Nessus 的 CGI abuses 系列

ID名称严重性
80862ALCASAR 检测
info
80554Lexmark MarkVision Enterprise GfdFileUploadServerlet RCE 漏洞
critical
80475WordPress 的多个幻灯片插件“img”参数本地文件包含漏洞
medium
80442Dell iDRAC 产品 IPMI 任意命令注入漏洞
medium
80358Centreon“insertLog()”函数 RCE
high
80357Centreon < 2.5.4 多种漏洞
high
80334IBM 网络安全保护 XGS 默认凭据
critical
80332PHP 5.6.x < 5.6.4“process_nested_data”RCE
high
80331PHP 5.5.x < 5.5.20“process_nested_data”RCE
high
80330PHP 5.4.x < 5.4.36“process_nested_data”RCE
high
80199IBM 网络安全保护 XGS 远程代码执行 (swg21690823)(受信任的攻击)
medium
80226Centreon GetXMLTrapsForVendor.php“mnftr_id”参数 SQL 注入
critical
80225Centreon 默认管理员密码
high
80224Centreon < 2.5.3 多种漏洞
critical
80223Centreon 2.3.3 < 2.4.0 menuXML.php“menu”参数 SQL 注入
medium
80221Centreon 检测
info
80121MediaWiki < 1.19.22 / 1.22.14 / 1.23.7 多种漏洞
high
80118Symantec Web Gateway < 5.2.2 认证操作系统命令注入 (SYM14-016)
medium
80084Visual Mining NetCharts Server 默认凭据 (Web UI)
high
80083Visual Mining NetCharts Server 任意文件上传
high
79797phpMyAdmin 4.0.x < 4.0.10.7 / 4.1.x < 4.1.14.8 / 4.2.x < 4.2.13.1 多种漏洞 (PMASA-2014-17 - PMASA-2014-18)
medium
79724Splunk Enterprise 5.0.x < 5.0.10 / 6.1.x < 6.1.4 多种漏洞
medium
79723Splunk Enterprise 6.0.x < 6.0.7 多种漏洞 (POODLE)
low
79722Splunk Enterprise 6.0.x < 6.0.6 多种漏洞
medium
79719HP SiteScope SSLv3 Padding Oracle 降级旧式加密漏洞 (POODLE)
low
79691IBM WebSphere Portal 7.0.0.x < 7.0.0.2 CF29 多种漏洞
high
80082Visual Mining NetCharts Server Web UI 检测
info
79641Citrix CloudPlatform 默认凭据
high
79640Citrix CloudPlatform 未授权的访问漏洞 (CTX140989)
low
79599phpMyAdmin 4.0.x < 4.0.10.6 / 4.1.x < 4.1.14.7 / 4.2.x < 4.2.12 多种漏洞 (PMASA-2014-13 - PMASA-2014-16)
medium
79585Cisco TelePresence Conductor 默认凭据 (Web UI)
high
79582Cisco TelePresence Conductor WebUI 检测
info
79437WordPress < 3.7.5/3.8.5/3.9.3/4.0.1 多种漏洞
medium
79421Creative Contact Form Plugin for WordPress 文件上传 RCE
high
79420Creative Contact Form Component for Joomla! 文件上传 RCE
critical
79386Drupal 6.x < 6.34 / 7.x < 7.34 多种漏洞
medium
79248PHP 5.6.x < 5.6.3“donote”DoS
medium
79247PHP 5.5.x < 5.5.19“donote”DoS
medium
79246PHP 5.4.x < 5.4.35“donote”DoS
medium
79216IBM WebSphere Portal 8.5.0 < 8.5.0 CF02 多种漏洞
high
78917SolarWinds Log and Event Manager 不受支持的版本检测
critical
78916SolarWinds Log and Event Manager 默认凭据
critical
78915SolarWinds Log and Event Manager < 6.0.1 HyperSQL 远程代码执行
high
78913SolarWinds Log and Event Manager 检测
info
78912Joomla! 不支持的版本检测
critical
78893Citrix NetScaler 不明远程代码执行 (CTX200206)
high
78859Jenkins < 1.583 / 1.565.3 和 Jenkins Enterprise 1.532.x / 1.554.x / 1.565.x < 1.532.10.1 / 1.554.10.1 / 1.565.3.1 多种漏洞
critical
78828Cisco Prime Security Manager GNU Bash 环境变量处理命令注入 (cisco-sa-20140926-bash) (Shellshock)
critical
78776Oracle Business Transaction Management“FlashTunnelService”“WriteToFile”消息 RCE
critical
78775Oracle Business Transaction Management 检测
info