrelmail s/mime plugin |
| Cgi abuses |
Squirrelmail base_uri parameter information disclosure vulnerability |
|
Tries to change path parameter used by squirrelmail cookies |
| Cgi abuses |
Squirrelmail decodeheader html injection vulnerability |
|
Check squirrelmail for html injection vulnerability |
| Cgi abuses |
Squirrelmail plugins parameter local file include vulnerability |
Cve-2006-2842 |
Tries to read file using squirrelmail |
| Cgi abuses |
Squirrelmail session_expired_post arbitrary variables overwriting vulnerability |
Cve-2006-4019 |
Tries to overwrite a variable squirrelmail |
| Cgi abuses |
Squirrelmail's multiple flaws |
|
Determine if squirrelmail reads arbitrary files |
| Cgi abuses |
Squirrelcart cart_isp_root remote file include vulnerability |
Cve-2006-2483 |
Tries to read a local file using squirrelcart |
| Cgi abuses |
Stadtaus php scripts file include vulnerabilities |
|
Detects file include vulnerabilities in auth.php in stadtaus' php scripts |
| Cgi abuses |
Stellardocs path disclosure |
|
Sql injection and more. |
| Cgi abuses |
Stockman shopping cart command execution |
|
Determines the version of shop.plx |
| Cgi abuses |
Stockman shopping cart path disclosure |
|
Determines the remote root path |
| Cgi abuses |
Stronghold swish |
|
Checks for the presence of cgi-bin/search |
| Cgi abuses |
Sugar open source detection |
|
Checks for presence of sugar open source |
| Cgi abuses |
Sugarcrm <= 4.0 beta remote file inclusion vulnerability |
Cve-2005-4087, cve-2005-4086 |
Check if sugarcrm is vulnerable to directory traversal and remote file inclusion |
| Cgi abuses |
Sugarcrm <= 4.2.0a multiple remote file include vulnerabilities |
Cve-2006-2460 |
Tries to read a local file using sugarcrm |
| Cgi abuses |
Sugarsales remote file access |
|
Checks for a file reading flaw in sugarsales |
| Cgi abuses |
Sun server console authentication bypass vulnerability |
Cve-2006-2513 |
Tries to authenticate to server console as admin/admin |
| Cgi abuses |
Sun's java web server remote command execution |
Cve-2000-0629 |
Checks for the presence of /servlet/sunexamples.bboardservlet |
| Cgi abuses |
Sunone application server source disclosure |
Cve-2003-0411 |
Attempts to read the source of a jsp page |
| Cgi abuses |
Sunsolve cd cgi user input validation |
Cve-2002-0436 |
Sunsolve cd cgi scripts are vulnerable to a few user input validation problems |
| Cgi abuses |
Super guestbook config disclosure |
|
Checks for superguestconfig |
| Cgi abuses |
Super-m son hserver directory traversal |
Cve-2003-0417 |
Super-m son hserver is vulnerable to an exploit which lets an attacker view any file that the web server has access to. |
| Cgi abuses |
Sybase easerver default administrator password |
|
Checks for default administrator password in sybase easerver |
| Cgi abuses |
Symantec antivirus scan engine multiple remote vulnerabilities |
Cve-2006-0230, cve-2006-0231, cve-2006-0232 |
Checks if symantec scan engine is vulnerable |
| Cgi abuses |
Sympa invalid ldap password dos |
|
Checks for sympa version |
| Cgi abuses |
Sympa queue utility privilege escalation vulnerability |
Cve-2005-0073 |
Checks for sympa version |
| Cgi abuses |
Sympa unauthorised list creation security issue |
|
Checks for sympa version |
| Cgi abuses |
Sympa wwsympa do_search_list overflow dos |
|
Checks for sympa version |
| Cgi abuses |
Synchrologic user account information disclosure |
|
Determines if synchrologic is installed |
| Cgi abuses |
Syscp < 1.2.11 multiple script execution vulnerabilities |
|
Checks for multiple script execution vulnerabilities in syscp < 1.2.11 |
| Cgi abuses |
Sysinfo name parameter code execution vulnerability |
Cve-2006-1831 |
Tries to execute arbitrary code using sysinfo |
| Cgi abuses |
Tips mailpost multiple flaws |
|
Test the remote mailpost.exe |
| Cgi abuses |
Twiki detection |
|
Checks for presence of twiki |
| Cgi abuses |
Twiki multiple vulnerabilties |
Cve-2005-0516 |
Checks for the presence of twiki |
| Cgi abuses |
Twiki configure script arbitrary command execution vulnerability |
Cve-2006-3819 |
Tries to run a command using twiki |
| Cgi abuses |
Talentsoft web+ input validation bug vulnerability |
Cve-2000-0282 |
Checks if webplus reads any file |
| Cgi abuses |
Talentsoft web+ version detection |
|
Get the version of web+ cgi |
| Cgi abuses |
Talentsoft web+ reveals install path |
|
Checks for webplus install path disclosure |
| Cgi abuses |
Terminal services web detection |
|
Find instances of tsweb |
| Cgi abuses |
Tests for nimda worm infected html files |
|
Tests for nimda worm infected html files |
| Cgi abuses |
Textportal default passwords |
|
Logs into the remote textportal interface |
| Cgi abuses |
The includer remote command execution flaw |
Cve-2005-0689 |
The includer remote command execution detection |
| Cgi abuses |
Tikiwiki < 1.8.6 / 1.9.1 multiple vulnerabilities |
Cve-2005-1925 |
Checks for multiple vulnerabilities in tikiwiki < 1.8.6 / 1.9.1 |
| Cgi abuses |
Tikiwiki unauthorized page access |
|
Checks the version of tikiwiki |
| Cgi abuses |
Tikiwiki multiple input validation vulnerabilities |
Cve-2004-1923, cve-2004-1924, cve-2004-1925, cve-2004-1926, cve-2004-1927, cve-2004-1928 |
Checks the version of tikiwiki |
| Cgi abuses |
Tikiwiki multiple remote unspecified flaws |
|
Checks the version of tikiwiki |
| Cgi abuses |
Tivoli ldacgi directory traversal |
Cve-2004-2526 |
Ibm tivoli directory traversal |
| Cgi abuses |
Tomcat 4.x jsp source exposure |
Cve-2002-1148 |
Tomcat 4.x jsp source exposure |
| Cgi abuses |
Tomcat's /admin is world readable |
Cve-2000-0672 |
Checks for the presence of /admin |
| Cgi abuses |
Tomcat's snoop servlet gives too much information |
Cve-2000-0760 |
Checks for the presence of /examples/jsp/snp/anything.snp |
| Cgi abuses |
Torrenttrader sql injection |
|
Checks for the presence of sql injection in torrenttrader |
| Cgi abuses |
Towerblog admin bypass |
|
Checks for the presence of a towerblog admin bypassing |
| Cgi abuses |
Trackercam multiple remote vulnerabilities |
Cve-2005-0478, cve-2005-0479, cve-2005-0480, cve-2005-0481, cve-2005-0482 |
Checks for flaws in trackercam |
| Cgi abuses |
Trend micro emanager software check |
Cve-2001-0958 |
Check for certain trend micro dlls |
| Cgi abuses |
Trendmicro controlmanager multiple vulnerabilities |
Cve-2005-1929 |
Checks for controlmanager version |
| Cgi abuses |
Trendmicro officescan multiple vulnerabilities |
|
Checks for officescan stack overflows |
| Cgi abuses |
Truegalerie admin access |
|
Logs into the remote truegalerie installation |
| Cgi abuses |
Turba detection |
|
Checks for presence of turba |
| Cgi abuses |
Turba path disclosure |
|
Checks for status.php |
| Cgi abuses |
Turbo seek files reading |
|
Checks for the presence of tseekdir.cgi |
| Cgi abuses |
Typo3 cmw linklist extension sql injection vulnerability |
|
Detects sql injection vulnerability in typo3 cmw linklist extension |
| Cgi abuses |
Ubb.threads < 6.5.2 beta multiple vulnerabilities |
Cve-2005-1199 |
Checks for multiple vulnerabilities in ubb.threads < 6.5.2 beta |
| Cgi abuses |
Ubb.threads detection |
|
Checks for presence of ubb.threads |
| Cgi abuses |
Ubb.threads debug parameter cross-site scripting vulnerability |
Cve-2006-2755 |
Tries to exploit an xss flaw in ubb.threads |
| Cgi abuses |
Ubb.threads dosearch.php sql injection |
Cve-2004-1622 |
Sql injection in ubb.threads |
| Cgi abuses |
Ubb.threads editpost.php sql injection vulnerability |
Cve-2005-0726 |
Checks for sql injection vulnerability in ubb.threads editpost.php |
| Cgi abuses |
Ubb.threads thispath parameter remote file include vulnerability |
Cve-2006-2568 |
Tries to read a local file using ubb.threads |
| Cgi abuses |
Us robotics disclosed password check |
|
Us robotics password check |
| Cgi abuses |
Uebimiau session directory disclosure |
|
Checks for the presence of sessions directory of uebimiau |
| Cgi abuses |
Ultimate php board information leak |
|
Checks for upb |
| Cgi abuses |
Ultimate php board viewforum.php sql injection and xss flaws |
Cve-2005-1614, cve-2005-1615 |
Checks for upb |
| Cgi abuses |
Ultimate php board admin_ip.php code injection |
|
Checks for upb |
| Cgi abuses |
Ultimate php board users.dat information disclosure |
Cve-2005-2005, cve-2005-2030 |
Tries to get the users.dat file and checks upb version |
| Cgi abuses |
Ultraseek 3.1.x remote dos |
Cve-2000-1019 |
Hangs the remote ultraseek server for some time |
| Cgi abuses |
Unify ewave servletexec 3.0c file upload |
Cve-2000-1024 |
Unify ewave servletexec 3.0c file upload |
| Cgi abuses |
Unknown cgis arguments torture |
|
Tortures the arguments of the remote cgis |
| Cgi abuses |
Unpassworded iiprotect administrative interface |
|
Determines if iisprotect is password-protected |
| Cgi abuses |
Unprotected sitescope service |
Cve-1999-0508 |
Unprotected sitescope service |
| Cgi abuses |
Upload cgi |
|
Checks for the presence of /cgi-bin/upload.cgi |
| Cgi abuses |
Uploadlite cgi |
|
Checks for the presence of /cgi-bin/upload.cgi |
| Cgi abuses |
Vchat information disclosure |
|
Checks for the presence of vchat/msg.txt |
| Cgi abuses |
Vhcs check_login authentication bypass vulnerability |
Cve-2006-0685 |
Tries to access a restricted script using vhcs |
| Cgi abuses |
Vhcs include_path parameter remote file include vulnerability |
|
Tries to read a local file using vhcs |
| Cgi abuses |
Vp-asp sql injection (2) |
|
Performs a sql injection against the remote shopping cart |
| Cgi abuses |
Vp-asp shopsearch sql injection |
|
Checks for the presence of vp-asp |
| Cgi abuses |
Various dangerous cgi scripts |
Cve-1999-1072, cve-2002-0749, cve-2001-0135, cve-2002-0955, cve-2001-0562, cve-2002-0346, cve-2000-0923, cve-2001-0123 |
Checks for dangerous cgi scripts |
| Cgi abuses |
Verity ultraseek search request xss |
Cve-2005-0514 |
Checks verity ultraseek search request xss |
| Cgi abuses |
Virobot linux server remote buffer overflow vulnerability |
|
Checks for remote buffer overflow vulnerability in virobot linux server |
| Cgi abuses |
Virobot linux server filescan authentication bypass vulnerability |
Cve-2006-0864 |
