Formated by GeSHi
--------------------------------------------------------------------------- - Nikto 1.35/1.36 - www.cirt.net + Target IP: 82.119.226.108 + Target Hostname: www.spojenaskola.sk + Target Port: 80 + Start Time: Sun Feb 25 15:26:30 2007 --------------------------------------------------------------------------- - Scan is dependent on "Server" string which can be faked, use -g to override + Server: Apache + Server does not respond with '404' for error messages (uses '200'). + This may increase false-positives. + All CGI directories 'found', use '-C none' to test none - Retrieved X-Powered-By header: PHP/4.4.4 + /robots.txt - contains 6 'disallow' entries which should be manually viewed (added to mutation file lists) (GET). + PHP/4.4.4 appears to be outdated (current is at least 5.1.4) + /.DS_Store - Apache on Mac OSX will serve the .DS_Store file, which contains sensitive information. Configure Apache to ignore this file or upgrade to a newer version. (GET) + /.FBCIndex - This file son OSX contains the source of the files in the directory. http://www.securiteam.com/securitynews/5LP0O005FS.html (GET) + /docs/ - May give list of installed software (GET) + /examples/servlet/AUX - Apache Tomcat versions below 4.1 may be vulnerable to DoS by repeatedly requesting this file. (GET) + /icons/ - Directory indexing is enabled, it should only be enabled for specific directories (if required). If indexing is not used, the /icons directory should be removed. (GET) + /index.html.ca - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.cz.iso8859-2 - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.de - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.dk - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.ee - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.el - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.en - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.es - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.et - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.fr - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.he.iso8859-8 - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.hr.iso8859-2 - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.it - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.ja.iso2022-jp - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.kr.iso2022-kr - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.ltz.utf8 - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + Over 20 "OK" messages, this may be a by-product of the + server answering all requests with a "200 OK" message. You should + manually verify your results. + /index.html.lu.utf8 - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.nl - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.nn - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.no - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.po.iso8859-2 - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.pt-br - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.pt - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.ru.cp-1251 - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.ru.cp866 - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.ru.iso-ru - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.ru.koi8-r - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.ru.utf8 - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.se - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.tw.Big5 - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.tw - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /index.html.var - Apache default foreign language file found. All default files should be removed from the web server as they may give an attacker additional system information. (GET) + /jservdocs/ - Default Apache JServ docs should be removed. (GET) + /manual/images/ - Apache 2.0 directory indexing is enabled, it should only be enabled for specific directories (if required). Apache's manual should be removed and directory indexing disabled. (GET) + /server-info - This gives a lot of Apache information. Comment out appropriate line in httpd.conf or restrict access to allowed hosts. (GET) + /site/eg/source.asp - This asp (installed with Apache::ASP) allows attackers to upload files to the server. Upgrade to 1.95 or higher. CAN-2000-0628. (GET) + /soap/servlet/soaprouter - Oracle 9iAS SOAP components allow anonymous users to deploy applications by default. (GET) + /soapConfig.xml - Oracle 9iAS configuration file found - see bugrtraq #4290. (GET) + /stronghold-info - Redhat Stronghold from versions 2.3 up to 3.0 disclose sensitive information. This gives information on configuration. CAN-2001-0868. (GET) + /stronghold-status - Redhat Stronghold from versions 2.3 up to 3.0 disclose sensitive information. CAN-2001-0868. (GET) + /tomcat-docs/index.html - Default Apache Tomcat documentation found. (GET) + /XSQLConfig.xml - Oracle 9iAS configuration file found - see bugrtraq #4290. (GET) + /admin/config.php - PHP Config file may contain database IDs and passwords. (GET) + /adm/config.php - PHP Config file may contain database IDs and passwords. (GET) + /My_eGallery/public/displayCategory.php - My_eGallery prior to 3.1.1.g are vulnerable to a remote execution bug via SQL command injection. displayCategory.php calls imageFunctions.php without checking URL/location arguments. (GET) + /postnuke/My_eGallery/public/displayCategory.php - My_eGallery prior to 3.1.1.g are vulnerable to a remote execution bug via SQL command injection. displayCategory.php calls imageFunctions.php without checking URL/location arguments. (GET) + /postnuke/html/My_eGallery/public/displayCategory.php - My_eGallery prior to 3.1.1.g are vulnerable to a remote execution bug via SQL command injection. displayCategory.php calls imageFunctions.php without checking URL/location arguments. (GET) + /modules/My_eGallery/public/displayCategory.php - My_eGallery prior to 3.1.1.g are vulnerable to a remote execution bug via SQL command injection. displayCategory.php calls imageFunctions.php without checking URL/location arguments. (GET) + /phpBB/My_eGallery/public/displayCategory.php - My_eGallery prior to 3.1.1.g are vulnerable to a remote execution bug via SQL command injection. displayCategory.php calls imageFunctions.php without checking URL/location arguments. (GET) + /forum/My_eGallery/public/displayCategory.php - My_eGallery prior to 3.1.1.g are vulnerable to a remote execution bug via SQL command injection. displayCategory.php calls imageFunctions.php without checking URL/location arguments. (GET) + /_layouts/alllibs.htm - Microsoft SharePoint Portal and Team Serices vulnerable to NT or NTLM authentication bypass on Win2000 SP4 using IE 6.x. Bugtraq 03-11-19 post by arkanian@hacker.am (GET) + /_layouts/settings.htm - Microsoft SharePoint Portal and Team Serices vulnerable to NT or NTLM authentication bypass on Win2000 SP4 using IE 6.x. Bugtraq 03-11-19 post by arkanian@hacker.am (GET) + /_layouts/userinfo.htm - Microsoft SharePoint Portal and Team Serices vulnerable to NT or NTLM authentication bypass on Win2000 SP4 using IE 6.x. Bugtraq 03-11-19 post by arkanian@hacker.am (GET) + /..