Pass Default Password (synnet) for 'debug' Account CVE-1999-0502 08 Mar 2005 9.8 (v3) Critical Pass Default Password (public) for 'public' Account CVE-1999-0383 CVE-1999-0502 08 Mar 2005 9.8 (v3) Critical Pass Default Password (debug) for 'super' Account CVE-1999-0502 CVE-1999-1420 CVE-1999-1421 08 Mar 2005 9.8 (v3) Critical Pass Default Password (forgot) for 'super' Account CVE-1999-0502 CVE-1999-1420 CVE-1999-1421 08 Mar 2005 9.8 (v3) Critical Pass MS06-018: Vulnerability in Microsoft Distributed Transaction Coordinator Could Allow DoS (913580) (uncredentialed check)CVE-2006-0034 CVE-2006-1184 10 May 2006 10 (v2) Critical Pass Default Password (debug) for 'user' Account CVE-1999-0502 CVE-1999-1420 08 Mar 2005 9.8 (v3) Critical Pass Default Password (forgot) for 'user' Account CVE-1999-0502 CVE-1999-1420 08 Mar 2005 9.8 (v3) Critical Pass FortressSSH SSH_MSG_KEXINIT Logging Remote Overflow CVE-2006-2421 23 May 2006 7.5 (v2) High Pass Panda AdminSecure Communications Agent Detection 25 Jul 2007 None Pass Easy File Sharing Web Server Crafted Request ADS Arbitrary File Access CVE-2006-5714 08 Nov 2006 5 (v2) Medium Pass Juniper Junos ttymodem() DoS (PSN-2012-08-699) 26 Oct 2012 7.1 (v2) High Pass phpMyFAQ Forum Message username Field SQL Injection CVE-2005-0702 09 Mar 2005 7.5 (v2) High Pass phpBB <= 2.0.13 Multiple Vulnerabilities CVE-2005-0659 CVE-2005-0673 CVE-2005-1026 09 Mar 2005 6.5 (v2) Medium Pass PHP-Fusion BBCode IMG Tag XSS CVE-2005-0692 09 Mar 2005 4.3 (v2) Medium Noise TCP/IP Timestamps Supported 16 May 2007 None Pass YaBB YaBB.pl usersrecentposts Action username Parameter XSS CVE-2005-0741 CVE-2005-0785 10 Mar 2005 4.3 (v2) Medium Pass NewsScript newsscript.pl mode Parameter Privilege Escalation CVE-2005-0735 10 Mar 2005 6.4 (v2) Medium Pass XMPP Server Detection 29 May 2007 None Pass Packeteer Web Management Interface Detection 26 Jun 2007 None Pass AlienVault OSSIM REST API Service Detection 24 May 2017 None Pass Atlassian Jira Data Center / Jira Service Management Data Center Missing Authentication (2021-07-21) CVE-2020-36239 29 Jul 2021 9.8 (v3) Critical Pass Firewall Detection 26 Oct 2007 None Pass Skype skype4com URI Handler Remote Heap Corruption (uncredentialed check) CVE-2007-5989 07 Dec 2007 9.3 (v2) High Pass HP DesignJet Accounting.xls Information Disclosure Vulnerability 16 Apr 2019 5.3 (v3) Medium Pass Tenable Core Web Interface Detection 18 Nov 2019 None Pass NGINX Unit HTTP Server Detection 26 Apr 2019 None Pass Juniper Junos Oversized BGP UPDATE Remote DoS (JSA10609) CVE-2014-0616 16 Jan 2014 4.3 (v2) Medium Pass Juniper Junos SRX Series flowd Remote DoS (JSA10611) CVE-2014-0618 16 Jan 2014 7.8 (v2) High Pass OS Identification: iPhone or iPad 10 Jul 2019 None Pass Pinnacle Cart index.php pg Parameter XSS CVE-2005-1130 13 Apr 2005 4.3 (v2) Medium Pass Cisco TelePresence Conductor REST API Server-Side Request Forgery Vulnerability CVE-2019-1679 27 Aug 2019 5 (v3) Medium Pass Tenable Nessus < 8.6.0 Denial of Service vulnerability (TNS-2019-05) CVE-2019-3974 23 Aug 2019 8.1 (v3) High Pass Puppet Enterprise 2015.x < 2016.4.0 Denial of Service Vulnerability CVE-2016-9686 09 Oct 2019 5.3 (v3) Medium Pass Mac OS X 10.9.x < 10.9.4 