Checks for authentication bypass vulnerability in virobot linux server's filescan component |
| Cgi abuses |
Videodb multiple vulnerabilities |
|
Checks for the version of videodb |
| Cgi abuses |
Viewcvs http response splitting |
Cve-2004-1062 |
Viewcvs flaw |
| Cgi abuses |
Vignette application portal information disclosure |
Cve-2004-0917 |
Request /portal/diag |
| Cgi abuses |
Vignette storyserver information disclosure |
Cve-2002-0385 |
Checks the version of the remote vignette storyserver |
| Cgi abuses |
Vignette storyserver tcl code injection |
|
Checks the version of the remote vignette storyserver |
| Cgi abuses |
Viruswall's catinfo overflow |
Cve-2001-0432 |
Overflow in catinfo |
| Cgi abuses |
Visnetic / merak mail server multiple flaws |
Cve-2005-4556, cve-2005-4557, cve-2005-4558, cve-2005-4559 |
Checks for visnetic mail server arbitrary script include |
| Cgi abuses |
Vssetcookie.exe vulnerability |
Cve-2002-0236 |
Checks for the vssetcookie.exe file |
| Cgi abuses |
Web-inf folder accessible |
Cve-2002-1855, cve-2002-1856, cve-2002-1857, cve-2002-1858, cve-2002-1859, cve-2002-1860, cve-2002-1861 |
Tests for web-inf folder access |
| Cgi abuses |
Webinsta cms templates_dir parameter remote file include vulnerability |
|
Tries to read a local file using webinsta cms |
| Cgi abuses |
Webalbum local file include vulnerability |
Cve-2006-1480 |
Checks for file includes in index.php |
| Cgi abuses |
Wf-chat user account disclosure |
|
Checks for the presence of !pwds.txt |
| Cgi abuses |
Whm autopilot multiple vulnerabilities |
Cve-2004-1420, cve-2004-1421, cve-2004-1422 |
Determines if whm autopilot can include third-party files |
| Cgi abuses |
Wps wps_shop.cgi remote command execution flaw |
Cve-2005-2290 |
Checks for wps wps_shop.cgi remote command execution flaw |
| Cgi abuses |
Web server load balancer detection |
|
Web server load balancer detection |
| Cgi abuses |
Web wiz forums database disclosure |
|
Checks for wwforum.mdb |
| Cgi abuses |
Web wiz site news / compulsize media cnu5 database disclosure |
|
Checks for news.mdb |
| Cgi abuses |
Web wiz txtusername parameter sql injection vulnerability |
Cve-2005-4606 |
Checks for txtusername parameter sql injection vulnerability in web wiz products |
| Cgi abuses |
Webapp apage.cgi remote command execution flaw |
Cve-2005-1628 |
Checks for apage.cgi remote command execution flaw |
| Cgi abuses |
Webapp detection |
|
Checks for presence of webapp |
| Cgi abuses |
Webapp directory traversal |
Cve-2004-1742 |
Checks for a directory traversal bug in webapp |
| Cgi abuses |
Webapp file disclosure vulnerability |
Cve-2005-0927 |
Checks for file disclosure vulnerability in webapp |
| Cgi abuses |
Webactive world readable log file |
Cve-2000-0642 |
Requests /active.log |
| Cgi abuses |
Webcalendar < 1.0.2 multiple vulnerabilities |
Cve-2005-3949, cve-2005-3961, cve-2005-3982, cve-2005-3982 |
Checks for multiple vulnerabilities in webcalendar < 1.0.2 |
| Cgi abuses |
Webcalendar detection |
|
Checks for presence of webcalendar |
| Cgi abuses |
Webcalendar sql injection |
Can-2004-1506, can-2004-1507, can-2004-1508, can-2004-1509, can-2004-1510 |
Checks for the presence of an sql injection in view_topic.php |
| Cgi abuses |
Webcalendar sql injection vulnerability |
Cve-2005-0474 |
Sends a malformed cookie to the remote host |
| Cgi abuses |
Webcalendar user account enumeration disclosure issue |
Cve-2006-2247 |
Checks for webcalendar user account enumeration disclosure weakness |
| Cgi abuses |
Webcalendar assistant_edit.php unauthorized access vulnerability |
Cve-2005-2320 |
Checks for assistant_edit.php unauthorized access vulnerability in webcalendar |
| Cgi abuses |
Webcalendar file reading |
|
Checks for file reading flaw in webcalendar |
| Cgi abuses |
Webcalendar includedir parameter remote file include vulnerability |
Cve-2005-2717 |
Checks for includedir parameter remote file include vulnerability in webcalendar |
| Cgi abuses |
Webgui < 6.7.3 multiple command execution vulnerabilities |
Cve-2005-2837 |
Checks for multiple command execution vulnerabilities in webgui < 6.7.3 |
| Cgi abuses |
Webgui < 6.7.6 arbitrary command execution |
Cve-2005-4694 |
Checks for arbitrary remote command execution in webgui < 6.7.6 |
| Cgi abuses |
Webgui unspecified vulnerability |
|
Checks the version of webgui |
| Cgi abuses |
Webhints remote command execution flaw |
Cve-2005-1950 |
Checks for webhints remote command execution flaw |
| Cgi abuses |
Weblibs file disclosure |
Can-2004-1221 |
Checks for the presence of a weblibs file disclosure |
| Cgi abuses |
Weblogic < 8.1 sp3 multiple vulnerabilities |
Cve-2004-2320 |
Checks the version of weblogic |
| Cgi abuses |
Weblogic clear-text passwords |
Cve-2003-1224, cve-2003-1225 |
Checks the version of weblogic |
| Cgi abuses |
Weblogic management servlet |
Cve-2003-1095 |
Checks the version of weblogic |
| Cgi abuses |
Weblogic source code disclosure |
Cve-2000-0682 |
Checks for weblogic file disclosures |
| Cgi abuses |
Webmatic security vulnerability |
|
Checks the version of webmatic |
| Cgi abuses |
Website pro reveals the physical file path of web directories |
Cve-2000-0066 |
Attempts to find the location of the remote web root |
| Cgi abuses |
Webspeed remote configuration |
Cve-2000-0127 |
Checks if webspeed can be administered |
| Cgi abuses |
Webstores 2000 browse_item_details.asp sql injection |
Cve-2004-0304 |
Webstores 2000 sql injection |
| Cgi abuses |
Webcart misconfiguration |
Cve-1999-0610 |
Checks for the webcart misconfiguration |
| Cgi abuses |
Webchat code injection |
|
Checks for the presence of webchat's defines.php |
| Cgi abuses |
Webfroot shoutbox file inclusion |
|
Checks for the presence of shoutbox.php |
| Cgi abuses |
Webmin / usermin arbitrary file disclosure vulnerability |
Cve-2006-3392 |
Tries to read a local file using miniserv.pl |
| Cgi abuses |
Webnews.exe vulnerability |
Cve-2002-0290 |
Checks for the webnews.exe file |
| Cgi abuses |
Website baker admin login sql injection vulnerability |
Cve-2005-4140 |
Checks for admin login sql injection vulnerability in website baker |
| Cgi abuses |
Websitepro buffer overflow |
Cve-2000-0623 |
Checks for websitepro |
| Cgi abuses |
Whatsup gold <= 8.04 multiple vulnerabilities |
|
Checks for multiple vulnerabilities in whatsup gold <= 8.04 |
| Cgi abuses |
Whatsup gold vulnerable cgi |
Cve-2004-0798 |
Checks for the presence of /_maincfgret.cgi |
| Cgi abuses |
Wihphoto file reading |
Cve-2003-1239 |
Checks for the presence of remotehtmlview.php |
| Cgi abuses |
Wikka local file include vulnerability |
|
Tries to read a local file in wikka |
| Cgi abuses |
Windmail.exe allows any user to execute arbitrary commands |
Cve-2000-0242 |
Checks for the presence of windmail.exe |
| Cgi abuses |
Winmail mail server information disclosure |
|
Checks for the presence of an information disclosure in winmail mail server |
| Cgi abuses |
Winmail server <= 4.2 build 0824 multiple vulnerabilities |
Cve-2005-3692, cve-2005-3811 |
Checks for multiple vulnerabilities in winmail server <= 4.2 build 0824 |
| Cgi abuses |
Winmail server unspecified webmail vulnerability |
Cve-2006-1250 |
Checks version of winmail server |
| Cgi abuses |
Woltlab burning board sql injection flaw |
Cve-2005-3369, cve-2006-1094 |
Checks sql injection flaw in woltlab burning board database module |
| Cgi abuses |
Woppoware postmaster <= 4.2.2 multiple vulnerabilities |
Cve-2005-1650, cve-2005-1651, cve-2005-1652, cve-2005-1653 |
Checks for multiple vulnerabilities in woppoware postmaster <= 4.2.2 |
| Cgi abuses |
Wordpress < 1.5.1 multiple vulnerabilities |
|
Checks for multiple vulnerabilities in wordpress < 1.5.1 |
| Cgi abuses |
Wordpress < 1.5.1.2 multiple vulnerabilities |
Cve-2005-1921 |
Checks for multiple vulnerabilities in wordpress < 1.5.1.2 |
| Cgi abuses |
Wordpress cross-site scripting / sql injection |
|
Checks for the presence of wordpress |
| Cgi abuses |
Wordpress detection |
|
Checks for presence of wordpress |
| Cgi abuses |
Wordpress http splitting vulnerability |
Cve-2004-1584 |
Checks for http response splitting vulnerability in wordpress < 1.2.1 |
| Cgi abuses |
Wordpress multiple flaws (xss, html injection, sql injection) |
|
Checks for multiple flaws in wordpress < 1.2.2 |
| Cgi abuses |
Wordpress cache_lastpostdate parameter php code injection vulnerability |
|
Checks for cache_lastpostdate parameter php code injection vulnerability in wordpress |
| Cgi abuses |
Wordpress cat_id sql injection vulnerability |
Cve-2005-1810 |
Checks for cat_id sql injection vulnerability in wordpress |
| Cgi abuses |
Wordpress code/sql injection |
|
Checks for the presence of wordpress |
| Cgi abuses |
Wordit logbook file disclosure vulnerability |
|
Checks for the presence of logbook.pl |
| Cgi abuses |
Wowbb <= 1.61 multiple flaws |
Cve-2004-2180, cve-2004-2181 |
Checks wowbb version |
| Cgi abuses |
Wowbb view_user.php sql injection flaw |
Cve-2005-1554 |
Checks for sql injection flaw in wowbb |
| Cgi abuses |
X-cart multiple vulnerabilities |
Cve-2005-1822, cve-2005-1823 |
Checks for multiple vulnerabilities in x-cart |
| Cgi abuses |
X7 chat help_file parameter local file include vulnerability |
Cve-2006-2156 |
Tries to read a local file using x7 chat |
| Cgi abuses |
X7 chat old_prefix sql injection vulnerability |
Cve-2006-3851 |
Checks for sql injection flaw in x7 chat |
| Cgi abuses |
Xmb forum < 1.9.2 multiple vulnerabilities |
Cve-2005-0885, cve-2005-2574, cve-2005-2575 |
Checks for multiple vulnerabilities in xmb forum < 1.9.2 |
| Cgi abuses |
Xmb sql injection |
|
Determine if xmb forums is vulnerable to a sql injection attack |
| Cgi abuses |
Xoops xoopsconfig parameter local file inclusion vulnerabilities |
Cve-2005-3680, cve-2005-3681 |
Checks for xoopsconfig parameter local file inclusion vulnerabilities in xoops |
| Cgi abuses |
Xaraya module parameter directory traversal vulnerability |
Cve-2005-3929 |
Checks for module parameter directory traversal vulnerability in xaraya |
| Cgi abuses |
Xerver < 4.20 multiple vulnerabilities |
Cve-2005-3293, cve-2005-4774 |
Checks for multiple vulnerabilities in xerver < 4.20 |
| Cgi abuses |