\..\..\..\..\..\temp\temp.class - Cisco ACS 2.6.x and 3.0.1 (build 40) allows authenticated remote users to retrieve any file from the system. Upgrade to the latest version. (GET) + /..%252f..%252f..%252f..%252f..%252f../windows/repair/sam - BadBlue server is vulnerable to multiple remote exploits. See http://www.securiteam.com/exploits/5HP0M2A60G.html for more information. (GET) + /..%252f..%252f..%252f..%252f..%252f../winnt/repair/sam._ - BadBlue server is vulnerable to multiple remote exploits. See http://www.securiteam.com/exploits/5HP0M2A60G.html for more information. (GET) + /..%252f..%252f..%252f..%252f..%252f../winnt/repair/sam - BadBlue server is vulnerable to multiple remote exploits. See http://www.securiteam.com/exploits/5HP0M2A60G.html for more information. (GET) + /..%255c..%255c..%255c..%255c..%255c../windows/repair/sam - BadBlue server is vulnerable to multiple remote exploits. See http://www.securiteam.com/exploits/5HP0M2A60G.html for more information. (GET) + /..%255c..%255c..%255c..%255c..%255c../winnt/repair/sam._ - BadBlue server is vulnerable to multiple remote exploits. See http://www.securiteam.com/exploits/5HP0M2A60G.html for more information. (GET) + /..%255c..%255c..%255c..%255c..%255c../winnt/repair/sam - BadBlue server is vulnerable to multiple remote exploits. See http://www.securiteam.com/exploits/5HP0M2A60G.html for more information. (GET) + /.access - Contains authorization information (GET) + /.addressbook - PINE addressbook, may store sensitive e-mail address contact information and notes (GET) + /.bash_history - A user's home directory may be set to the web root, the shell history was retrieved. This should not be accessible via the web. (GET) + /.bashrc - User home dir was found with a shell rc file. This may reveal file and path information. (GET) + /.forward - User home dir was found with a mail forward file. May reveal where the user's mail is being forwarded to. (GET) + /.history - A user's home directory may be set to the web root, the shell history was retrieved. This should not be accessible via the web. (GET) + /.lynx_cookies - User home dir found with LYNX cookie file. May reveal cookies received from arbitrary web sites. (GET) + /.mysql_history - Database SQL? (GET) + /.passwd - Contains authorization information (GET) + /.pinerc - User home dir found with a PINE rc file. May reveal system information, directories and more. (GET) + /.plan - User home dir with a .plan, a now mostly outdated file for delivering information via the finger protocol (GET) + /.proclog - User home dir with a Procmail log file. May reveal user mail traffic, directories and more. (GET) + /.procmailrc - User home dir with a Procmail rc file. May reveal sub directories, mail contacts and more. (GET) + /.profile - User home dir with a shell profile was found. May reveal directory information and system configuration. (GET) + /.rhosts - A user's home directory may be set to the web root, a .rhosts file was retrieved. This should not be accessible via the web. (GET) + /.sh_history - A user's home directory may be set to the web root, the shell history was retrieved. This should not be accessible via the web. (GET) + /.ssh - A user's home directory may be set to the web root, an ssh file was retrieved. This should not be accessible via the web. (GET) + /.ssh/authorized_keys - A user's home directory may be set to the web root, an ssh file was retrieved. This should not be accessible via the web. (GET) + /.ssh/known_hosts - A user's home directory may be set to the web root, an ssh file was retrieved. This should not be accessible via the web. (GET) + / - TRACE option appears to allow XSS or credential theft. See http://www.cgisecurity.com/whitehat-mirror/WhitePaper_screen.pdf for details (TRACE) + /[SecCheck]/..%252f..%252f../ext.ini - BadBlue server is vulnerable to multiple remote exploits. See http://www.securiteam.com/exploits/5HP0M2A60G.html for more information. (GET) + /[SecCheck]/..%255c..%255c../ext.ini - BadBlue server is vulnerable to multiple remote exploits. See http://www.securiteam.com/exploits/5HP0M2A60G.html for more information. (GET) + ///etc/hosts - The server install allows reading of any system file by adding an extra '/' to the URL. (GET) + //admin/admin.shtml - Axis network camera may allow admin bypass by using double-slashes before URLs. (GET) + //admin/aindex.htm - FlexWATCH firmware 2.2 is vulnerable to authentication bypass by prepending an extra '/'. http://packetstorm.linuxsecurity.com/0310-exploits/FlexWATCH.txt (GET) + /~root/ - Allowed to browse root's home directory (GET) + /a/ - May be Kebi Web Mail administration menu. (GET) + /acart2_0/acart2_0.mdb - Alan Ward A-Cart 2.0 allows remote user to read customer database file which may contain usernames, passwords, credit cards and more. (GET) + /acart2_0/admin/category.asp - Alan Ward A-Cart 2.0 is vulnerable to an XSS attack which may cause the administrator to delete database information. (GET) + /accounts/getuserdesc.asp - Hosting Controller 2002 administration page is available. This should be protected. (GET) + /Admin_files/order.log - Selena Sol's WebStore 1.0 exposes order information, http://www.extropia.com/, http://www.mindsec.com/advisories/post2.txt. (GET) + /admin.php?en_log_id=0&action=config - EasyNews from http://www.webrc.ca version 4.3 allows remote admin access. This php file should be protected. (GET) + /admin.php?en_log_id=0&action=users - EasyNews from http://www.webrc.ca version 4.3 allows remote admin access. This php file should be protected. (GET) + /admin.php4?reg_login=1 - Mon Album from http://www.3dsrc.com version 0.6.2d allows remote admin access. This should be protected. (GET) + /admin/admin_phpinfo.php4 - Mon Album from http://www.3dsrc.com version 0.6.2d allows remote admin access. This should be protected. (GET) + /admin/admin.php?adminpy=1 - PY-Membres 4.2 may allow administrator access. (GET) + /admin/contextAdmin/contextAdmin.html - Tomcat may be configured to let attackers read arbitrary files. Restrict access to /admin. (GET) + /admin/cplogfile.log - DevBB 1.0 final (http://www.mybboard.com) log file is readable remotely. Upgrade to the latest version. (GET) + /admin/database/wwForum.mdb - Web Wiz Forums pre 7.5 is vulnerable to Cross-Site Scripting attacks. Default login/pass is Administrator/letmein (GET) + /admin/phpinfo.php - Immobilier or phPay allows phpinfo() to be run. See http://www.frog-man.org/tutos/Immoblier.txt or http://phpay.sourceforge.net/ (GET) + /admin/system_footer.php - myphpnuke version 1.8.8_final_7 reveals detailed system information. (GET) + /admin/wg_user-info.ml - WebGate Web Eye exposes user names and passwords. OSVDB-2922 (GET) + /administrator/gallery/uploadimage.php - Mambo PHP Portal/Server 4.0.12 BETA and below may allow upload of any file type simply putting '.jpg' before the real file extension. (GET) + /agentadmin.php - Immobilier may allow php files to be included from remote sites. See http://www.frog-man.org/tutos/Immoblier.txt (GET) + /akopia/ - Akopia is installed. (GET) + /amber_csh.html - Has been seen in web logs from an unknown scanner. (GET) + /ammerum/ - Ammerum pre 