Multiple Vulnerabilities CVE-2014-0015 CVE-2014-1317 CVE-2014-1355 CVE-2014-1356 CVE-2014-1357 CVE-2014-1358 CVE-2014-1359 CVE-2014-1361 CVE-2014-1370 CVE-2014-1371 CVE-2014-1372 CVE-2014-1373 CVE-2014-1375 CVE-2014-1376 CVE-2014-1377 CVE-2014-1378 CVE-2014-1379 CVE-2014-1380 CVE-2014-138101 Jul 2014 10 (v2) Critical Pass Juniper Junos Invalid PIM DoS (JSA10637) CVE-2014-3819 15 Jul 2014 7.8 (v2) High Pass Juniper Junos TCP Packet Processing Remote DoS (JSA10638) CVE-2004-0230 15 Jul 2014 5 (v2) Medium Pass McAfee Web Gateway Information Disclosure (SB10080) CVE-2014-6064 05 Sep 2014 4 (v2) Medium Pass Juniper Junos 'em' Interface Fragmentation Remote DoS (JSA10655) CVE-2014-6380 14 Oct 2014 7.8 (v2) High Pass PhotoPost PHP < 5.0.1 Multiple Remote Vulnerabilities CVE-2005-0774 CVE-2005-0775 CVE-2005-0776 CVE-2005-0777 CVE-2005-0778 CVE-2005-1629 11 Mar 2005 7.5 (v2) High Pass UBB.threads Detection 12 Mar 2005 None Pass Phorum < 5.0.15 Multiple XSS CVE-2005-0783 CVE-2005-0784 17 Mar 2005 4.3 (v2) Medium Pass Unpassworded 'help' Account CVE-1999-0502 19 Mar 2005 9.8 (v3) Critical Pass Phorum search.php location Parameter HTTP Response Splitting CVE-2005-0843 22 Mar 2005 4.3 (v2) Medium Pass Kayako eSupport Troubleshooter Module index.php Multiple Parameter XSS CVE-2005-0842 22 Mar 2005 4.3 (v2) Medium Pass XMB Forum < 1.9.10 Multiple Vulnerabilities CVE-2005-0885 CVE-2005-2574 CVE-2005-2575 24 Mar 2005 7.5 (v2) High Pass Invision Power Board HTTP POST Request IFRAME Tag XSS CVE-2005-0886 24 Mar 2005 3.5 (v2) Low Pass Juniper Junos MX Series Trio-based PFE Modules Security Bypass (JSA10666) CVE-2014-6383 23 Jan 2015 5 (v2) Medium Pass Cisco TelePresence Conductor GNU glibc gethostbyname Function Buffer Overflow Vulnerability (GHOST)CVE-2015-0235 18 Feb 2015 10 (v2) Critical Pass Cisco Wireless LAN Controller Web Authentication DoS (CSCum03269) CVE-2015-0723 21 May 2015 6.1 (v2) Medium Pass Sybase SQL Anywhere Server Detection 07 Mar 2007 None Pass PHPSysInfo < 2.5 Multiple Script XSS CVE-2005-0870 24 Mar 2005 4.3 (v2) Medium Pass Oracle Reports Server test.jsp Multiple Parameter XSS CVE-2005-0873 24 Mar 2005 4.3 (v2) Medium Pass Juniper Junos J-Web Multiple Vulnerabilities (JSA10682) CVE-2014-6447 04 Aug 2015 10 (v2) Critical Pass Default Password '666666' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Libssh ssh_packet_kexinit() Double-free Memory DoS CVE-2014-8132 16 Jan 2015 5 (v2) Medium Pass Puppet Enterprise Multiple OpenSSL Vulnerabilities (FREAK) CVE-2015-0204 CVE-2015-0209 CVE-2015-0286 CVE-2015-0287 CVE-2015-0288 CVE-2015-0289 CVE-2015-0292 CVE-2015-0293 30 Dec 2015 7.5 (v2) High Pass IPMI v2.0 Password Hash Disclosure CVE-2013-4786 18 Dec 2014 7.5 (v3) High Pass GoAhead Embedded Web Server websNormalizeUriPath() Directory Traversal Vulnerability CVE-2014-9707 03 Apr 2015 7.5 (v2) High Pass MIT Kerberos 5 setup_server_realm() Remote DoS CVE-2013-1418 18 Nov 2013 4.3 (v2) Medium Pass HP Intelligent Management Center SOM Module Information Disclosure CVE-2013-4826 09 Jan 2014 5 (v2) Medium Pass MS07-029: Vulnerability in Windows DNS RPC Interface Could Allow Remote Code Execution (935966) (uncrCVE-2007-1748edentialed check) 05 Mar 2014 10 (v2) Critical