Xoops < 2.0.12 multiple vulnerabilities |
Cve-2005-2112, cve-2005-2113 |
Checks for multiple vulnerabilities in xoops < 2.0.12 |
| Cgi abuses |
Xoops detection |
|
Detects xoops |
| Cgi abuses |
Xoops incontent module directory traversal vulnerability |
|
Checks for the presence of xoops incontent module |
| Cgi abuses |
Xoops multiple vulnerabilities |
Cve-2002-0216, cve-2002-0217, cve-2002-1802 |
Checks for xoops |
| Cgi abuses |
Yabb information disclosure |
Cve-2000-0853 |
Checks for the presence of yabb.pl |
| Cgi abuses |
Yabb se command execution |
Cve-2000-1176 |
Determine if yabb se can be used to execute arbitrary commands |
| Cgi abuses |
Yabb xss and administrator command execution |
Cve-2004-2402, cve-2004-2403 |
Checks yabb.pl xss |
| Cgi abuses |
Yapig <= 0.9.5b multiple vulnerabilities |
Cve-2005-2736, cve-2005-4799 |
Checks for multiple vulnerabilities in yapig <= 0.9.5b |
| Cgi abuses |
Yapig multiple flaws |
Cve-2005-1881, cve-2005-1882, cve-2005-1883, cve-2005-1884, cve-2005-1885, cve-2005-1886 |
Checks for yapig version |
| Cgi abuses |
Yapig password protected directory access flaw |
|
Checks for yapig version |
| Cgi abuses |
Yapig remote server-side script execution vulnerability |
|
Checks for yapig version |
| Cgi abuses |
Yawcam directory traversal |
Cve-2005-1230 |
Checks for directory traversal in yawcam |
| Cgi abuses |
Yaws remote source code disclosure vulnerability |
Cve-2005-2008 |
Downloads the source of .yaws scripts |
| Cgi abuses |
Yusasp web asset manager vulnerability |
|
Checks for the presence of a yusasp web asset vulnerability |
| Cgi abuses |
Zanfi cms lite remote file include |
Cve-2004-2195 |
Determines if zanfi cms can include third-party files |
| Cgi abuses |
Zen cart admin_email parameter sql injection vulnerability |
Cve-2005-3996 |
Checks for admin_email parameter sql injection vulnerability in zen cart |
| Cgi abuses |
Zen cart autoloadconfig remote file include vulnerability |
|
Tries to read a local file with zen cart |
| Cgi abuses |
Zen cart custom sql injection vulnerability |
|
Checks for sql injection flaw in zen cart |
| Cgi abuses |
Zeroboard flaws |
Cve-2004-1419 |
Checks for zeroboard flaws |
| Cgi abuses |
Zeroboard flaws (2) |
Cve-2005-0380 |
Checks for zeroboard flaws |
| Cgi abuses |
Zeus shows the content of the cgi scripts |
Cve-2000-0149 |
Checks for zeus |
| Cgi abuses |
Zeus shows the content of the cgi scripts |
Cve-2000-0149 |
Checks for zeus |
| Cgi abuses |
Zixforum database disclosure |
|
Checks for zixforum.mdb |
| Cgi abuses |
Ad.cgi |
Cve-2001-0025 |
Checks for the presence of /cgi-bin/ad.cgi |
| Cgi abuses |
Admin.cgi overflow |
Cve-2002-0199 |
Overflows admin.cgi |
| Cgi abuses |
Aenovo database content disclosure vulnerability |
|
Checks for the presence of db file of aenovo |
| Cgi abuses |
Album.pl command execution |
|
Determines the version of album.pl |
| Cgi abuses |
Alibaba.pl |
Cve-1999-0885 |
Checks for the presence of /cgi-bin/alibaba.pl |
| Cgi abuses |
Anacondaclip cgi vulnerability |
Cve-2001-0593 |
Checks for the presence of anacondaclip.pl |
| Cgi abuses |
Aprox portal file disclosure |
Cve-2004-0237 |
Checks aprox portal |
| Cgi abuses |
Args.bat |
Cve-1999-1180 |
Checks for the presence of /cgi-dos/args.bat |
| Cgi abuses |
Artmedic_links5 file inclusion vulnerability |
|
Checks for artmedic_links5's php inclusion vulnerability |
| Cgi abuses |
Aspwebalbum sql injection |
Cve-2004-1552, cve-2004-1553 |
Sql injection |
| Cgi abuses |
Aspwebcalendar sql injection |
Cve-2004-1552, cve-2004-1553 |
Sql injection |
| Cgi abuses |
Auktion.cgi |
Cve-2001-0212 |
Checks for the presence of /cgi-bin/auktion.cgi |
| Cgi abuses |
Axis2400 webcams |
|
Reads the remote /var/log/messages |
| Cgi abuses |
B2 cafelog code injection |
Cve-2002-0734 |
Checks for the presence of gm-2-b2.php |
| Cgi abuses |
B2evolution title sql injection |
|
Checks for the presence of an sql injection in title parameter |
| Cgi abuses |
Bblog <= 0.7.4 multiple vulnerabilities |
Cve-2004-1570, cve-2004-1865, cve-2005-1309, cve-2005-1310 |
Checks for multiple vulnerabilities in bblog <= 0.7.4 |
| Cgi abuses |
Bblog sql injection flaw |
Cve-2004-1570 |
Check bblog version |
| Cgi abuses |
Bb-hist.sh |
Cve-1999-1462 |
Read arbitrary files using the cgi bb-hist.sh |
| Cgi abuses |
Bb-hostsvc.sh |
Cve-2000-0638 |
Read arbitrary files using the cgi bb-hostsvc.sh |
| Cgi abuses |
Bigconf |
Cve-1999-1550 |
Checks for the presence of /cgi-bin/bigconf.cgi |
| Cgi abuses |
Bizdb1-search.cgi located |
Cve-2000-0287 |
Determines the presence of cgi-bin/bizdb1-search.cgi |
| Cgi abuses |
Biztalk server flaws |
Cve-2003-0117, cve-2003-0118 |
Determines if biztalk is installed |
| Cgi abuses |
Boastmachine remote arbitrary file upload vulnerability |
Cve-2005-1580 |
Checks for remote arbitrary file upload vulnerability in boastmachine |
| Cgi abuses |
Bttlxeforum sql injection |
Cve-2003-0215 |
Uses a sql query as a password |
| Cgi abuses |
Cpanel backup file disclosure |
Cve-2004-1603 |
Checks for the version of cpanel |
| Cgi abuses |
Cpanel frontpage extension flaws |
Cve-2004-1603 |
Checks for the version of cpanel |
| Cgi abuses |
Cpanel login command execution |
Cve-2004-1769, cve-2004-1770, cve-2004-2308 |
Command injection |
| Cgi abuses |
Calendar_admin.pl |
Cve-2000-0432 |
Checks for the presence of /cgi-bin/calendar_admin.pl |
| Cgi abuses |
Cfwebstore sql injection |
Cve-2004-1806 |
Sql injection |
| Cgi abuses |
Cgi.rb |
Cve-2004-0983 |
Checks for the presence of cgi.rb |
| Cgi abuses |
Cgiwebupdate.exe vulnerability |
Cve-2001-1150 |
Checks for the cgiwebupdate.exe file |
| Cgi abuses |
Cgiforum |
Cve-2000-1171 |
Checks for the presence of /cgi-bin/cgiforum.pl |
| Cgi abuses |
Cgitest.exe buffer overrun |
Cve-2002-0128 |
Checks for the /cgi-bin/cgitest.exe buffer overrun |
| Cgi abuses |
Commerce.cgi |
Cve-2001-0210 |
Checks for the presence of /cgi-bin/commerce.cgi |
| Cgi abuses |
Counter.exe vulnerability |
Cve-1999-1030 |
Checks for the counter.exe file |
| Cgi abuses |
Counter.php file overwrite |
|
Determine if counter.php is present |
| Cgi abuses |
Cpanel remote command execution |
|
Executes /bin/id |
| Cgi abuses |
Cssearch.cgi |
Cve-2002-0495 |
Checks for the presence of /cgi-bin/cssearch.cgi |
| Cgi abuses |
Ctss.idc check |
|
Checks for the presence of /scripts/tools/ctss.idc |
| Cgi abuses |
Dcforum |
Cve-2001-0436 |
Checks for the presence of /cgi-bin/dcforum |
| Cgi abuses |
Ddicgi.exe vulnerability |
Cve-2000-0826 |
Checks for the ddicgi.exe file |
| Cgi abuses |
Directory pro web traversal |
Cve-2001-0780 |
Checks for the presence of /cgi-bin/directorypro.cgi |
| Cgi abuses |
Directory.php |
Cve-2002-0434 |
Checks for the presence of /directory.php |
| Cgi abuses |
Dotproject remote file include vulnerabilities |
Cve-2006-0754, cve-2006-0755 |
Checks for remote file include vulnerabilities in dotproject |
| Cgi abuses |
Dotproject docs directory information disclosure vulnerabilities |
Cve-2006-0756 |
Checks for docs directory information disclosure vulnerabilities in dotproject |
| Cgi abuses |
E107 <= 0.617 multiple vulnerabilities |
Cve-2005-2805 |
Checks for multiple vulnerabilities in e107 <= 0.617 |
| Cgi abuses |
E107 detection |
|
Checks for the presence of e107 |
| Cgi abuses |
E107 email injection vulnerability |
Cve-2006-2591 |
Tries to send arbitrary email with e107 |
| Cgi abuses |
E107 cookie sql injection vulnerability |
Cve-2006-2416 |
Tries to bypass authentication in e107 with a special cookie |
| Cgi abuses |
E107 database dump |
|
E107 flaw |
| Cgi abuses |
E107 eping plugin arbitrary code execution vulnerability |
Cve-2005-1949 |
Checks for arbitrary code execution vulnerability in e107 eping plugin |
| Cgi abuses |
E107 etrace plugin arbitrary code execution vulnerability |
Cve-2005-1966 |
Checks for arbitrary code execution vulnerability in e107 etrace plugin |
| Cgi abuses |
E107 resetcore.php sql injection |
Cve-2005-3521 |
E107 sql injection |
| Cgi abuses |
Ecommerce multiple vulnerabilities |
Cve-2005-2543, cve-2005-2544 |
Checks for multiple vulnerabilities in ecommerce |
| Cgi abuses |
Efiction < 2.0.2 multiple vulnerabilities |
Cve-2005-4167, cve-2005-4168, cve-2005-4169, cve-2005-4170, cve-2005-4171, cve-2005-4172, cve-2005-4173, cve-2005-4174 |
Checks for multiple vulnerabilities in efiction < 2.0.2 |
| Cgi abuses |
Eldapo cleartext passwords |
|
Checks for eldapo |
| Cgi abuses |
Epolicy orchestrator local information disclosure vulnerability |
Cve-2005-2554 |
Checks for local information disclosure vulnerability in epolicy orchestrator |
| Cgi abuses |
E_board arbitrary file reading |
|
Checks for e_board |
| Cgi abuses |
Empower cgi path |
Cve-2001-0224 |
Attempts to find the location of the remote web root |
| Cgi abuses |
Ezpublish config disclosure |
|
Determine if ezpublish config file can be retrieved |
| Cgi abuses |
Ezupload <= 2.2 multiple vulnerabilities |
Cve-2005-2616, cve-2005-4308, cve-2005-4309 |
Checks for multiple vulnerabilities in ezupload <= 2.2 |
| Cgi abuses |
Formmail.pl |
Cve-1999-0172 |
Checks for the presence of /cgi-bin/formmail.pl |
| Cgi abuses |
Foxweb cgi |
|
Checks for the presence of foxweb.exe or foxweb.dll |
| Cgi abuses |
Ftp.pl shows the listing of any dir |
Cve-2000-0674 |
Checks for the presence of /cgi-bin/ftp/ftp.pl |
| Cgi abuses |
Gcards multiple vulnerabilities |
Cve-2006-1346, cve-2006-1347, cve-2006-1348 |
Checks for directory transversal in gcards index.php script |
| Cgi abuses |
Gallery authentication bypass |
Cve-2004-0522 |
Checks for a bug in gallery |
| Cgi abuses |
Gallery code injection |
Cve-2001-1234 |
Checks for the presence of includes/needinit.php |
| Cgi abuses |
Gallery code injection (2) |
Cve-2003-1227 |
Checks for the presence of setup/index.php |
| Cgi abuses |
Gallery code injection (3) |
Cve-2004-2124 |
Checks for the presence of init.php |
| Cgi abuses |
Get32.exe vulnerability |
Cve-1999-0885 |
Checks for the presence of /cgi-bin/get32.exe |
| Cgi abuses |
Glimpse |
Cve-1999-0147 |
Checks for the presence of /cgi-bin/phf |
| Cgi abuses |
Guestbook tr3 password storage |
|
Checks for the presence of passwd.txt |