0.6-1 had several security issues. (GET) + /anthill/login.php - Anthill bug tracking system may be installed. Versions lower than 0.1.6.1 allow XSS/HTML injection and may allow users to bypass login requirements. http://anthill.vmlinuz.ca/ and CA-2000-02 (GET) + /ariadne/ - Ariadne pre 2.1.2 has several vulnerabilities. The default login/pass to the admin page is admin/muze. (GET) + /ASP/cart/database/metacart.mdb - MetaCart2 is an ASP shopping cart. The database of customers is available via the web. (GET) + /author.asp - May be FactoSystem CMS, which could include SQL injection problems which could not be tested remotely. (GET) + /autologon.html?10514 - Remotely Anywhere 5.10.415 is vulnerable to CSS attacks that can lead to cookie theft or privilege escalation. This is typically found on port 2000. (GET) + /axis-cgi/buffer/command.cgi - Axis WebCam 2400 may allow overwriting or creating files on the system. See http://www.websec.org/adv/axis2400.txt.html for details. (GET) + /b2-include/b2edit.showposts.php - Some versions of B2 (cafelog.com) are vulnerable to remote inclusion by redefining $b2inc to a remote php file. Upgrade to a version higher than b2.06pre2. This vulnerability could not be confirmed. (GET) + /BACLIENT - IBM Tivoli default file found. OSVDB-2117. (GET) + /ban.bak - Bannermatic versions 1-3 reveal sensitive information from unprotected files. These files should be protected. (GET) + /ban.dat - Bannermatic versions 1-3 reveal sensitive information from unprotected files. These files should be protected. (GET) + /ban.log - Bannermatic versions 1-3 reveal sensitive information from unprotected files. These files should be protected. (GET) + /banmat.pwd - Bannermatic versions 1-3 reveal sensitive information from unprotected files. These files should be protected. (GET) + /basilix/ - BasiliX webmail application. Default mysql database name is 'BASILIX' with password 'bsxpass' (GET) + /basilix/compose-attach.php3 - BasiliX webmail application prior to 1.1.1 contains non descript security vulnerability in compose-attach.php3 related to attachment uploads (GET) + /basilix/mbox-list.php3 - BasiliX webmail application prior to 1.1.1 contains a CSS issue in 'message list' function/page (GET) + /basilix/message-read.php3 - BasiliX webmail application prior to 1.1.1 contains a CSS issue in 'read message' function/page (GET) + /bb-dnbd/faxsurvey - This may allow arbitrary command execution. (GET) + /bigconf.cgi - BigIP Configuration CGI (GET) + /blah_badfile.shtml - Allaire Coldfusion allows jsp source viewed through a vulnerable SSI call. (GET) + /buddies.blt - Buddy List? (GET) + /buddy.blt - Buddy List? (GET) + /buddylist.blt - Buddy List? (GET) + /c32web.exe/ChangeAdminPassword - This CGI may contain a backdoor and may allow attackers to change the Cart32 admin password. (GET) + /cartcart.cgi - If this is Dansie shopping cart 3.0.8 or earlier, it contains a backdoor to allow attackers to execute arbitrary commands. (GET) + /catalog/includes/include_once.php - This phpWebSite script may allow inclusion of remote scripts by adding ?inc_prefix=http://YOURHOST/ (GET) + /catinfo - May be vulnerable to a buffer overflow. Request '/catinfo?' and add on 2048 of garbage to test. (GET) + /cbms/cbmsfoot.php - CBMS Billing Management has had many vulnerabilities in versions 0.7.1 and below. none could be confirmed here, but they should be manually checked if possible. http://freshmeat.net/projects/cbms/ (GET) + /cbms/changepass.php - CBMS Billing Management has had many vulnerabilities in versions 0.7.1 and below. none could be confirmed here, but they should be manually checked if possible. http://freshmeat.net/projects/cbms/ (GET) + /cbms/editclient.php - CBMS Billing Management has had many vulnerabilities in versions 0.7.1 and below. none could be confirmed here, but they should be manually checked if possible. http://freshmeat.net/projects/cbms/ (GET) + /cbms/passgen.php - CBMS Billing Management has had many vulnerabilities in versions 0.7.1 and below. none could be confirmed here, but they should be manually checked if possible. http://freshmeat.net/projects/cbms/ (GET) + /cbms/realinv.php - CBMS Billing Management has had many vulnerabilities in versions 0.7.1 and below. none could be confirmed here, but they should be manually checked if possible. http://freshmeat.net/projects/cbms/ (GET) + /cbms/usersetup.php - CBMS Billing Management has had many vulnerabilities in versions 0.7.1 and below. none could be confirmed here, but they should be manually checked if possible. http://freshmeat.net/projects/cbms/ (GET) + /cd-cgi/sscd_suncourier.pl - Sunsolve CD script may allow users to execute arbitrary commands. The script was confirmed to exist, but the test was not done. (GET) + /cfappman/index.cfm - susceptible to ODBC/pipe-style exploit; see RFP9901 http://www.wiretrip.net/rfp/p/doc.asp/i2/d3.htm (GET) + /cfdocs/cfmlsyntaxcheck.cfm - can be used for a DoS on the server by requesting it check all .exe's (GET) + /cfdocs/examples/cvbeans/beaninfo.cfm - susceptible to our ODBC exploit; see RFP9901 http://www.wiretrip.net/rfp/p/doc.asp/i2/d3.htm (GET) + /cfdocs/examples/parks/detail.cfm - susceptible to our ODBC exploit; see RFP9901 http://www.wiretrip.net/rfp/p/doc.asp/i2/d3.htm (GET) + /cfdocs/expeval/displayopenedfile.cfm - Unknown vul (GET) + /cfdocs/expeval/openfile.cfm - Sample code shipped with ColdFusion may allow an attacker to verify the existance of files or directories outside the web server path, launch Denial of Service attacks, and more. CVE-1999-0924. Allaire ASB99-02 (http://www.macromedia.com/v1/handlers/index.cfm?ID=8739&Method=Full). (GET) + /cfdocs/expeval/sendmail.cfm - can be used to send email; go to the page and fill in the form (GET) + /cfdocs/snippets/evaluate.cfm - can enter CF code to be evaluated, or create denial of service see www.allaire.com/security/ technical papers and advisories for info (GET) + /cfdocs/snippets/fileexists.cfm - can be used to verify the existance of files (on the same drive info as the web tree/file) (GET) + /cfdocs/snippets/gettempdirectory.cfm - depending on install, creates files, gives you physical drive info, sometimes defaults to \winnt\ directory as temp directory (GET) + /cfdocs/snippets/viewexample.cfm - this can be used to view .cfm files, request viewexample.cfm?Tagname=..\..\..