Pass Zebra ZTC Printer Web Interface Detection 25 Nov 2019 None Pass CKEditor Preview Plugin Unspecified XSS CVE-2014-5191 31 Jul 2014 4.3 (v2) Medium Pass Oracle Web Determinations Detection 12 Sep 2014 None Pass Oracle Web Cache Admin Module Multiple GET Request Method DoS CVE-2002-0386 14 Aug 2002 5 (v2) Medium Pass PostgreSQL 8.4 < 8.4.17 / 9.0 < 9.0.13 / 9.1 < 9.1.9 / 9.2 < 9.2.4 Predictable Random Number Generator CVE-2013-1900 08 Apr 2013 8.8 (v3) High Pass Apache mod_wsgi < 3.5 Apache Process Privilege Escalation CVE-2014-0240 14 Jul 2014 8.1 (v3) High Pass Novell NetWare Web Server sewse.nlm (viewcode.jse) Traversal Arbitrary File Access CVE-2001-1580 06 Feb 2004 5 (v2) Medium Pass Apache Tomcat 3.x < 3.2.2 Malformed URL JSP Source Disclosure CVE-2001-0590 26 Oct 2010 5.3 (v3) Medium Pass OpenSSL SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG Session Resume Ciphersuite Downgrade IssueCVE-2010-4180 07 Feb 2011 4.3 (v2) Medium Pass Apache 2.2.x < 2.2.18 APR apr_fnmatch DoS CVE-2011-1928 25 May 2011 5.3 (v3) Medium Pass Oracle Secure Backup Administration Server login.php XSS CVE-2011-2251 27 Jul 2011 4.3 (v2) Medium Pass OpenSSL 1.0.0 < 1.0.0j DTLS CBC Denial of Service CVE-2012-2333 11 May 2012 5 (v2) Medium Pass HP Data Protector Unspecified Local Unauthorized Access CVE-2009-4183 28 Jan 2010 4.6 (v2) Medium Pass CVS pserver Line Entry Handling Overflow CVE-2004-0396 19 May 2004 10 (v2) Critical Pass Cisco Content Security Management Appliance Web Detection 26 Jul 2013 None Pass Real Video Server Telnet Malformed Data Remote DoS CVE-1999-0271 22 Aug 1999 5 (v2) Medium Pass BenHur Firewall Source Port 20 ACL Restriction Bypass CVE-2002-2307 22 Jul 2002 5 (v2) Medium Pass Apache < 2.0.44 Illegal Character Default Script Mapping Bypass CVE-2003-0017 22 Jan 2003 5.3 (v3) Medium Pass Solaris in.lpd Crafted Job Request Arbitrary Remote Command Execution CVE-2001-1583 03 Apr 2003 10 (v2) Critical Pass mod_gzip Debug Mode mod_gzip_printf Remote Format String CVE-2003-0843 02 Jun 2003 5.1 (v2) Medium Pass PhotoPost < 5.1 Multiple Input Validation Vulnerabilities CVE-2005-0928 CVE-2005-0929 30 Mar 2005 7.5 (v2) High Pass PHP Multiple Image Processing Functions File Handling DoS CVE-2005-0524 CVE-2005-0525 02 Apr 2005 5.4 (v2) Medium Pass Apple iTunes For Windows iTunesHelper.exe Path Subversion Local Privilege Escalation (uncredentialed check)CVE-2005-2938 16 Nov 2005 7.2 (v2) High Pass phpMyAdmin index.php convcharset Parameter XSS CVE-2005-0992 05 Apr 2005 4.3 (v2) Medium Pass MySQL Zero-length Scrambled String Crafted Packet Authentication Bypass CVE-2004-0627 07 Jan 2011 7.5 (v2) High Pass PHP < 4.4.2 Multiple XSS Vulnerabilities CVE-2006-0208 18 Nov 2011 2.6 (v2) Low Pass PHP < 4.4.4 Multiple Vulnerabilities CVE-2006-1017 CVE-2006-4020 18 Nov 2011 9.3 (v2) High Pass PHP 5.x < 5.1.0 Multiple Vulnerabilities CVE-2005-3319 CVE-2005-3883 18 Nov 2011 5 (v2) Medium Pass IBM Storwize V7000 Unified ACL Security Bypass CVE-2014-0875 31 Aug 2015 3.5 (v2) Low Pass PHP 5.1.x < 5.1.2 Multiple Vulnerabilities CVE-2006-0200 CVE-2006-0207 CVE-2006-0208 18 Nov 2011 9.3 (v2) High Pass Oracle Primavera Unifier Multiple Vulnerabilities (July 2018 CPU) CVE-2016-4055 