| Cgi abuses |
Guestbook.cgi |
Cve-1999-0237 |
Checks for the presence of /cgi-bin/guestbook.cgi |
| Cgi abuses |
Guestbook.pl |
Cve-1999-1053 |
Checks for the presence of /cgi-bin/guestbook.pl |
| Cgi abuses |
Hsx directory traversal |
Cve-2001-0253 |
Checks for the presence of /cgi-bin/hsx.cgi |
| Cgi abuses |
Ht://dig's htsearch potential exposure/dos |
Cve-2001-0834 |
Htsearch?-c/nonexistent |
| Cgi abuses |
Ht://dig's htsearch reveals web server path |
Can-2000-1191 |
Retrieve the real path using htsearch |
| Cgi abuses |
Htdig |
Cve-1999-0978, cve-2000-0208 |
Checks if htdig is vulnerable |
| Cgi abuses |
Htgrep |
Cve-2000-0832 |
Checks for the presence of /cgi-bin/htgrep |
| Cgi abuses |
I-gallery <= 3.3 multiple vulnerabilities |
Cve-2005-2033, cve-2005-2034 |
Checks for multiple vulnerabilities in i-gallery <= 3.3 |
| Cgi abuses |
I-mall.cgi |
Cve-2004-2275 |
Checks for the presence of i-mall.cgi |
| Cgi abuses |
Ixmail sql injection |
|
Checks for ixmail |
| Cgi abuses |
Ixmail arbitrary file upload |
|
Checks for ixmail |
| Cgi abuses |
Ibillpm.pl |
Cve-2001-0839 |
Checks for the presence of /cgi-bin/ibillpm.pl |
| Cgi abuses |
Icat |
Cve-1999-1069 |
Determines the presence of the 'icat' cgi |
| Cgi abuses |
Ideabox code injection |
|
Injects a path |
| Cgi abuses |
Idq.dll directory traversal |
Cve-2000-0126 |
Attempts to read an arbitrary file |
| Cgi abuses |
Iiprotect bypass |
|
Determines if iisprotect can be escaped |
| Cgi abuses |
Iiprotect sql injection |
Cve-2000-0188 |
Determines if iisprotect is password-protected |
| Cgi abuses |
Imagevue < 16.2 multiple vulnerabilities |
Cve-2006-0700, cve-2006-0701, cve-2006-0702, cve-2006-0703 |
Checks for unauthorized file upload vulnerability in imagevue |
| Cgi abuses |
Imagemap.exe |
Cve-1999-0951 |
Overflows /cgi-bin/imagemap.exe |
| Cgi abuses |
Info2www |
Cve-1999-0266 |
Checks for the presence of /cgi-bin/info2www |
| Cgi abuses |
Infosrch.cgi |
Cve-2000-0207 |
Checks for the presence of /cgi-bin/infosrch.cgi |
| Cgi abuses |
Inserter.cgi file inclusion and command execution vulnerabilities |
|
Checks for the presence of a file inclusion vulnerability |
| Cgi abuses |
Ion-p.exe vulnerability |
Cve-2002-1559 |
Checks for the ion-p.exe file |
| Cgi abuses |
Jj cgi |
Cve-1999-0260 |
Checks for the presence of /cgi-bin/jj |
| Cgi abuses |
Lighttpd script source disclosure vulnerability |
Cve-2006-0814 |
Checks version of lighttpd |
| Cgi abuses |
Mailnews.cgi |
Cve-2001-0271 |
Checks for the presence of mailnews.cgi |
| Cgi abuses |
Mailreader.com directory traversal and arbitrary command execution |
Cve-2002-1581, cve-2002-1582 |
Checks directory traversal & version number of mailreader.com software |
| Cgi abuses |
Miniportail cookie admin access |
Cve-2003-0272 |
Determine if miniportail can abused |
| Cgi abuses |
Mmstdod.cgi |
Cve-2001-0021 |
Checks for the presence of /cgi-bin/mmstdod.cgi |
| Cgi abuses |
Msmmask.exe |
|
Checks for the presence of /cgi-bin/msmmask.exe |
| Cgi abuses |
Multihtml cgi |
Cve-2000-0912 |
Checks for the presence of /cgi-bin/multihtml.pl |
| Cgi abuses |
Mvnforum activatemember cross-site scripting vulnerabilities |
Cve-2006-3245 |
Checks for an xss flaw in mvnforum's activatemember script |
| Cgi abuses |
Mybloggie multiple vulnerabilities |
Can-2005-1140, can-2005-1498, can-2005-1499, can-2005-1500 |
Checks for the presence of a mybloggie |
| Cgi abuses |
Myphpnuke phptonuke.php directory traversal |
Cve-2002-1913 |
Reads file through phptonuke.php |
| Cgi abuses |
Myphpcalendar injection |
|
Checks for the presence of contacts.php |
| Cgi abuses |
Myserver 0.4.3 / 0.7 directory traversal vulnerability |
|
Attempts to retrieve the path '/././..' |
| Cgi abuses |
Myserver post denial of service |
|
Test post dos on myserver |
| Cgi abuses |
Myphppagetool code injection |
|
Checks for the presence of index.html |
| Cgi abuses |
Myphpnuke code injection |
|
Checks for the presence of displaycategory.php |
| Cgi abuses |
Nbmember.cgi information disclosure |
|
Checks for nbmember.cgi |
| Cgi abuses |
Ncbook/book.cgi |
Cve-2001-1114 |
Checks for the presence of /cgi-bin/ncbook/book.cgi |
| Cgi abuses |
Ndcgi.exe vulnerability |
Cve-2001-0922 |
Checks for the ndcgi.exe file |
| Cgi abuses |
Netscape publishingxpert 2 psuser problem |
Cve-2000-1196 |
Checks if /psuser/pscoerrpage.htm reads any file |
| Cgi abuses |
Newdsn.exe check |
Cve-1999-0191 |
Checks for the presence of /scripts/tools/newdsn.exe |
| Cgi abuses |
News desk |
Cve-2001-0231 |
Checks for the presence of /cgi-bin/newsdesk.cgi |
| Cgi abuses |
Nph-publish.cgi |
Cve-1999-1177, cve-2001-0400 |
Checks for the presence of /cgi-bin/nph-publish.cgi |
| Cgi abuses |
Nph-test-cgi |
Cve-1999-0045 |
Checks for the presence of /cgi-bin/nph-test-cgi |
| Cgi abuses |
Ocportal remote file include |
Cve-2004-1592 |
Determines if ocportal can include third-party files |
| Cgi abuses |
Openwebmail command execution |
Cve-2002-1385 |
Determines the version of openwebmail |
| Cgi abuses |
Oscommerce unprotected admin directory |
|
Checks for unprotected admin directory in oscommerce |
| Cgi abuses |
Oscommerce directory traversal |
Cve-2004-2021 |
Determine if oscommerce is vulnerable to dir traversal |
| Cgi abuses |
Oscommerce readme_file parameter file disclosure vulnerability |
Cve-2005-2330 |
Tries to read a file with oscommerce |
| Cgi abuses |
Osticket <= 1.2.7 multiple vulnerabilities |
Cve-2005-1436, cve-2005-1437, cve-2005-1438, cve-2005-1439 |
Checks for multiple vulnerabilities in osticket <= 1.2.7 |
| Cgi abuses |
Osticket <= 1.3.1 multiple vulnerabilities |
Cve-2005-2153, cve-2005-2154 |
Checks version of osticket |
| Cgi abuses |
Osticket attachment code execution vulnerability |
Cve-2004-0613 |
Checks for attachment code execution vulnerability in osticket |
| Cgi abuses |
Osticket attachment viewing vulnerability |
Cve-2004-0613 |
Checks for attachment viewing vulnerability in osticket |
| Cgi abuses |
Osticket large attachment vulnerability |
Cve-2004-0614 |
Checks for large attachment vulnerability in osticket |
| Cgi abuses |
Osticket setup.php accessibility |
|
Checks accessibility of osticket's setup.php |
| Cgi abuses |
Overflow.cgi detection |
|
Checks for the presence of a cgi |
| Cgi abuses |
Ows-bin |
Cve-2000-0169 |
Checks if ows-bin is vulnerable |
| Cgi abuses |
P-news admin access |
|
Checks for the presence of p-news.php |
| Cgi abuses |
Pafaq multiple vulnerabilities |
Cve-2005-0475, cve-2005-2011, cve-2005-2012, cve-2005-2013, cve-2005-2014 |
Checks for multiple vulnerabilities in pafaq |
| Cgi abuses |
Pafiledb detection |
|
Checks for presence of pafiledb |
| Cgi abuses |
Pafiledb sql injection |
|
Determine if pafiledb is vulnerable to a sql injection |
| Cgi abuses |
Pafiledb password hash disclosure |
Cve-2004-1219 |
Determines the version of pafiledb |
| Cgi abuses |
Panews detection |
|
Checks for presence of panews |
| Cgi abuses |
Panews input validation vulnerabilities |
Cve-2005-0646, cve-2005-0647 |
Detects input validation vulnerabilities in panews |
| Cgi abuses |
Panews admin_setup.php remote code execution vulnerability |
|
Checks for remote code execution in admin_setup.php in panews |
| Cgi abuses |
Panews showpost parameter cross-site scripting vulnerability |
Cve-2005-0485 |
Checks version of panews |
| Cgi abuses |
Pagelog.cgi |
Cve-2000-0940 |
Checks for the presence of /cgi-bin/pagelog.cgi |
| Cgi abuses |
Pals-cgi |
Cve-2001-0216 |
Checks for the presence of /cgi-bin/pals-cgi |
| Cgi abuses |
Perl interpreter can be launched as a cgi |
Cve-1999-0509 |
Checks for the presence of /cgi-bin/perl |
| Cgi abuses |
Perlcal |
Cve-2001-0463 |
Checks for the presence of /cgi-bin/cal_make.pl |
| Cgi abuses |
Pfdispaly |
Cve-1999-0270 |
Checks for the presence of /cgi-bin/pfdispaly |
| Cgi abuses |
Phf |
Cve-1999-0067 |
Checks for the presence of /cgi-bin/phf |
| Cgi abuses |
Phorum's common.php |
|
Checks for the presence of phorum's common.php |
| Cgi abuses |
Php 4.2.x malformed post |
Cve-2002-0986 |
Checks for version of php |
| Cgi abuses |
Php 4.3.0 |
Cve-2003-0097 |
Checks for version of php |
| Cgi abuses |
Php < 4.3.3 |
|
Checks for version of php |
| Cgi abuses |
Php imap overflow |
|
Checks for version of php |
| Cgi abuses |
Php php_variables memory disclosure |
|
Checks for version of php |
| Cgi abuses |
Php post file uploads |
Cve-2002-0081 |
Checks for version of php |
| Cgi abuses |
Php arbitrary file upload |
|
Checks for version of php |
| Cgi abuses |
Php file upload |
Cve-2000-0860 |
Checks for version of php |
| Cgi abuses |
Php log |
Cve-2000-0967 |
Checks for version of php |
| Cgi abuses |
Php mail injection |
Cve-2005-3883 |
Checks for version of php vunerable to email injection |
| Cgi abuses |
Php safemode |
Cve-2001-1246 |
Checks for version of php |
| Cgi abuses |
Php socket_iovec_alloc() integer overflow |
Cve-2003-0166 |
Checks for version of php |
| Cgi abuses |
Php-ping count parameter command execution vulnerability |
|
Detect php ping code execution |
| Cgi abuses |
Php-proxima file reading |
|
Determines owl is installed |
| Cgi abuses |
Php.cgi |
Cve-1999-0238 |
Checks for the presence of /cgi-bin/php.cgi |
| Cgi abuses |
Php.cgi buffer overrun |
Cve-1999-0058 |
Checks for the /cgi-bin/php.cgi buffer overrun |
| Cgi abuses |
Php4 multiple flaws |
Cve-2002-1396, cve-2003-0442 |
Checks for version of php |
| Cgi abuses |
Php4/5 vulnerabilities |
|
Checks for version of php |
| Cgi abuses |
Php4/5 vulnerabilities |
|
Checks for version of php |
| Cgi abuses |
Php4/5 vulnerabilities |
|
Checks for version of php |
| Cgi abuses |
Php4/5 vulnerabilities |
|
Checks for version of php |
| Cgi abuses |
Php4/5 vulnerabilities |
|
Checks for version of php |
| Cgi abuses |
Php4/5 vulnerabilities |
|
Checks for version of php |
| Cgi abuses |
Php4/5 vulnerabilities |
|
Checks for version of php |
| Cgi abuses |
Php4/5 vulnerabilities |
|
Checks for version of php |
| Cgi abuses |
Php4/5 vulnerabilities |
|
Checks for version of php |
| Cgi abuses |
Php4/5 vulnerabilities |
|
Checks for version of php |
| Cgi abuses |
Php4/5 vulnerabilities |
|
Checks for version of php |