\file (.cfm is assumed) (GET) + /cfide/Administrator/startstop.html - can start/stop the server (GET) + /cgi-bin/.cobalt/siteUserMod/siteUserMod.cgi - Older versions of this CGI allow any user to change the administrator password. (GET) + /cgi-bin/admin/admin.cgi - May be ImageFolio Pro administration CGI. Default login is Admin/ImageFolio. (GET) + /cgi-bin/admin/setup.cgi - May be ImageFolio Pro setup CGI. Default login is Admin/ImageFolio. (GET) + /cgi-bin/bigconf.cgi - BigIP Configuration CGI (GET) + /cgi-bin/common/listrec.pl - This CGI allows attackers to execute commands on the host. (GET) + /cgi-bin/handler - comes with IRIX 5.3 - 6.4; allows to run arbitrary commands (GET) + /cgi-bin/MachineInfo - gives out information on the machine (IRIX), including hostname (GET) + /cgi-bin/pfdisplay.cgi - comes with IRIX 6.2-6.4; allows to run arbitrary commands (GET) + /cgi-bin/webdist.cgi - comes with IRIX 5.0 - 6.3; allows to run arbitrary commands (GET) + /cgi-bin/wrap - comes with IRIX 6.2; allows to view directories (GET) + /cgi-sys/addalink.cgi - Default CGI, often with a hosting manager of some sort. No known problems, but host managers allow sys admin via web (GET) + /cgi-sys/cgiecho - Default CGI, often with a hosting manager of some sort. No known problems, but host managers allow sys admin via web (GET) + /cgi-sys/cgiemail - Default CGI, often with a hosting manager of some sort. No known problems, but host managers allow sys admin via web (GET) + /cgi-sys/countedit - Default CGI, often with a hosting manager of some sort. No known problems, but host managers allow sys admin via web (GET) + /cgi-sys/domainredirect.cgi - Default CGI, often with a hosting manager of some sort. No known problems, but host managers allow sys admin via web (GET) + /cgi-sys/entropybanner.cgi - Default CGI, often with a hosting manager of some sort. No known problems, but host managers allow sys admin via web (GET) + /cgi-sys/entropysearch.cgi - Default CGI, often with a hosting manager of some sort. No known problems, but host managers allow sys admin via web (GET) + /cgi-sys/FormMail-clone.cgi - Default CGI, often with a hosting manager of some sort. No known problems, but host managers allow sys admin via web (GET) + /cgi-sys/helpdesk.cgi - Default CGI, often with a hosting manager of some sort. No known problems, but host managers allow sys admin via web (GET) + /cgi-sys/mchat.cgi - Default CGI, often with a hosting manager of some sort. No known problems, but host managers allow sys admin via web (GET) + /cgi-sys/randhtml.cgi - Default CGI, often with a hosting manager of some sort. No known problems, but host managers allow sys admin via web (GET) + /cgi-sys/realhelpdesk.cgi - Default CGI, often with a hosting manager of some sort. No known problems, but host managers allow sys admin via web (GET) + /cgi-sys/realsignup.cgi - Default CGI, often with a hosting manager of some sort. No known problems, but host managers allow sys admin via web (GET) + /cgi-sys/scgiwrap - Default CGI, often with a hosting manager of some sort. No known problems, but host managers allow sys admin via web (GET) + /cgi-sys/signup.cgi - Default CGI, often with a hosting manager of some sort. No known problems, but host managers allow sys admin via web (GET) + /cgi/cgiproc? - It may be possible to crash Nortel Contivity VxWorks by requesting '/cgi/cgiproc?$' (not attempted!). Upgrade to version 2.60 or later. (GET) + /cgis/wwwboard/wwwboard.cgi - Versions 2.0 Alpha and below have multiple problems. See BID-649 and BID 1795. Default ID 'WebAdmin' with pass 'WebBoard'. (GET) + /cgis/wwwboard/wwwboard.pl - Versions 2.0 Alpha and below have multiple problems. See BID-649 and BID 1795. Default ID 'WebAdmin' with pass 'WebBoard'. (GET) + /chat/!nicks.txt - WF-Chat 1.0 Beta allows retrieval of user information. (GET) + /chat/!pwds.txt - WF-Chat 1.0 Beta allows retrieval of user information. (GET) + /chat/data/usr - SimpleChat! 1.3 allows retrieval of user information. (GET) + /clusterframe.jsp - Macromedia Jrun 4 build 61650 remote administration interface is vulnerable to several CSS attacks. (GET) + /config.inc - DotBr 0.1 configuration file includes usernames and passwords. (GET) + /config.php - PHP Config file may contain database IDs and passwords. (GET) + /config/ - Configuration information may be available remotely. (GET) + /Config1.htm - This may be a D-Link, some devices have a DoS condition if an oversized POST request is sent. This DoS was not tested. See http://www.phenoelit.de/stuff/dp-300.txt for info. (GET) + /contents.php?new_language=elvish&mode=select - Requesting a file with an invalid language selection from DC Portal may reveal the system path. (GET) + /counter/1/n/n/0/3/5/0/a/123.gif - The Roxen Counter may eat up excessive CPU time with image requests. (GET) + /cpanel/ - Web-based control panel (GET) + /cplogfile.log - XMB Magic Lantern forum 1.6b final (http://www.xmbforum.com) log file is readable remotely. Upgrade to the latest version. (GET) + /custdata/ - This may be COWS (CGI Online Worldweb Shopping), and may be interesting... (GET) + /CVS/Entries - CVS Entries file may contain directory listing information. (GET) + /data.sql - Database SQL? (GET) + /data/member_log.txt - Teekai's forum full 1.2 member's log can be retrieved remotely. (GET) + /data/userlog/log.txt - Teekai's Tracking Online 1.0 log can be retrieved remotely. (GET) + /database/ - Databases? Really?? (GET) + /database/metacart.mdb - MetaCart2 is an ASP shopping cart. The database of customers is available via the web. (GET) + /databases/ - Databases? Really?? (GET) + /databse.sql - Database SQL? (GET) + /db.sql - Database SQL? (GET) + /db/users.dat - upb PB allows the user database to be retrieved remotely. (GET) + /dc/auth_data/auth_user_file.txt - The DCShop installation allows credit card numbers to be viewed remotely. See dcscripts.com for fix information. (GET) + /dc/orders/orders.txt - The DCShop installation allows credit card numbers to be viewed remotely. See dcscripts.com for fix information. (GET) + /dcshop/auth_data/auth_user_file.txt - The DCShop installation allows credit card numbers to be viewed remotely. See dcscripts.com for fix information. (GET) + /dcshop/orders/orders.txt - The DCShop installation allows credit card numbers to be viewed remotely. See dcscripts.com for fix information. (GET) + /doc/ - The /doc directory is browsable. This may be /usr/doc. (GET) + /dostuff.php?action=modify_user - Blahz-DNS allows unauthorized users to edit user information. Upgrade to version 0.25 or higher. http://blahzdns.sourceforge.net/ (GET) + /ews/ews/architext_query.pl - Versions older than 1.1 of Excite for Web Servers allow attackers to execute arbitrary commands. BID-2665. (GET) + /exair/howitworks/Code.asp - Scripts within the Exair package on IIS 4 can be used for a DoS against the server. CVE-1999-0449. BID-193. (GET) + /examples/jsp/snp/anything.snp - Tomcat servlet gives lots of host information. (GET) + /ext.dll?MfcIsapiCommand=LoadPage&page=admin.hts%20&a0=add&a1=root&a2=%5C - This check (A) sets up the next bad blue test (B) for possible exploit. see http://www.badblue.com/down.htm (GET) + /filemanager/filemanager_forms.php - Some versions of PHProjekt allow remote file inclusions. Verify the current version is running. See http://www.securiteam.com/unixfocus/5PP0F1P6KS.html for more info (GET) + /finance.xls - Finance spreadsheet? (GET) + /finances.xls - Finance spreadsheet? (GET) + /foo.php3 - DotBr 0.1 has a phpinfo() script called foo.php3. (GET) + /forum/admin/database/wwForum.mdb - Web Wiz Forums pre 7.5 is vulnerable to Cross-Site Scripting attacks. Default login/pass is Administrator/letmein (GET) + /forum/admin/wwforum.mdb - Web Wiz Forums passwords found. (GET) + /forums/@ADMINconfig.php - PHP Config file may contain database IDs and passwords. (GET) + /forums/config.php - PHP Config file may contain database IDs and passwords. (GET) + /forums/index.php?top_message=<script>alert(document.cookie)</script> - Led-Forums