CVE-2016-7103 CVE-2018-2965 CVE-2018-2966 CVE-2018-2967 CVE-2018-2968 CVE-2018-2969 20 Jul 2018 6.1 (v3) Medium Pass Jenkins < 2.138.4 LTS / 2.150.1 LTS / 2.154 Multiple Vulnerabilities CVE-2018-1000861 CVE-2018-1000862 CVE-2018-1000863 CVE-2018-1000864 07 Dec 2018 9.8 (v3) Critical Pass HP Data Protector 'EXEC_INTEGUTIL' Arbitrary Command Execution 13 Nov 2014 10 (v2) Critical Pass Palo Alto Networks Panorama PAN-OS < 6.0.1 Firmware Signature Verification Bypass Arbitrary Code ExecutionCVE-2015-6531 28 Sep 2015 7.6 (v2) High Pass Apple TV < 10.1.1 Multiple Vulnerabilities CVE-2016-8687 CVE-2017-2350 CVE-2017-2354 CVE-2017-2355 CVE-2017-2356 CVE-2017-2360 CVE-2017-2362 CVE-2017-2363 CVE-2017-2365 CVE-2017-2369 CVE-2017-2370 CVE-2017-237330 Jan 2017 7.8 (v3) High Pass Apache Tomcat 4.x < 4.1.0 Multiple Vulnerabilities CVE-2002-2006 CVE-2003-0866 04 Nov 2010 5.3 (v3) Medium Pass Apache Tomcat 3.x < 3.3.2 Multiple Vulnerabilities CVE-2003-0044 CVE-2007-3384 09 Nov 2010 5.6 (v3) Medium Pass Dropbear SSH Server < 2016.72 Multiple Vulnerabilities CVE-2016-7406 CVE-2016-7407 CVE-2016-7408 CVE-2016-7409 22 Sep 2016 9.8 (v3) Critical Pass Oracle Database Multiple Vulnerabilities (October 2010 CPU) CVE-2010-1321 CVE-2010-2389 CVE-2010-2390 CVE-2010-2391 CVE-2010-2407 CVE-2010-2411 CVE-2010-2412 CVE-2010-2415 CVE-2010-241918 Nov 2010 7.5 (v2) High Pass Ethernet MAC Addresses 16 Oct 2015 None Pass macOS 10.13.x < 10.13.4 Multiple Vulnerabilities CVE-2017-13080 CVE-2017-13890 CVE-2017-13911 CVE-2017-15412 CVE-2017-7151 CVE-2018-4104 CVE-2018-4105 CVE-2018-4106 CVE-2018-4107 CVE-2018-4108 CVE-2018-4111 CVE-2018-4112 CVE-2018-4115 CVE-2018-4131 CVE-2018-4132 CVE-2018-4135 CVE-2018-4136 CVE-2018-4138 CVE-2018-4139 CVE-2018-4142 CVE-2018-4143 CVE-2018-4144 CVE-2018-4150 CVE-2018-4151 CVE-2018-4152 CVE-2018-4154 CVE-2018-4155 CVE-2018-4156 CVE-2018-4157 CVE-2018-4158 CVE-2018-4160 CVE-2018-4167 CVE-2018-4170 CVE-2018-4173 CVE-2018-4174 CVE-2018-4175 CVE-2018-4176 CVE-2018-4179 CVE-2018-4185 CVE-2018-4187 CVE-2018-429802 Apr 2018 9.8 (v3) Critical Pass Palo Alto Networks PAN-OS 6.x.x < 6.1.21 / 7.1.x < 7.1.18 / 8.0.x < 8.0.11-h1 Multiple Vulnerabilities CVE-2018-7636 CVE-2018-9242 CVE-2018-9334 CVE-2018-9335 13 Jul 2018 5.5 (v3) Medium Pass Juniper Junos Privilege Escalation (JSA10857) CVE-2018-0024 20 Jul 2018 7.8 (v3) High Pass Citrix NetScaler Multiple Vulnerabilities (CTX232161) CVE-2018-6186 CVE-2018-6808 CVE-2018-6809 CVE-2018-6810 CVE-2018-6811 05 Jul 2018 9.8 (v3) Critical Pass Cisco Prime Data Center Network Manager Web Detection 11 Jul 2013 None Pass Microsoft Windows 95/98/ME Unsupported Installation Detection 01 Jun 2006 10 (v2) Critical Pass Solaris rpc.yppasswdd username Remote Overflow CVE-2001-0779 29 May 2001 10 (v2) Critical Pass WebLogic Server Encoded Request Directory Listing 16 Feb 2016 5 (v2) Medium Pass Citrix NFuse Server launch.asp Arbitrary Server/Port Redirect 16 Oct 2003 5 (v2) Medium Pass QlikView Server AccessPoint XML External Entity Injection CVE-2015-3623 23 Jun 2016 6.4 (v2) Medium Pass Disk Sorter HTTP POST Request Handling Remote Stack Buffer Overflow 15 Jun 2018 9.8 (v3) Critical 69
RELAYTO Penetration Test Results Page 68 Page 70