| Cgi abuses |
Php4/5 vulnerabilities |
|
Checks for version of php |
| Cgi abuses |
Php4/5 vulnerabilities |
|
Checks for version of php |
| Cgi abuses |
Phpadsnew / phppgads < 2.0.6 multiple vulnerabilities |
Cve-2005-2498, cve-2005-2635, cve-2005-2636 |
Checks for multiple vulnerabilities in phpadsnew / phppgads < 2.0.6 |
| Cgi abuses |
Phpadsnew multiple vulnerabilities |
Can-2005-0791 |
Checks for the presence of a xss in phpadsnew |
| Cgi abuses |
Phpadsnew xml-rpc library remote code injection vulnerability |
Cve-2005-1921 |
Checks for remote code injection vulnerability in phpadsnew xml-rpc library |
| Cgi abuses |
Phpalbum data_dir parameter remote file include vulnerability |
Cve-2006-1839 |
Tries to read /etc/passwd using phpalbum |
| Cgi abuses |
Phpbb < 2.0.11 |
|
Check for the version of phpbb |
| Cgi abuses |
Phpbb <= 2.0.15 remote code execution vulnerability |
Cve-2005-2086 |
Checks for remote code execution vulnerability in phpbb <= 2.0.15 |
| Cgi abuses |
Phpbb <= 2.0.16 nested bbcode url tags cross-site scripting vulnerability |
Cve-2005-2161 |
Checks for nested bbcode url tags cross-site scripting vulnerability in phpbb <= 2.0.16 |
| Cgi abuses |
Phpbb <= 2.0.17 multiple vulnerabilities |
Cve-2005-3415, cve-2005-3416, cve-2005-3417, cve-2005-3418, cve-2005-3419, cve-2005-3420 |
Checks for multiple vulnerabilities in phpbb <= 2.0.17 |
| Cgi abuses |
Phpbb component phpbb_root_path parameter remote file include vulnerabilities |
|
Tries to read a local file using the phpbb component |
| Cgi abuses |
Phpbb detection |
|
Check for phpbb version |
| Cgi abuses |
Phpbb fetch all < 2.0.12 |
|
Check for phpbb fetch all version |
| Cgi abuses |
Phpbb file upload script vulnerability |
Cve-2005-1047 |
Checks for file upload script vulnerability in phpbb |
| Cgi abuses |
Phpbb knowledge base module sql injection vulnerability |
Cve-2005-1196 |
Checks for sql injection vulnerability in phpbb knowledge base module |
| Cgi abuses |
Phpbb photo album module <= 2.0.53 multiple vulnerabilities |
Cve-2005-1114, cve-2005-1115 |
Checks for multiple vulnerabilities in phpbb photo album module <= 2.0.53 |
| Cgi abuses |
Phpbb remote php file include vulnerability |
|
Checks for the presence of admin_cash.php |
| Cgi abuses |
Phpbannerexchange template class local file include vulnerability |
Cve-2006-1201 |
Tries to read a file using phpbannerexchange's template class |
| Cgi abuses |
Phpbugtracker bug.php sql injection |
|
Checks for the presence of an sql injection bug in phpbugtracker |
| Cgi abuses |
Phpcoin < 1.2.2 2005-12-13 fix-file multiple vulnerabilities |
Cve-2005-4211, cve-2005-4212, cve-2005-4213 |
Checks for multiple vulnerabilities in phpcoin < 1.2.2 2005-12-13 fix-file |
| Cgi abuses |
Phpcommunitycalendar multiple vulnerabilities |
|
Checks for the presence of a phpcommunitycalendar |
| Cgi abuses |
Phpdig vulnerability |
|
Checks the version of phpmyadmin |
| Cgi abuses |
Phpdocumentor <= 1.3.0 rc4 local and remote file inclusion vulnerability |
Cve-2005-4593 |
Check if phpdocumentor is vulnerable to remote file inclusion flaws |
| Cgi abuses |
Phpformgenerator arbitrary file upload vulnerability |
|
Tries to execute arbitrary code using phpformgenator |
| Cgi abuses |
Phpgedview code injection vulnerability |
|
Detect phpgedview include() vulnerability |
| Cgi abuses |
Phpgedview arbitrary file reading |
Cve-2004-0127, cve-2004-0128 |
Checks aprox portal |
| Cgi abuses |
Phpldapadmin anonymous bind security bypass vulnerability |
Cve-2005-2654 |
Checks for anonymous bind security bypass vulnerability in phpldapadmin |
| Cgi abuses |
Phpldapadmin custom_welcome_page parameter file include vulnerability |
Cve-2005-2792, cve-2005-2793 |
Checks for custom_welcome_page parameter file include vulnerability in phpldapadmin |
| Cgi abuses |
Phplistpro returnpath remote file include vulnerabilities |
Cve-2006-1749 |
Checks for file includes in phplistpro's config.php |
| Cgi abuses |
Phpmyadmin < 2.6.4-pl3 multiple vulnerabilities |
Cve-2005-3300, cve-2005-3301 |
Checks for multiple vulnerabilities in phpmyadmin < 2.6.4-pl3 |
| Cgi abuses |
Phpmyadmin detection |
|
Checks for the presence of phpmyadmin |
| Cgi abuses |
Phpmyadmin multiple remote vulnerabilities |
Cve-2004-1147, cve-2004-1148 |
Checks the version of phpmyadmin |
| Cgi abuses |
Phpmyadmin arbitrary file reading (2) |
Cve-2004-0129 |
Checks phpmyadmin |
| Cgi abuses |
Phpmyadmin arbitrary files reading |
Cve-2001-0478 |
Checks for the presence of sql.php |
| Cgi abuses |
Phpmyadmin import_blacklist variable overwriting vulnerability |
Cve-2005-4079 |
Tries to read a local file using phpmyadmin |
| Cgi abuses |
Phpmyadmin multiple flaws |
|
Checks for the presence of phpmyadmin |
| Cgi abuses |
Phpmyadmin remote command execution |
Cve-2004-2630 |
Checks the version of phpmyadmin |
| Cgi abuses |
Phpmyagenda rootagenda parameter file include vulnerability |
Cve-2006-2009 |
Checks for a possible file inclusion flaw in phpmyagenda |
| Cgi abuses |
Phpmychat information disclosure |
|
Checks for the presence of an information disclosure in phpmychat |
| Cgi abuses |
Phpmyexplorer dir traversal |
Cve-2001-1168 |
Phpmyexplorer dir traversal |
| Cgi abuses |
Phpmyfaq < 1.5.2 multiple vulnerabilities |
|
Checks for multiple vulnerabilities in phpmyfaq < 1.5.2 |
| Cgi abuses |
Phpmyfaq detection |
|
Checks for presence of phpmyfaq |
| Cgi abuses |
Phpmyfaq image upload authentication bypass |
Cve-2004-2257 |
Check the version of phpmyfaq |
| Cgi abuses |
Phpmyfaq action parameter arbitrary file disclosure vulnerability |
Cve-2004-2255 |
Check the version of phpmyfaq |
| Cgi abuses |
Phpmyfaq username sql injection vulnerability |
Cve-2005-0702 |
Checks for username sql injection vulnerability in phpmyfaq |
| Cgi abuses |
Phppgads http response splitting vulnerability |
|
Checks for the presence of phppgads/phpadsnew |
| Cgi abuses |
Phppgadmin arbitrary files reading |
Cve-2001-0479 |
Checks for the presence of sql.php |
| Cgi abuses |
Phppgadmin formlanguage parameter local file include vulnerability |
Cve-2005-2256 |
Checks for formlanguage parameter directory traversal vulnerability in phppgadmin |
| Cgi abuses |
Phprpc library remote code execution vulnerability |
Cve-2006-1032 |
Checks for remote code execution in phprpc library |
| Cgi abuses |
Phpsecurepages cfgprogdir variable file include vulnerabilities |
Cve-2005-2251 |
Checks for cfgprogdir variable file include vulnerabilities in phpsecurepages |
| Cgi abuses |
Phpsysinfo < 2.4.1 multiple vulnerabilities |
Cve-2003-0536, cve-2005-0870, cve-2005-3347, cve-2005-3348 |
Checks for multiple vulnerabilities in phpsysinfo < 2.4.1 |
| Cgi abuses |
Phpwebftp language parameter local file include vulnerability |
Cve-2006-1813 |
Tries to read /etc/passwd using phpwebftp |
| Cgi abuses |
Phpweblog cross site scripting |
Can-2005-0698 |
Checks for the presence of a phpweblog xss |
| Cgi abuses |
Phpwebnotes t_path_core parameter file include vulnerability |
Cve-2005-2775 |
Checks for t_path_core parameter file include vulnerability in phpwebnotes |
| Cgi abuses |
Phpwebsite <= 0.10.1 multiple vulnerabilities |
|
Detects multiple vulnerabilities in phpwebsite <= 0.10.1 |
| Cgi abuses |
Phpwebsite arbitrary php file upload as image file vulnerability |
Cve-2005-0565 |
Detects arbitrary php file upload as image file vulnerability in phpwebsite |
| Cgi abuses |
Phpwebsite detection |
|
Checks for the presence of phpwebsite |
| Cgi abuses |
Phpwebsite search module sql injection vulnerability |
Cve-2005-4792 |
Detects search module sql injection vulnerability in phpwebsite |
| Cgi abuses |
Phpwebsite hub_dir parameter local file include vulnerability |
Cve-2006-1819 |
Tries to read /etc/passwd using phpwebsite |
| Cgi abuses |
Phpwebsite multiple flaws |
|
Sql injection and more. |
| Cgi abuses |
Phpwebthings forum parameter sql injection vulnerabilities |
Cve-2005-3585, cve-2005-4218 |
Check if phpwebthings is vulnerable to sql injection attacks |
| Cgi abuses |
Phpauction admin authentication bypass |
|
Attempts to bypass phpauction administrative authentication |
| Cgi abuses |
Phpbb-auction phpbb_root_path parameter remote file include vulnerability |
Cve-2006-2245 |
Tries to read /etc/passwd using phpbb-auction |
| Cgi abuses |
Phpdig code injection vulnerability |
Cve-2004-0068 |
Detect phpdig code injection vuln |
| Cgi abuses |
Phpinfo.php |
|
Checks for the presence of phpinfo.php |
| Cgi abuses |
Phpix remote command execution |
|
Detect phpix cmd execution |
| Cgi abuses |
Phpping code execution |
|
Checks for the presence of phpping |
| Cgi abuses |
Phpwcms multiple vulnerabilities |
Cve-2005-3789 |
Checks for multiple vulnerabilities in phpwcms |
| Cgi abuses |
Phpwcms spaw_root parameter remote file include vulnerability |
Cve-2006-2519 |
Tries to read a local file using phpwcms |
| Cgi abuses |
Ping.asp |
|
Checks for the presence of ping.asp |
| Cgi abuses |
Pmachine code injection |
|
Checks for the presence of lib.inc.php |
| Cgi abuses |
Pmachine code injection (2) |
Cve-2005-0513 |
Checks for the presence of mail_autocheck.php |
| Cgi abuses |
Popper_mod |
Cve-2002-0513 |
Checks if popper_mod is vulnerable |
| Cgi abuses |
Printenv |
|
Checks for the presence of /cgi-bin/printenv |
| Cgi abuses |
Processit |
|
Checks for the presence of /cgi-bin/processit |
| Cgi abuses |
Quickstore traversal |
Cve-1999-0607, cve-2000-1188 |
Checks for the presence of /cgi-bin/quickstore.cgi |
| Cgi abuses |
Quickstore traversal (2) |
|
Checks for the presence of /cgi-bin/quickstore.cgi |
| Cgi abuses |
Readfile.tcl |
|
Checks for readfile.tcl |
| Cgi abuses |
Readmsg.php detection |
Cve-2001-1408 |
Checks for the presence of cobal cube webmail |
| Cgi abuses |
Rot13sj.cgi |
|
Checks for rot13sj.cgi |
| Cgi abuses |
Rpm_query cgi |
Cve-2000-0192 |
Checks for rpm_query |
| Cgi abuses |
Sblog keyword parameter sql injection vulnerability |
Cve-2006-2189 |
Checks for keyword parameter sql injection in sblog |
| Cgi abuses |
Sdbsearch.cgi |
Cve-2001-1130 |
Determines the presence of the sdbsearch.cgi |
| Cgi abuses |
Sendtemp.pl |
Cve-2001-0272 |
Checks for the presence of /cgi-bin/sendtemp.pl |