allows any user to change the welcome message, and it is vulnerable to Cross Site Scripting (XSS). CA-2000-02. (GET) + /fpdb/shop.mdb - MetaCart2 is an ASP shopping cart. The database of customers is available via the web. (GET) + /gb/index.php?login=true - gBook may allow admin login by setting the value 'login' equal to 'true'. (GET) + /geeklog/users.php - Geeklog prior to 1.3.8-1sr2 contain a SQL injection vulnerability that lets a remote attacker reset admin password. (GET) + /getaccess - This may be an indication that the server is running getAccess for SSO (GET) + /global.inc - PHP-Survey's include file should not be available via the web. Configure the web server to ignore .inc files or change this to global.inc.php (GET) + /globals.jsa - Oracle globals.jsa file (GET) + /guestbook/?number=5&lng=%3Cscript%3Ealert(document.domain);%3C/script%3E - MPM Guesbook 1.2 and previous are vulnreable to CSS/XSS attacks. (GET) + /guestbook/admin.php - Guestbook admin page available without authentication. (GET) + /guestbook/admin/o12guest.mdb - Ocean12 ASP Guestbook Manager allows download of SQL database which contains admin password. (GET) + /guestbook/guestbookdat - PHP-Gastebuch 1.60 Beta reveals sensitive information about its configuration. (GET) + /guestbook/pwd - PHP-Gastebuch 1.60 Beta reveals the md5 hash of the admin password. (GET) + /help/ - Help directory should not be accessible (GET) + /hola/admin/cms/htmltags.php?datei=./sec/data.php - hola-cms-1.2.9-10 may reveal the administrator ID and password. (GET) + /hostingcontroller/ - This might be interesting...probably HostingController, www.hostingcontroller.com (GET) + /hp/device/this.LCDispatcher - The Hewlett Packard Color LaserJet 4550 may allow unauthenticated users to permanently include links (and other data) in the web interface. (GET) + /htpasswd - Passwords? (GET) + /IDSWebApp/IDSjsp/Login.jsp - Tivoli Directory Server Web Administration. (GET) + /IlohaMail/blank.html - IlohaMail 0.8.10 contains a CSS vulnerability. Previous versions contain other non-descript vulnerabilities. (GET) + /img-sys/ - Default image directory should not allow directory listing. (GET) + /inc/common.load.php - Bookmark4U v1.8.3 include files are not protected, and may contain remote source injection by using the 'prefix' variable. (GET) + /inc/config.php - Bookmark4U v1.8.3 include files are not protected, and may contain remote source injection by using the 'prefix' variable. (GET) + /inc/dbase.php - Bookmark4U v1.8.3 include files are not protected, and may contain remote source injection by using the 'prefix' variable. (GET) + /index.php?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 - PHP reveals potentially sensitive information via certain HTTP requests which contain specific QUERY strings. OSVDB-12184. (GET) + /index.php?=PHPE9568F34-D428-11d2-A769-00AA001ACF42 - PHP reveals potentially sensitive information via certain HTTP requests which contain specific QUERY strings. OSVDB-12184. (GET) + /index.php?=PHPE9568F35-D428-11d2-A769-00AA001ACF42 - PHP reveals potentially sensitive information via certain HTTP requests which contain specific QUERY strings. OSVDB-12184. (GET) + /index.php?=PHPE9568F36-D428-11d2-A769-00AA001ACF42 - PHP reveals potentially sensitive information via certain HTTP requests which contain specific QUERY strings. OSVDB-12184. (GET) + /index.php?module=My_eGallery - My_eGallery prior to 3.1.1.g are vulnerable to a remote execution bug via SQL command injection. (GET) + /index.php?top_message=<script>alert(document.cookie)</script> - Led-Forums allows any user to change the welcome message, and it is vulnerable to Cross Site Scripting (XSS). CA-2000-02. (GET) + /info.php - Contains PHP configuration information (GET) + /instantwebmail/message.php - Instant Web Mail (http://understroem.kdc/instantwebmail/) is installed. Versions 0.59 and lower can allow remote users to embed POP3 commands in URLs contained in email. (GET) + /interchange/ - Interchange chat is installed. Look for a high-numbered port like 20xx to find it running. (GET) + /ip.txt - This may be User Online from http://www.elpar.net version 2.0, which has a remotely accessible log file. (GET) + /isapi/count.pl? - AN HTTPd default script may allow writing over arbitrary files with a new content of '1', which could allow a trivial DoS. Append /../../../../../ctr.dll to replace this file's contents, for example. (GET) + /isqlplus - Oracle iSQL*Plus is installed. This may be vulnerable to a buffer overflow in the user id field. http://www.ngssoftware.com/advisories/ora-isqlplus.txt (GET) + /jamdb/ - JamDB pre 0.9.2 mp3.php and image.php can allow user to read arbitrary file out of docroot. (GET) + /java-sys/ - Default Java directory should not allow directory listing. (GET) + /javadoc/ - Documentation...? (GET) + /jigsaw/ - Jigsaw server may be installed. Versions lower than 2.2.1 are vulnerable to Cross Site Scripting (XSS), update to latest at http://freshmeat.net/users/yveslafon/. CA-2000-02. (GET) + /Jigsaw/ - Jigsaw server may be installed. Versions lower than 2.2.1 are vulnerable to Cross Site Scripting (XSS), update to latest at http://freshmeat.net/users/yveslafon/. CA-2000-02. (GET) + /kboard/ - KBoard Forum 0.3.0 and prior have a security problem in forum_edit_post.php, forum_post.php and forum_reply.php (GET) + /krysalis/ - Krysalis pre 1.0.3 may allow remote users to read arbitrary files outside docroot (GET) + /level/16 - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/16/exec/-///pwd - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/16/exec/-///show/configuration - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/16/exec/ - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/16/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/16/exec//show/access-lists - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/16/level/16/exec//show/configuration - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/16/level/16/exec//show/interfaces - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/16/level/16/exec//show/interfaces/status - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/16/level/16/exec//show/running-config/interface/FastEthernet - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/16/level/16/exec//show/version - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/17/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/18/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/19/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/20/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/21/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/22/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/23/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/24/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/25/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/26/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/27/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/28/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/29/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/30/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/31/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/32/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/33/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/34/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/35/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/36/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/37/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/38/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/39/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/40/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/41/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/42/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/42/exec/show%20conf - Retrieved Cisco configuration file. (GET) + /level/43/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/44/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/45/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/46/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/47/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/48/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/49/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/50/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/51/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/52/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/53/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/54/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/55/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/56/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/57/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/58/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/59/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/60/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/61/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/62/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/63/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/64/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/65/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/66/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/67/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/68/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/69/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/70/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/71/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/72/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/73/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/74/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/75/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/76/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/77/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/78/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/79/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/80/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/81/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/82/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/83/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/84/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/85/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/86/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/87/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/88/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/89/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/90/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/91/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/92/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/93/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/94/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/95/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/96/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/97/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/98/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /level/99/exec//show - CISCO HTTP service allows remote execution of commands. OSVDB-578 (GET) + /lists/admin/ - PHPList pre 2.6.4 contains a number of vulnerabilities including remote administrative access, harvesting user info and more. Default login to admin interface is admin/phplist (GET) + /livehelp/ - LiveHelp may reveal system information. (GET) + /LiveHelp/ - LiveHelp may reveal system information. (GET) + /log/ - Ahh...log information...fun! (GET) + /logicworks.ini - web-erp 0.1.4 and earlier allow .ini files to be read remotely. (GET) + /LOGIN.PWD - The Nortel MIRAN password file is available remotely--it may not be encrypted. (GET) + /logjam/showhits.php - Logjam may possibly allow remote command execution via showhits.php page. (GET) + /logs/str_err.log - Bmedia error log, contains invalid login attempts which include the invalid usernames and passwords entered (could just be typos & be very close to the right entries). (GET) + /mall_log_files/order.log - EZMall2000 exposes order information, http://www.ezmall2000.com/, see http://www.mindsec.com/advisories/post2.txt for details. (GET) + /mambo/administrator/phpinfo.php - Mambo Site Server 4.0.11 phpinfo.php script reveals system information. (GET) + /manager/ - May be a web server or site manager. (GET) + /manual.php - Does not filter input before passing to shell command. Try 'ls -l' as the man page entry. (GET) + /manual/ - Web server manual? tsk tsk. (GET) + /master.password - Passwords? (GET) + /mcartfree/database/metacart.mdb - MetaCart2 is an ASP shopping cart. The database of customers is available via the web. (GET) + /megabook/files/20/setup.db - Megabook guestbook configuration available remotely. (GET) + /metacart/database/metacart.mdb - MetaCart2 is an ASP shopping cart. The database of customers is available via the web. (GET) + /midicart.mdb - MIDICART database is available for browsing. This should not be allowed via the web server. (GET) + /MIDICART/midicart.mdb - MIDICART database is available for browsing. This should not be allowed via the web server. (GET) + /mlog.phtml - Remote file read vulnerability CVE-1999-0346 (GET) + /modsecurity.php - This phpWebSite script may allow inclusion of remote scripts by adding ?inc_prefix=http://YOURHOST/ (GET) + /mp3/ - Uh oh... (GET) + /mpcsoftweb_guestbook/database/mpcsoftweb_guestdata.mdb - MPCSoftWeb Guest Book passwords retrieved. (GET) + /musicqueue.cgi - Musicqueue 1.20 is vulnerable to a buffer overflow. Ensure the latest version is installed (exploit not attempted). http://musicqueue.sourceforge.net/ (GET) + /ncl_items.html - This may allow attackers to reconfigure your Tektronix printer. (GET) + /ncl_items.shtml?SUBJECT=1 - This may allow attackers to reconfigure your Tektronix printer. (GET) + /news/news.mdb - Web Wiz Site News realease v3.06 admin password database is available and unencrypted. (GET) + /officescan/hotdownload/ofscan.ini - OfficeScan from Trend Micro allows anyone to read the ofscan.ini file, which may contain passwords. (GET) + /ojspdemos/basic/hellouser/hellouser.jsp - Oracle 9i default jsp page found, may be vulnerable to XSS in any field. (GET) + /ojspdemos/basic/simple/usebean.jsp - Oracle 9i default jsp page found, may be