| Cgi abuses |
Sgdynamo_path |
|
Sgdynamo.exe path disclosure |
| Cgi abuses |
Sglmerchant information disclosure vulnerability |
Can-2001-1019 |
Sglmerchant information disclosure vulnerability |
| Cgi abuses |
Smb2www installed |
|
Smb2www command execution |
| Cgi abuses |
Smb2www remote command execution |
Cve-2002-1342 |
Smb2www command execution |
| Cgi abuses |
Sojourn.cgi |
Cve-2000-0180 |
Checks for the presence of /cgi-bin/sojourn.cgi |
| Cgi abuses |
Spin_client.cgi buffer overrun |
|
Checks for the /cgi-bin/spin_client.cgi buffer overrun |
| Cgi abuses |
Store.cgi |
Cve-2001-0305 |
Checks for the presence of /cgi-bin/store.cgi |
| Cgi abuses |
Technote's main.cgi |
Cve-2001-0075 |
Checks for the presence of /technote/main.cgi |
| Cgi abuses |
Tektronix's _ncl_items.shtml |
Cve-2001-0484 |
Checks for the presence of _ncl_*.shtml |
| Cgi abuses |
Test-cgi |
Cve-1999-0070 |
Checks for the presence of /cgi-bin/test-cgi |
| Cgi abuses |
Texi.exe information disclosure |
|
Checks for texis.exe |
| Cgi abuses |
Texi.exe path disclosure |
Cve-2002-0266 |
Checks for texis.exe |
| Cgi abuses |
Textcounter.pl |
Cve-1999-1479 |
Checks for the presence of /cgi-bin/textcounter.pl |
| Cgi abuses |
Toendacms < 0.6.2.1 multiple vulnerabilities |
Cve-2005-3550, cve-2005-3551, cve-2005-4422 |
Checks for multiple vulnerabilities in toendacms < 0.6.2.1 |
| Cgi abuses |
Tst.bat cgi vulnerability |
Cve-1999-0885 |
Checks for the presence of /cgi-bin/tst.bat |
| Cgi abuses |
Ttcms code injection |
|
Attempts to include a file |
| Cgi abuses |
Ttawebtop |
Cve-2001-0805 |
Checks for the presence of /cgi-bin/ttawebtop.cgi |
| Cgi abuses |
Ttforum multiple flaws |
|
Determines if ttforum is vulnerable to code injection |
| Cgi abuses |
Typo3 arbitrary file reading |
|
Reads /etc/passwd |
| Cgi abuses |
Uploader.exe |
Cve-1999-0177 |
Checks for the presence of /cgi-win/uploader.exe |
| Cgi abuses |
Ustorekeeper file reading |
Cve-2001-0466 |
Checks for the presence of ustorekeeper.pl |
| Cgi abuses |
Vbulletin <= 3.0.9 multiple vulnerabilities |
Cve-2005-3019, cve-2005-3020 |
Checks for multiple vulnerabilities in vbulletin <= 3.0.9 |
| Cgi abuses |
Vbulletin detection |
|
Checks for the presence of vbulletin |
| Cgi abuses |
Vbulletin email field cross-site scripting vulnerability |
Cve-2006-1040 |
Checks version number of vbulletin |
| Cgi abuses |
Vbulletin forumdisplay.php remote command execution vulnerability |
Cve-2005-0429 |
Checks for vbulletin forumdisplay.php remote command execution vulnerability |
| Cgi abuses |
Vbulletin init.php unspecified vulnerability |
|
Checks the version of vbulletin |
| Cgi abuses |
Vbulletin misc.php php script code execution vulnerability |
|
Executes phpinfo() on the remote host |
| Cgi abuses |
Vbulletin sql injection issue |
|
Checks the version of vbulletin |
| Cgi abuses |
Vbulletin last10.php sql injection |
|
Checks for the presence of an sql and last10 |
| Cgi abuses |
Vbulletin's calender command execution vulnerability |
Cve-2001-0475 |
Vbulletin's calender command execution vulnerability |
| Cgi abuses |
Vcard match parameter remote file inclusion vulnerability |
Cve-2005-3332 |
Checks for match parameter remote file inclusion vulnerability in vcard |
| Cgi abuses |
Vtiger multiple flaw |
Cve-2005-3818, cve-2005-3819, cve-2005-3820, cve-2005-3821, cve-2005-3822, cve-2005-3823, cve-2005-3824 |
Checks for authentication bypass in vtiger |
| Cgi abuses |
Vbulletin calendar sql injection vulnerability |
Cve-2004-0036 |
Detect vbulletin calendar sql injection |
| Cgi abuses |
View_source |
Cve-1999-0174 |
Checks for the presence of /cgi-bin/view_source |
| Cgi abuses |
Viewpage.php arbitrary file reading |
|
Viewpage.php is vulnerable to an exploit which lets an attacker view any file that the cgi/httpd user has access to. |
| Cgi abuses |
Viralator |
Cve-2001-0849 |
Checks for the presence of /cgi-bin/viralator.cgi |
| Cgi abuses |
Vpasswd.cgi |
|
Checks for the presence of vpasswd.cgi |
| Cgi abuses |
Vpopmail.php command execution |
|
Determines the version of vpopmail.php |
| Cgi abuses |
W-agora <= 4.2.0 multiple vulnerabilities |
|
Checks for multiple vulnerabilities in w-agora <= 4.2.0 |
| Cgi abuses |
W-agora site parameter remote directory traversal flaw |
Cve-2005-2648 |
Checks for directory traversal in w-agora |
| Cgi abuses |
W-agora inc_dir parameter remote file include vulnerabilities |
|
Tries to read a local file using w-agora |
| Cgi abuses |
W-agora remote directory traversal flaw |
|
Checks for directory traversal in w-agora |
| Cgi abuses |
W3-msql overflow |
Cve-2000-0012 |
Overflow in w3-msql |
| Cgi abuses |
Way-board |
Cve-2001-0214 |
Checks for the presence of /cgi-bin/way-board |
| Cgi abuses |
Weberp configuration file remote access |
|
Determines if weberp is installed |
| Cgi abuses |
Webadmin.dll detection |
Cve-2003-0471 |
Checks for the presence of webadmin.dll |
| Cgi abuses |
Webadmin.php detection |
|
Try to read /etc/passwd through webadmin.php |
| Cgi abuses |
Webcart.cgi |
Cve-2001-1502 |
Detects webcart.cgi |
| Cgi abuses |
Webdist.cgi |
Cve-1999-0039 |
Checks for the presence of webdist.cgi |
| Cgi abuses |
Webdriver |
|
Checks for the presence of webdriver |
| Cgi abuses |
Webgais |
Cve-1999-0176 |
Checks for the presence of /cgi-bin/webgais |
| Cgi abuses |
Websendmail |
Cve-1999-0196 |
Checks for the presence of /cgi-bin/websendmail |
| Cgi abuses |
Webspirs.cgi |
Cve-2001-0211 |
Checks for the presence of webspirs.cgi |
| Cgi abuses |
Webwho plus |
Cve-2000-0010 |
Checks if webwho.pl is vulnerable |
| Cgi abuses |
Whois_raw |
Cve-1999-1063 |
Checks if whois_raw.cgi is vulnerable |
| Cgi abuses |
Wpoison (nasl version) |
|
Some common sql injection techniques |
| Cgi abuses |
Wrap |
Cve-1999-0149 |
Checks for the presence of /cgi-bin/wrap |
| Cgi abuses |
Wwwboard passwd.txt |
Cve-1999-0953 |
Checks for the presence of /wwwboard/passwd.txt |
| Cgi abuses |
Wwwwais |
Cve-2001-0223 |
Checks for the presence of /cgi-bin/wwwwais |
| Cgi abuses |
X-news 1 |
Cve-2002-1656 |
Check if version of x-news 1.x is installed |
| Cgi abuses |
Xoops nocommon parameter local file include vulnerability |
Cve-2006-2516 |
Tries to read a local file using xoops |
| Cgi abuses |
Zentrack files reading |
Cve-2002-2158 |
Checks for the presence of zentrack's index.php |
| Cgi abuses |
Zentrack code injection |
Cve-2002-2158 |
Checks for the presence of zentrack's index.php |
| Cgi abuses |
Zml.cgi directory traversal |
Cve-2001-1209 |
Zml.cgi is vulnerable to an exploit which lets an attacker view any file that the cgi/httpd user has access to. |
| Cgi abuses : xss |
punbb url quote tag xss |
|
Checks for punbb version |
| Cgi abuses : xss |
12planet chat server one2planet.infolet.infoservlet xss |
Can-2004-0678 |
Checks for the presence of an xss bug in 12planet chat server |
| Cgi abuses : xss |
Asp portal xss |
|
Checks for asp portal |
| Cgi abuses : xss |
Asp-dev xm forum img tag script injection vulnerability |
Cve-2005-1008 |
Asp-dev xm forum img tag script injection vulnerability |
| Cgi abuses : xss |
Asp.net cross site scripting |
Cve-2003-0223 |
Tests for asp.net css |
| Cgi abuses : xss |
Asprunner multiple flaws |
Cve-2004-2057, cve-2004-2058, cve-2004-2059, cve-2004-2060 |
Check for multiple flaws in asprunner |
| Cgi abuses : xss |
Atutor cross site scripting vulnerability |
Cve-2005-2649 |
Checks for xss in login.php |
| Cgi abuses : xss |
Advanced guestbook user-agent html injection vulnerability |
|
Checks for user-agent html injection vulnerability in advanced guestbook |
| Cgi abuses : xss |
Agora cgi cross site scripting |
Cve-2001-1199 |
Tests for agora cgi cross site scripting |
| Cgi abuses : xss |
Apache jakarta cross-site scripting vulnerability |
|
Checks xss in apache jakarta lucene. |
| Cgi abuses : xss |
Apache tomcat /servlet cross site scripting |
Cve-2002-0682 |
Tests for apache tomcat /servlet xss bug |
| Cgi abuses : xss |
Apache tomcat dos device name xss |
|
Tests for apache tomcat dos device name xss bug |
| Cgi abuses : xss |
Apache tomcat troubleshooter servlet installed |
Cve-2002-2006 |
Tests whether the apache tomcat troubleshooter servlet is installed |
| Cgi abuses : xss |
Argosoft mail server pro webmail server cross-site scripting vulnerabilities |
Cve-2006-0978 |
Checks version of argosoft mail server pro banner |
| Cgi abuses : xss |
Auction deluxe xss |
Cve-2002-0257 |
Checks for auction.pl |
| Cgi abuses : xss |
Autoindex search parameter cross-site scripting vulnerability |
Cve-2005-2163 |
Checks for search parameter cross-site scripting vulnerability in autoindex |
| Cgi abuses : xss |
Aztek forum xss |
|
Checks xss in aztek forum |
| Cgi abuses : xss |
Bmforum multiple xss flaws |
|
Checks for xss in topic.php |
| Cgi abuses : xss |
Bandmin xss |
Cve-2003-0416 |
Checks for bandmin |
| Cgi abuses : xss |
Basilix content-type xss vulnerability |
|
Checks for content-type xss vulnerability in basilix |
| Cgi abuses : xss |
Basit cms cross site scripting bugs |
|
Determine if basit cms is vulnerable to xss attack |
| Cgi abuses : xss |
Beanwebb's guestbook |
|
Checks for the presence of admin.php |
| Cgi abuses : xss |
Blog torrent cross site scripting |
|
Looks for a xss in blog torrent. |
| Cgi abuses : xss |
Bookreview multiple cross-site scripting vulnerabilities |
Cve-2005-1782 |
Checks for unathentication access to admin.asp |
| Cgi abuses : xss |
Breakcalendar xss |
|
Checks for breakcalendar version |
| Cgi abuses : xss |
Bugzilla internal error cross site scripting vulnerability |
Cve-2004-1061 |
Checks for the presence of bugzilla |
| Cgi abuses : xss |
Burning board pms.php cross-site scripting vulnerability |
Cve-2005-1327 |
Checks for cross-site scripting vulnerability in burning board's pms.php script |
| Cgi abuses : xss |
Cgiemail's cross site scripting vulnerability (cgicso) |
|
Determine if a remote host is vulnerable to the cgicso vulnerability |
| Cgi abuses : xss |
Cmsimple index.php guestbook xss |
|
Checks for xss in guestbook module in index.php |
| Cgi abuses : xss |
Cmsimple index.php search xss |
Cve-2005-2392 |
Checks for xss in search field in index.php |
| Cgi abuses : xss |
Cpg dragonfly multiple cross-site scripting vulnerabilities |
Cve-2005-0914 |
Checks for multiple cross-site scripting vulnerabilities in cpg dragonfly |
| Cgi abuses : xss |
Cvstrac cross-site scripting vulnerability |
Cve-2004-1146 |
Checks for cvstrac version |
| Cgi abuses : xss |
Cart32 getlatestbuilds xss |
Can-2004-0675 |
Checks for the presence of an xss bug in cart32 |
| Cgi abuses : xss |
Chora common-footer.inc cross-site scripting vulnerability |
|
Checks for cross-site scripting vulnerability in chora common-footer.inc |
| Cgi abuses : xss |
Citrix nfuse_application parameter xss |
Cve-2002-0504 |
Test citrix nfuse_application parameter xss |
| Cgi abuses : xss |
Citrix web interface xss |
Cve-2003-1157 |
Checks for citrix web interface cross site scripting vulnerability |
| Cgi abuses : xss |
Cjoverkill trade.php xss |
Cve-2004-2193 |
Check cjoverkill version |
| Cgi abuses : xss |
Claroline xss |
|
Checks if claroline is vulnerable to a xss attack |
| Cgi abuses : xss |
Cleartrust xss |
|
Checks for cleartrust xss |
| Cgi abuses : xss |
Comersus cart cross-site scripting vulnerability |
Can-2004-0681, can-2004-0682 |
Checks for the presence of an xss bug in comersus |
| Cgi abuses : xss |
Comersus cart username field html injection vulnerability |
Cve-2005-1010 |
Checks for username field html injection vulnerability in comersus cart |
| Cgi abuses : xss |
Comersus cart comersus_searchitem.asp cross-site scripting vulnerability |
Cve-2005-1188 |
Checks for comersus_searchitem.asp cross-site scripting vulnerability in comersus cart |
| Cgi abuses : xss |
Coolphp multiple vulnerabilities |
Cve-2004-1599, cve-2004-1601 |
Checks for coolphp |
| Cgi abuses : xss |
Coppermine gallery exif data script insertion vulnerability |
Cve-2005-2676 |
Checks version number of coppermine gallery |
| Cgi abuses : xss |
Coppermine photo gallery x-forwarded-for logging vulnerability |
Cve-2005-1172 |
Checks for x-forwarded-for logging vulnerability in coppermine photo gallery |
| Cgi abuses : xss |
Cross-site scripting vulnerabilities in phpmyadmin libraries and themes |
Cve-2005-0543 |
Detects cross-site scripting vulnerabilities in phpmyadmin libraries and themes |
| Cgi abuses : xss |
Cubecart settings.inc.php cross-site scripting and path disclosure vulnerabilities |
Cve-2005-0606, cve-2005-0607 |
Checks version of cubecart |
| Cgi abuses : xss |
Cutenews xss |
|
Checks for the presence of show_archives.php |
| Cgi abuses : xss |
Cutenews index.php xss |
Cve-2004-1659 |
Checks for the presence of index.php |
| Cgi abuses : xss |
Cutenews show_news.php xss |
Can-2004-0660 |
Checks for the presence of an xss bug in cutenews |
| Cgi abuses : xss |
Dcp-portal code injection |
|
Determine if dcp-portal is vulnerable to an injection attack |
| Cgi abuses : xss |
Dcp-portal xss |
Cve-2004-2511, cve-2004-2512 |
Check for dcp-portal xss flaws |
| Cgi abuses : xss |
Devoybb multiple flaws |
Cve-2004-2177, cve-2004-2178 |
Checks devoybb version |
| Cgi abuses : xss |
Ecommerce corp. online store kit more.php injection vulnerability |
Cve-2004-0300, cve-2004-0301 |
More.php mosql injection |
| Cgi abuses : xss |
Faq-o-matic fom.cgi xss |
Cve-2002-0230, cve-2002-2011 |
Checks faq-o-matic xss |
| Cgi abuses : xss |
Fastcgi samples cross site scripting |
|
Tests for fastcgi samples cross site scripting |
| Cgi abuses : xss |
Fusetalk forum xss |
Cve-2004-1594 |
Checks xss in fusetalk |
| Cgi abuses : xss |
Fusebox fuseaction parameter cross-site scripting vulnerability |
Cve-2005-2480 |
Checks for fuseaction parameter cross-site scripting vulnerability in fusebox |
| Cgi abuses : xss |
Gallery exif data script insertion vulnerability |
Cve-2005-2734 |
Checks for exif data script insertion vulnerability in gallery |
| Cgi abuses : xss |
Geronimo cal2.jsp example cross-site scripting vulnerability |
Cve-2006-0254 |
Checks for cal2.jsp cross-site scripting vulnerability in geronimo |
| Cgi abuses : xss |
Gforge <= 4.5 multiple cross-site scripting vulnerabilities |
Cve-2005-2430 |
Checks for multiple cross-site scripting vulnerabilities in gforge <= 4.5 |
| Cgi abuses : xss |
Gosmart message board multiple flaws |
Cve-2004-1588, cve-2004-1589 |
Checks gosmart message board flaws |
| Cgi abuses : xss |
Goollery multiple xss |
Cve-2004-2245 |
Checks for the presence of goollery xss flaw in viewpic.php |
| Cgi abuses : xss |
Gossamer links < 3.0.4 multiple cross-site scripting vulnerabilities |
|
Checks for multiple cross-site scripting vulnerabilities in gossamer links < 3.0.4 |
| Cgi abuses : xss |
Gossamer links url parameter cross-site scripting vulnerability |
Cve-2005-1492 |
Checks for url parameter cross-site scripting vulnerability in gossamer links |
| Cgi abuses : xss |
Greymatter gm.cgi html injection flaw |
|
Checks the version of the remote greymatter |
| Cgi abuses : xss |
Groupwise webaccess cross-site scripting vulnerability |
Cve-2005-2276 |
Checks for cross-site scripting vulnerability in groupwise webaccess |
| Cgi abuses : xss |
Http trace method enabled |
Cve-2004-2320 |
Http trace xss attack |
| Cgi abuses : xss |
Horde 3.0 xss |
Cve-2005-0378 |
Checks for xss flaws in horde 3.0 |
| Cgi abuses : xss |
Horde help subsystem xss |
|
Checks for help subsystem xss flaw in horde |
| Cgi abuses : xss |
Horde imp status.php3 xss |
Cve-2002-0181 |
Checks for status.php3 xss flaw in horde imp |
| Cgi abuses : xss |
Horde parent page title cross-site scripting vulnerability |
Cve-2005-0961 |
Checks for parent page title xss vulnerability in horde |
| Cgi abuses : xss |
Horde common-footer.inc cross-site scripting vulnerability |
|
Checks for cross-site scripting vulnerability in horde common-footer.inc |
| Cgi abuses : xss |
Horde url parameter cross-site scripting vulnerabilities |
Cve-2006-3548, cve-2006-3549 |
Tries to exploit an xss flaw in horde's services/go.php |
| Cgi abuses : xss |
Iis 5.0 sample app vulnerable to cross-site scripting attack |
|
Iis 5.0 sample app vulnerable to cross-site scripting attack |
| Cgi abuses : xss |
Iis xss via 404 error |
Cve-2002-0148, cve-2002-0150 |
Tests for iis xss via 404 errors |
| Cgi abuses : xss |
Iis xss via idc error |
|
Tests for iis xss via idc errors |
| Cgi abuses : xss |
Imp content-type xss vulnerability |
Cve-2004-0584 |
Checks for content-type xss vulnerability in imp |
| Cgi abuses : xss |
Imp html mime viewer xss vulnerabilities |
|
Checks for html mime viewer xss vulnerabilities in imp |
| Cgi abuses : xss |
Imp html+time xss vulnerability |
Cve-2004-1443 |
Checks for html+time vulnerability in imp |
| Cgi abuses : xss |
Imp common-footer.inc cross-site scripting vulnerability |
Cve-2005-1319 |
Checks for cross-site scripting vulnerability in imp common-footer.inc |
| Cgi abuses : xss |
Imp_mime_viewer_html class xss vulnerabilities |
|
Imp_mime_viewer_html class is vulnerable to xss attacks |
| Cgi abuses : xss |
Ilohamail email header html injection vulnerability |
|
Checks for email header html injection vulnerability in ilohamail |
| Cgi abuses : xss |
Ilohamail email message cross-site scripting vulnerabilities |
Cve-2005-1120 |
Checks for email message cross-site scripting vulnerabilities in ilohamail |
| Cgi abuses : xss |
Inmail/inshop xss |
Cve-2004-1196, cve-2004-1197 |
Checks xss in inmail and inshop |
| Cgi abuses : xss |
Infinity cgi exploit scanner |
|
Checks for the presence of nph-exploitscanget.cgi |
| Cgi abuses : xss |
Interspire articlelive 2005 xss vulnerability |
Can-2005-0881 |
Checks for the presence of a articlelive xss |
| Cgi abuses : xss |
Invision power board color sml tag script injection vulnerability |
Cve-2005-0477 |
Detect invision power board color sml tag script injection |
| Cgi abuses : xss |
Invision power board iframe html injection vulnerability |
Cve-2005-0886 |
Checks for iframe html injection vulnerability in invision power board |
| Cgi abuses : xss |
Invision power board referer field xss |
Cve-2004-1578 |
Checks for invision power board xss |
| Cgi abuses : xss |
Invision power board act parameter cross-site scripting vulnerability |
Cve-2005-1443 |
Checks for act parameter cross-site scripting vulnerability in invision power board |
| Cgi abuses : xss |
Invision power board pop parameter xss |
Cve-2004-2279 |
Checks for the presence of an xss bug in invision powerboard |
| Cgi abuses : xss |
Jaws html injection vulnerabilities |
Cve-2005-1231, cve-2005-1800 |
Checks for html injection vulnerabilities in jaws |
| Cgi abuses : xss |
Jshop cross-site scripting vulnerability |
Can-2004-2084 |
Checks for the presence of an xss bug in jshop |
| Cgi abuses : xss |
Jelsoft vbulletin xss |
Cve-2004-2076 |
Checks for jelsoft vbulletin |
| Cgi abuses : xss |
Justice guestbook |
|
Checks for the presence of cfooter.php3 |
| Cgi abuses : xss |
Kayako esupport cross-site scripting vulnerability |
Cve-2005-0487 |
Determines the presence of kayako esupport |
| Cgi abuses : xss |
Kayako esupport index.php multiple cross-site scripting vulnerabilities |
Cve-2005-0842 |
Checks for multiple cross-site scripting vulnerabilities in kayako esupport's index.php |
| Cgi abuses : xss |
Kayako esupport sql injection and cross-site-scripting |
Can-2004-1412, can-2004-1413 |
Checks for the presence of an sql and xss in kayako |
| Cgi abuses : xss |
Keene digital media server xss |
|
Checks xss in keene server |
| Cgi abuses : xss |
Lotus domino src and basetarget xss |
Cve-2005-3015 |
Checks lotus domino xss |
| Cgi abuses : xss |
Lotus domino xss |
Cve-2001-1161 |
Checks for lotus domino xss |
| Cgi abuses : xss |
Lotus domino xss (2) |
Cve-2004-1621 |
Checks for lotus domino xss |
| Cgi abuses : xss |
Mpc softweb guestbook database disclosure |
|
Checks for mpcsoftware_guestdata.mdb |
| Cgi abuses : xss |
Mvnforum search cross-site scripting vulnerability |
Cve-2005-1183 |
Mvnforum search cross-site scripting vulnerability |
| Cgi abuses : xss |
Mailreader remote html injection vulnerability |
Cve-2005-0386 |
Checks for remote html injection vulnerability in mailreader |
| Cgi abuses : xss |
Mambo site server 4.0.10 xss |
Cve-2003-1203 |
Determine if mambo site server is vulnerable to xss attack |