vulnerable to XSS in any field. (GET) + /ojspdemos/basic/simple/welcomeuser.jsp - Oracle 9i default jsp page found, may be vulnerable to XSS in any field. (GET) + /openautoclassifieds/friendmail.php?listing=<script>alert(document.domain);</script> - OpenAutoClassifieds 1.0 is vulnerable to a CSS/XSS attack (GET) + /order/order_log_v12.dat - Web shopping system from http://www.io.com/~rga/scripts/cgiorder.html exposes order information, see http://www.mindsec.com/advisories/post2.txt (GET) + /order/order_log.dat - Web shopping system from http://www.io.com/~rga/scripts/cgiorder.html exposes order information, see http://www.mindsec.com/advisories/post2.txt (GET) + /orders/order_log_v12.dat - Web shopping system from http://www.io.com/~rga/scripts/cgiorder.html exposes order information, see http://www.mindsec.com/advisories/post2.txt (GET) + /Orders/order_log_v12.dat - Web shopping system from http://www.io.com/~rga/scripts/cgiorder.html exposes order information, see http://www.mindsec.com/advisories/post2.txt (GET) + /orders/order_log.dat - Web shopping system from http://www.io.com/~rga/scripts/cgiorder.html exposes order information, see http://www.mindsec.com/advisories/post2.txt (GET) + /Orders/order_log.dat - Web shopping system from http://www.io.com/~rga/scripts/cgiorder.html exposes order information, see http://www.mindsec.com/advisories/post2.txt (GET) + /ows/restricted%2eshow - OWS may allow restricted files to be viewed by replacing a character with its encoded equivalent. (GET) + /pafiledb/includes/team/file.php - paFileDB 3.1 and below may allow file upload without authentication. (GET) + /passwdfile - Passwords? (GET) + /pccsmysqladm/incs/dbconnect.inc - This file should not be accessible, as it contains database connectivity information. Upgrade to version 1.2.5 or higher. (GET) + /PDG_Cart/oder.log - Shopping cart software log (GET) + /people.lst - Passwords? (GET) + /photo_album/ - Atomic Photo Album pre 1.0.3 had a 'few' security problems. (GET) + /photo/ - My Photo Gallery pre 3.6 contains multiple vulnerabilities including .. traversal, unspecified vulnerabilities, and remote management interface access. (GET) + /photo/manage.cgi - My Photo Gallery management interface. May allow full access to photo galleries and more. (GET) + /photodata/ - My Photo Gallery pre 3.6 contains multiple vulnerabilities including .. traversal, unspecified vulnerabilities, and remote management interface access. (GET) + /photodata/manage.cgi - My Photo Gallery management interface. May allow full access to photo galleries and more. (GET) + /php-coolfile/action.php?action=edit&file=config.php - PHP-Coolfile 1.4 allows unauthorized administrative access. (GET) + /php.ini - This file should not be available through the web interface. (GET) + /php/index.php - Monkey Http Daemon default php file found. (GET) + /php/mlog.phtml - Remote file read vulnerability CVE-1999-0346 (GET) + /phpBB/phpinfo.php - phpBBmod contains an enhanced version of the phpinfo.php script. This should be removed as it contains detailed system information. (GET) + /phpBB2/includes/db.php - Some versions of db.php from phpBB2 allow remote file inclusions. Verify the current version is running. See http://www.securiteam.com/securitynews/5BP0F2A6KC.html for more info (GET) + /phpEventCalendar/file_upload.php - phpEventCalendar 1.1 and prior vulnerable to file upload bug. (GET) + /phpinfo.php?VARIABLE=<script>alert('Vulnerable')</script> - Contains PHP configuration information and is vulnerable to Cross Site Scripting (XSS). CA-2000-02. (GET) + /phpinfo.php - Contains PHP configuration information (GET) + /phpinfo.php3 - Contains PHP configuration information (GET) + /phpshare/phpshare.php - Several serious security holes pre 0.6b2. Several minor security holes pre 0.6b3 (GET) + /pmlite.php - A Xoops CMS script was found. Version RC3 and below allows all users to view all messages (untested). See http://www.phpsecure.org/?zone=pComment&d=101 for details. (GET) + /porn/ - This could be interesting (GET) + /postnuke/html/index.php?module=My_eGallery - My_eGallery prior to 3.1.1.g are vulnerable to a remote execution bug via SQL command injection. (GET) + /postnuke/index.php?module=My_eGallery - My_eGallery prior to 3.1.1.g are vulnerable to a remote execution bug via SQL command injection. (GET) + /powerportal/ - PowerPortal 1.1b is vulnerable to CSS attacks. (GET) + /pp.php?action=login - Pieterpost 0.10.6 allows anyone to access the 'virtual' account which can be used to relay/send e-mail. (GET) + /pr0n/ - Uh oh... (GET) + /project/index.php?m=projects&user_cookie=1 - dotProject 0.2.1.5 may allow admin login bypass by adding the user_cookie=1 to the URL. (GET) + /pron/ - Uh oh... (GET) + /pub/english.cgi?op=rmail - BSCW self-registration may be enabled. This could allow untrusted users semi-trusted access to the software. 3.x version (and probably some 4.x) allow arbitrary commands to be executed remotely. See http://www.securitytracker.com/alerts/2002/Jan/1003092.html (GET) + /pvote/ch_info.php?newpass=password&confirm=password%20 - PVote administration page is available. Versions 1.5b and lower do not require authentication to reset the administration password. (GET) + /pw/storemgr.pw - Encrypted ID/Pass for Mercantec's SoftCart, http://www.mercantec.com/, see http://www.mindsec.com/advisories/post2.txt for more information. (GET) + /pwd.db - Passwords? (GET) + /quikstore.cfg - Shopping cart config file, http://www.quikstore.com/, http://www.mindsec.com/advisories/post2.txt (GET) + /quikstore.cgi - A shopping cart. (GET) + /readme.txt - Default file found. (GET) + /README.TXT - Default file found. (GET) + /RLS_NOTE.TXT - The Nortel MIRAN reveals detailed information through the release notes file. (GET) + /scripts/wsisa.dll/WService=anything?WSMadmin - Allows Webspeed to remotely administered. Edit unbroker.properties and set AllowMsngrCmds to 0 (GET) + /search97cgi/s97_cgi - SCO Unixware search script may be vulnerable to XSS and command injection, BID-1717, CVE-2000-1014 (GET) + /securecontrolpanel/ - Web Server Control Panel (GET) + /securelogin/1,2345,A,00.html - Vignette Story Server v4.1, 6, may disclose sensitive information via a buffer overflow. CAN-2002-0385. (GET) + /server/ - If port 8000, Macromedia Jrun 4 build 61650 remote administration interface is vulnerable to several CSS attacks. (GET) + /servlet/allaire.jrun.ssi.SSIFilter - Allaire Coldfusion allows jsp source viewed through a vulnerable SSI call, see MPSB01-12 http://www.macromedia.com/devnet/security/security_zone/mpsb01-12.html. (GET) + /servlet/com.livesoftware.jrun.plugins.ssi.SSIFilter - Allaire Coldfusion allows jsp source viewed through a vulnerable SSI call. (GET) + /servlet/com.unify.servletexec.UploadServlet - This servlet allows attackers to upload files to the server. (GET) + /servlet/Counter - JRun default servlet found. All default code should be removed from servers. (GET) + /servlet/DateServlet - JRun default servlet found. All default code should be removed from servers. (GET) + /servlet/FingerServlet - JRun default servlet found. All default code should be removed from servers. (GET) + /servlet/HelloWorldServlet - JRun default servlet found. All default code should be removed from servers. (GET) + /servlet/SchedulerTransfer - PeopleSoft SchedulerTransfer servlet found, which may allow remote command execution. See http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21999 (GET) + /servlet/SessionManager - IBM WebSphere reconfigure servlet (user=servlet, password=manager). All default code should be removed from servers. (GET) + /servlet/SessionServlet - JRun default servlet found. All default code should be removed from servers. (GET) + /servlet/SimpleServlet - JRun default servlet found. All default code should be removed from servers. (GET) + /servlet/SnoopServlet - JRun default servlet found. All default code should be removed from servers. (GET) + /servlet/sunexamples.BBoardServlet - This default servlet lets attackers execute arbitrary commands. (GET) + /servlets/SchedulerTransfer - PeopleSoft SchedulerTransfer servlet found, which may allow remote command execution. See http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21999 (GET) + /session/admnlogin - SessionServlet Output, has session cookie info. (GET) + /SetSecurity.shm - Cisco System's My Access for Wireless... This resource should be password protected. (GET) + /shop/database/metacart.mdb - MetaCart2 is an ASP shopping cart. The database of customers is available via the web. (GET) + /shopa_sessionlist.asp - VP-ASP shopping cart test application is available from the web. This page may give the location of .mdb files which may also be available. (GET) + /shopadmin.asp - VP-ASP shopping cart admin may be available via the web. Default ID/PW are vpasp/vpasp and admin/admin. (GET) + /shoponline/fpdb/shop.mdb - MetaCart2 is an ASP shopping cart. The database of customers is available via the web. (GET) + /shopping/database/metacart.mdb - MetaCart2 is an ASP shopping cart. The database of customers is available via the web. (GET) + /shopping/diag_dbtest.asp - VP-ASP Shopping Cart 5.0 contains multiple SQL injection vulnerabilities. CAN-2003-0560, BID-8159 (GET) + /shopping300.mdb - VP-ASP shopping cart application allows .mdb files (which may include customer data) to be downloaded via the web. These should not be available. (GET) + /shopping400.mdb - VP-ASP shopping cart application allows .mdb files (which may include customer data) to be downloaded via the web. These should not be available. (GET) + /shoppingdirectory/midicart.mdb - MIDICART database is available for browsing. This should not be allowed via the web server. (GET) + /simplebbs/users/users.php - Simple BBS 1.0.6 allows user information and passwords to be viewed remotely. (GET) + /siteminder - This may be an indication that the server is running Siteminder for SSO (GET) + /SiteScope/htdocs/SiteScope.html - The SiteScope install may allow remote users to get sensitive information about the hosts being monitored. (GET) + /smssend.php - PhpSmssend may allow system calls if a ' is passed to it. http://zekiller.skytech.org/smssend.php (GET) + /splashAdmin.php - Cobalt Qube 3 admin is running. This may have multiple security problems as described by www.scan-associates.net. These could not be tested remotely. (GET) + /spwd - Passwords? (GET) + /sqldump.sql - Database SQL? (GET) + /sqlnet.log - Oracle log file found. (GET) + /ssdefs/ - Siteseed pre 1.4.2 has 'major' security problems. (GET) + /sshome/ - Siteseed pre 1.4.2 has 'major' security problems. (GET) + /structure.sql - Database SQL? (GET) + /submit?setoption=q&option=allowed_ips&value=255.255.255.255 - MLdonkey 2.x allows administrative interface access to be access from any IP. This is typically only found on port 4080. (GET) + /support/messages - Axis WebCam allows retrieval of messages file (/var/log/messages). See http://www.websec.org/adv/axis2400.txt.html (GET) + /sysuser/docmgr/iecreate.stm?template=../ - Sambar default file may allow directory listings. (GET) + /sysuser/docmgr/ieedit.stm?url=../ - Sambar default file may allow directory listings. (GET) + /texis.exe/?-dump - Texis installation may reveal sensitive information. (GET) + /texis.exe/?-version - Texis installation may reveal sensitive information. (GET) + /thebox/admin.php?act=write&username=admin&password=admin&aduser=admin&adpass=admin - paBox 1.6 may allow remote users to set the admin password. If successful, the 'admin' password is now 'admin'. (GET) + /tiki/ - Tiki 1.7.2 and previous allowed restricted Wiki pages to be viewed via a 'URL trick'. Default login/pass could be admin/admin (GET) + /tiki/tiki-install.php - Tiki 1.7.2 and previous allowed restricted Wiki pages to be viewed via a 'URL trick'. Default login/pass could be admin/admin (GET) + /tsweb/ - Microsoft TSAC found. http://www.dslwebserver.com/main/fr_index.html?/main/sbs-Terminal-Services-Advanced-Client-Configuration.html (GET) + /typo3conf/ - This may contain sensitive Typo3 files. (GET) + /typo3conf/database.sql - Typo3 sql file found. (GET) + /typo3conf/localconf.php - Typo3 config file found. (GET) + /uploader.php - This script may allow arbitrary files to be uploaded to the remote server. (GET) + /USER/CONFIG.AP - The Nortel MIRAN config file is available, which contains the TUI password. (GET) + /userlog.php - Teekai's Tracking Online 1.0 log can be retrieved remotely. (GET) + /vchat/msg.txt - VChat allows user information to be retrieved. (GET) + /vgn/ac/data - Vignette CMS admin/maintenance script available. (GET) + /vgn/ac/delete - Vignette CMS admin/maintenance script available. (GET) + /vgn/ac/edit - Vignette CMS admin/maintenance script available. (GET) + /vgn/ac/esave - Vignette CMS admin/maintenance script available. (GET) + /vgn/ac/fsave - Vignette CMS admin/maintenance script available. (GET) + /vgn/ac/index - Vignette CMS admin/maintenance script available. (GET) + /vgn/asp/MetaDataUpdate - Vignette CMS admin/maintenance script available. (GET) + /vgn/asp/previewer - Vignette CMS admin/maintenance script available. (GET) + /vgn/asp/status - Vignette CMS admin/maintenance script available. (GET) + /vgn/asp/style - Vignette CMS admin/maintenance script available. (GET) + /vgn/errors - Vignette CMS admin/maintenance script available. (GET) + /vgn/jsp/controller - Vignette CMS admin/maintenance script available. (GET) + /vgn/jsp/errorpage - Vignette CMS admin/maintenance script available. (GET) + /vgn/jsp/initialize - Vignette CMS admin/maintenance script available. (GET) + /vgn/jsp/jspstatus - Vignette CMS admin/maintenance script available. (GET) + /vgn/jsp/jspstatus56 - Vignette CMS admin/maintenance script available. (GET) + /vgn/jsp/metadataupdate - Vignette CMS admin/maintenance script available. (GET) + /vgn/jsp/previewer - Vignette CMS admin/maintenance script available. (GET) + /vgn/jsp/style - Vignette CMS admin/maintenance script available. (GET) + /vgn/legacy/edit - Vignette CMS admin/maintenance script available. (GET) + /vgn/legacy/save - Vignette Legacy Tool may be unprotected. To access this resource, set a cookie called 'vgn_creds' with any value. (GET) + /vgn/license - Vignette server license f Parsed in 3.74303293 seconds
| :: Download | ||||
| :: Print into | ||||
:: Make Diff
:: Erase Post