| Cgi abuses : xss |
Mambo site server xss and remote arbitrary code execution |
Cve-2003-1204 |
Determine if mambo site server is vulnerable to xss attack and remote flaw |
| Cgi abuses : xss |
Mambo site server itemid parameter xss |
Cve-2004-2072 |
Determine if mambo site server is vulnerable to xss attack |
| Cgi abuses : xss |
Mambo site server mos_change_template xss |
Cve-2004-1825 |
Determine if mambo site server is vulnerable to xss attack |
| Cgi abuses : xss |
Mantis multiple unspecified xss |
|
Checks for the version of mantis |
| Cgi abuses : xss |
Mediawiki page move template cross-site scripting vulnerability |
Cve-2005-2215 |
Checks for page move template cross-site scripting vulnerability in mediawiki |
| Cgi abuses : xss |
Mediawiki page template cross-site scripting vulnerability |
Cve-2005-1888 |
Checks for page template cross-site scripting vulnerability in mediawiki |
| Cgi abuses : xss |
Microsoft frontpage xss |
Cve-2000-0746 |
Checks for the presence of a frontpage xss |
| Cgi abuses : xss |
Mnemo common-footer.inc cross-site scripting vulnerability |
Cve-2005-1320 |
Checks for cross-site scripting vulnerability in mnemo common-footer.inc |
| Cgi abuses : xss |
Moniwiki xss |
Cve-2004-1632 |
Test for xss flaw in moniwiki |
| Cgi abuses : xss |
Moodle < 1.3.3 |
Cve-2004-0725, cve-2004-2233 |
Determines if moodle is older than 1.3.3 |
| Cgi abuses : xss |
Moodle xss |
Can-2004-1978 |
Checks for the presence of an xss bug in moodle |
| Cgi abuses : xss |
Moodle post.php xss |
Cve-2004-1711 |
Determines if moodle is vulnerable to post.php xss |
| Cgi abuses : xss |
Multiple cubecart xss vulnerabilities |
Cve-2005-3152 |
Checks for xss in index.php |
| Cgi abuses : xss |
Multiple metadot vulnerabilities |
|
Detect metadot sql injection |
| Cgi abuses : xss |
Multiple vulnerabilities in iwebnegar |
Cve-2004-1402 |
Sql injection |
| Cgi abuses : xss |
My little forum xss vulnerability |
|
Detect my little forum xss |
| Cgi abuses : xss |
Myabracadaweb cross site scripting |
|
Determine if a remote host is vulnerable to xss attack |
| Cgi abuses : xss |
Mysql eventum multiple flaws |
|
Test flaws in mysql eventum |
| Cgi abuses : xss |
Nag common-footer.inc cross-site scripting vulnerability |
Cve-2005-1322 |
Checks for cross-site scripting vulnerability in nag common-footer.inc |
| Cgi abuses : xss |
Neomail sort parameter cross-site scripting vulnerability |
|
Checks for sort parameter cross-site scripting vulnerability in neomail |
| Cgi abuses : xss |
Neoteris ive xss |
Cve-2003-0217 |
Checks for a xss is neoteris ive |
| Cgi abuses : xss |
Netcommerce sql injection |
Cve-2001-0319 |
Determine if the remote host is vulnerable to cross site scripting vulnerability |
| Cgi abuses : xss |
Network query tool xss |
|
Checks for the presence of an xss bug in nqt |
| Cgi abuses : xss |
Noah grey greymatter gm-comments.cgi html injection vulnerability |
|
Checks for the version of greymatter |
| Cgi abuses : xss |
Novell groupwise webaccess information disclosure |
|
Checks groupware xss |
| Cgi abuses : xss |
Novell groupwise webaccess xss |
|
Checks groupware xss |
| Cgi abuses : xss |
Nuked-klan function execution |
Cve-2003-1238 |
Executes phpinfo() |
| Cgi abuses : xss |
Nuked-klan cross site scripting bugs |
Cve-2003-1238 |
Determine if nuked-klan is vulnerable to xss attack |
| Cgi abuses : xss |
Oscommerce contact_us.php cross-site scripting vulnerability |
|
Determines the presence of oscommerce |
| Cgi abuses : xss |
Ocean12 guestbook xss |
|
Checks for ocean12 guestbook |
| Cgi abuses : xss |
Open webmail content-type xss |
|
Checks for content-type xss flaw in open webmail |
| Cgi abuses : xss |
Open webmail logindomain parameter cross-site scripting vulnerability |
Cve-2005-0445 |
Checks for logindomain parameter cross-site scripting vulnerability in open webmail |
| Cgi abuses : xss |
Open webmail sessionid parameter cross-site scripting vulnerability |
Cve-2005-2863 |
Checks for sessionid parameter cross-site scripting vulnerability in open webmail |
| Cgi abuses : xss |
Openbb xss |
|
Tests for xss flaw in openbb board.php |
| Cgi abuses : xss |
Oracle 9ias isqlplus xss |
|
Test for the possibility of an cross-site-scripting xss attack in oracle9i isqlplus |
| Cgi abuses : xss |
Oracle 9ias mod_plsql cross site scripting |
Cve-2002-0569 |
Tests for oracle 9ias mod_plsql cross site scripting |
| Cgi abuses : xss |
Oracle report server xss |
Cve-2005-0873 |
Tests for a xss in oracle reporting server |
| Cgi abuses : xss |
Outlook web access url injection |
Cve-2005-0420 |
The remote host is running microsoft outlook web access 2003 and is vulnerable to url injection. |
| Cgi abuses : xss |
Php-csl cross site scripting vulnerability |
Cve-2004-1746 |
Checks for the presence of an xss bug in php-csl |
| Cgi abuses : xss |
Php-fusion bbcode img tag script injection vulnerability |
Cve-2005-0692 |
Checks for bbcode img tag script injection vulnerability in php-fusion |
| Cgi abuses : xss |
Php-fusion bbcode url tag script injection vulnerability |
Cve-2005-2783 |
Checks for bbcode url tag script injection vulnerability in php-fusion |
| Cgi abuses : xss |
Php-fusion homepage address xss |
|
Checks the version of the remote php-fusion |
| Cgi abuses : xss |
Phpmyadmin < 2.6.4 cross-site scripting vulnerabilities |
Cve-2005-2869 |
Checks for multiple cross-site scripting vulnerabilities in phpmyadmin < 2.6.4 |
| Cgi abuses : xss |
Phpmyadmin convcharset cross-site scripting vulnerability |
Cve-2005-0992 |
Checks for convcharset cross-site scripting vulnerability in phpmyadmin |
| Cgi abuses : xss |
Phpmydirectory review.php multiple cross-site scripting vulnerabilities |
Cve-2005-0896 |
Checks for multiple cross-site scripting vulnerabilities in phpmydirectory's review.php |
| Cgi abuses : xss |
Phpsysinfo multiple cross-site scripting vulnerabilities |
Cve-2005-0870 |
Checks for multiple cross-site scripting vulnerabilities in phpsysinfo |
| Cgi abuses : xss |
Phpay information disclosure |
|
Checks for the presence of phpinfo.php |
| Cgi abuses : xss |
Phproxy xss |
|
Checks for the presence of a phproxy xss |
| Cgi abuses : xss |
Password protect sql injection |
Can-2004-1647, can-2004-1648 |
Tests for the password protect injection |
| Cgi abuses : xss |
Phorum http response splitting vulnerability |
Cve-2005-0843 |
Checks for http response splitting vulnerability in phorum |
| Cgi abuses : xss |
Phorum multiple subject and attachment cross-site scripting and html injection vulnerabilities |
Cve-2005-0783, cve-2005-0784 |
Checks for multiple subject and attachment cross-site scripting and html injection vulnerabilities in phorum |
| Cgi abuses : xss |
Phorum search cross site scripting vulnerability |
Cve-2004-2242 |
Checks for the presence of an xss bug in phorum |
| Cgi abuses : xss |
Phorum register.php cross-site scripting |
|
Checks for cross-site scripting vulnerability in phorum's register.php |
| Cgi abuses : xss |
Photoaday cross-site scripting vulnerability |
|
Checks for the presence of an xss bug in photoaday |
| Cgi abuses : xss |
Photopost php pro exif data script insertion vulnerability |
Cve-2005-2737 |
Checks for exif data script insertion vulnerability in photopost php pro |
| Cgi abuses : xss |
Phpgroupware main screen message script injection flaw |
|
Checks for phpgroupware version |
| Cgi abuses : xss |
Phpgroupware xss |
Cve-2004-0875 |
Checks for phpgroupware version |
| Cgi abuses : xss |
Phpgroupware xss and sql injection issues |
Cve-2004-1383, cve-2004-1384 |
Checks the version of phpgroupware |
| Cgi abuses : xss |
Pinnacle cart xss |
Cve-2005-1130 |
Checks xss in pinnacle cart |
| Cgi abuses : xss |
Pinnacle showcenter skin xss |
Cve-2004-1700 |
Checks skin xss in pinnacle showcenter |
| Cgi abuses : xss |
Pod.board forum_details.php cross site scripting |
|
Checks for pod.board xss |
| Cgi abuses : xss |
Post-nuke news module xss |
|
Determines if post-nuke is vulnerable to xss |
| Cgi abuses : xss |
Post-nuke sql injection |
|
Determines if post-nuke is vulnerable to xss |
| Cgi abuses : xss |
Postnuke reviews xss |
|
Determines if post-nuke is vulnerable to xss |
| Cgi abuses : xss |
Postnuke op and module parameters cross-site scripting vulnerabilities |
Cve-2005-1049 |
Checks for op and module parameters cross-site scripting vulnerabilities in postnuke |
| Cgi abuses : xss |
Profitcode payprocart cross-site scripting vulnerability |
|
Checks payprocart |
| Cgi abuses : xss |
Psnews xss |
Cve-2004-1665 |
Check psnews xss flaws |
| Cgi abuses : xss |
Psychostats login parameter cross-site scripting |
Can-2004-1417 |
Checks for the presence of a psychostats xss |
| Cgi abuses : xss |
Pubcookie login server cross-site scripting vulnerabilities |
Cve-2006-1392, cve-2006-1393, cve-2006-1394 |
Tries to inject arbitrary script into pubcookie login server |
| Cgi abuses : xss |
Punbb img tag client side scripting xss |
|
Checks for punbb version |
| Cgi abuses : xss |
Punbb install.php xss |
|
Checks for punbb install.php xss |
| Cgi abuses : xss |
Punbb profile.php input validation vulnerabilities |
Cve-2005-0818 |
Detects input validation vulnerabilities in punbb's profile.php |
| Cgi abuses : xss |
Punbb profile.php xss |
|
Checks for punbb profile.php xss |
| Cgi abuses : xss |
Rsa security rsa authentication agent for web xss |
Cve-2005-1118 |
Test for xss flaw in rsa security rsa authentication agent for web |
| Cgi abuses : xss |
Remotelyanywhere cross site scripting |
|
Detect remotelyanywhere www css |
| Cgi abuses : xss |
Swsoft plesk reloaded cross site scripting vulnerability |
|
Checks for the presence of an xss bug in plesk reloaded |
| Cgi abuses : xss |
Sambar server administrative interface multiple xss |
|
Determine if sambar server is prone to xss attack |
| Cgi abuses : xss |
Sambar xss |
|
Tests for xss attacks |
| Cgi abuses : xss |
Sandsurfer cross site scripting vulnerabilities |
Cve-2004-2550 |
Checks for sandsurfer |
| Cgi abuses : xss |
Sawmill < 7.1.14 cross-site scripting vulnerability |
Cve-2005-2950 |
Checks for cross-site scripting vulnerability in sawmill < 7.1.14 |
| Cgi abuses : xss |
|