Pass PHPix album Parameter Encoded Traversal Arbitrary File/Directory Access CVE-2000-0919 11 Dec 2000 5 (v2) Medium Pass A1Stats Multiple Script Traversal Arbitrary File Access CVE-2001-0561 14 May 2001 5 (v2) Medium Pass DeluxeBB Multiple Scripts SQL Injection CVE-2005-2989 19 Sep 2005 7.5 (v2) High Pass ManageEngine Security Manager Plus 'f' Directory Traversal Arbitrary File Access 10 Dec 2012 5 (v2) Medium Pass Sambar Server Multiple CGI Environment Variable Disclosure CVE-2003-1284 25 Jun 2003 5 (v2) Medium Pass Icecast MP3 Client HTTP GET Request Remote Overflow CVE-2002-0177 01 Oct 2004 7.5 (v2) High Pass WHM AutoPilot < 2.5.20 Multiple Remote Vulnerabilities CVE-2004-1420 CVE-2004-1421 CVE-2004-1422 28 Dec 2004 7.3 (v3) High Pass bBlog <= 0.7.4 Multiple Vulnerabilities (SQLi, XSS) CVE-2004-1570 CVE-2004-1865 CVE-2005-1309 CVE-2005-1310 03 May 2005 7.5 (v2) High Pass FUDforum < 2.7.1 Avatar Upload Extension Validation Weakness Arbitrary Code Execution CVE-2005-2781 29 Aug 2005 6.5 (v2) Medium Pass PunBB < 1.2.7 Multiple Vulnerabilities CVE-2005-4665 15 Sep 2005 4.3 (v2) Medium Pass Trend Micro ControlManager < 3.0 SP5 Multiple Vulnerabilities CVE-2005-1929 13 Jan 2006 7.5 (v2) High Pass ViRobot Linux Server filescan Authentication Bypass CVE-2006-0864 22 Feb 2006 10 (v2) Critical Pass UBB.threads doeditconfig Arbitrary Command Injection CVE-2006-5137 30 Sep 2006 8.8 (v3) High Pass Splunk 4.0.x < 4.0.11 / 4.1.x < 4.1.2 Directory Traversal CVE-2010-2502 07 Jul 2010 9 (v2) High Pass Eucalyptus Walrus REST Interface Key Verification Authentication Bypass (ESA-03) CVE-2012-3240 21 Aug 2012 7.5 (v2) High Pass PHP 5.x < 5.2 Multiple Vulnerabilities CVE-2006-1015 CVE-2006-1549 CVE-2006-2660 CVE-2006-4486 CVE-2006-4625 CVE-2006-4812 CVE-2006-5465 CVE-2006-5706 CVE-2006-7205 CVE-2007-0448 CVE-2007-1381 CVE-2007-1584 CVE-2007-1888 CVE-2007-2844 CVE-2007-542425 Mar 2008 7.5 (v2) High Pass Discuz! <= 4.0.0 rc4 Arbitrary File Upload CVE-2005-2614 19 Sep 2005 4.6 (v2) Medium Pass Greymatter Comment Name Field Control Panel Log XSS CVE-2005-2816 19 Sep 2005 4.3 (v2) Medium Pass phpGroupWare < 0.9.16 Addressbook Unspecified Vulnerability 19 Sep 2005 None Pass phpGroupWare Main Screen Message Body XSS CVE-2005-2761 19 Sep 2005 4.3 (v2) Medium Pass Tofu Server Detection 19 Sep 2005 None Pass vBulletin <= 3.0.9 Multiple Vulnerabilities CVE-2005-3019 CVE-2005-3020 CVE-2005-3024 CVE-2005-3025 19 Sep 2005 8.3 (v3) High Pass Lotus Domino Multiple Script Src / BaseTarget XSS CVE-2005-3015 20 Sep 2005 4.3 (v2) Medium Pass PHP Advanced Transfer Manager <= 1.30 Multiple Vulnerabilities 21 Sep 2005 5 (v2) Medium Pass Digital Scribe login.php SQL Injection CVE-2005-2987 21 Sep 2005 7.5 (v2) High Pass phpMyFAQ < 1.5.2 Multiple Vulnerabilities CVE-2005-3049 26 Sep 2005 6.8 (v2) Medium Pass WEBppliance ocw_login_username Parameter XSS CVE-2005-3014 27 Sep 2005 4.3 (v2) Medium Pass IceWarp Web Mail Multiple Flaws (4) CVE-2005-3131 CVE-2005-3132 CVE-2005-3133 30 Sep 2005 9.7 (v2) High Pass GuppY < 4.5.6a Multiple Vulnerabilities CVE-2005-2853 CVE-2005-3156 06 Oct 2005 4.3 (v2) Medium Pass HP iNode Management Center Detection 19 Aug 2011 None Pass phpMyAdmin grab_globals.lib.php subform Parameter Traversal Local File Inclusion CVE-2005-3299 11 Oct 2005 5.1 (v2) Medium Pass phpWebSite index.php Search Module SQL Injection CVE-2005-4792 14 Oct 2005 7.5 (v2) High Pass PunBB search.php old_searches Parameter SQL Injection CVE-2005-3518 17 Oct 2005 4.3 (v2) Medium Pass Splunk Enterprise 8.1.x < 8.1.6 MFA Bypass CVE-2021-26253 31 May 2022 8.1 (v3) High Pass Gallery main.php g2_itemId Parameter Traversal Arbitrary File Access CVE-2005-3251 18 Oct 2005 5 (v2) Medium Pass Terminal Services Encryption Level is Medium or Low 25 Jan 2012 4.3 (v2) Medium Pass w-Agora <= 4.2.0 Multiple Vulnerabilities 20 Oct 2005 7.5 (v2) High Pass Xerver < 4.20 Multiple Vulnerabilities CVE-2005-3293 CVE-2005-4774 20 Oct 2005 5 (v2) Medium Pass e107 resetcore.php user Field SQL Injection CVE-2005-3521 21 Oct 2005 7.5 (v2) High Pass phpMyAdmin < 2.6.4-pl3 Multiple Vulnerabilities CVE-2005-3300 CVE-2005-3301 26 Oct 2005 5.1 (v2) Medium Pass HP LaserJet Web Server Unspecified Admin Component Traversal Arbitrary File Access CVE-2008-4419 10 Apr 2009 7.8 (v2) High Pass PHP iCalendar index.php phpicalendar Parameter Remote File Inclusion CVE-2005-3366 27 Oct 2005 6.8 (v2) Medium Pass YIFF Sound Server Detection 27 Oct 2005 None Pass Mantis < 0.19.3 Multiple Vulnerabilities CVE-2005-3091 CVE-2005-3335 CVE-2005-3336 CVE-2005-3337 CVE-2005-3338 CVE-2005-3339 27 Oct 2005 6.8 (v2) Medium Pass PHP < 4.4.1 / 5.0.6 Multiple Vulnerabilities CVE-2002-0229 CVE-2005-2491 CVE-2005-3388 CVE-2005-3389 CVE-2005-3390 01 Nov 2005 7.5 (v2) High Pass Invision Gallery index.php st Parameter SQL Injection CVE-2005-3395 01 Nov 2005 7.5 (v2) High Pass Comersus BackOffice comersus_backoffice_menu.asp Multiple Parameter SQL Injection 02 Nov 2005 7.5 (v2) High Pass phpBB <= 2.0.17 Multiple Vulnerabilities CVE-2005-3415 CVE-2005-3416 CVE-2005-3417 CVE-2005-3418 CVE-2005-3419 CVE-2005-3420 CVE-2005-3536 CVE-2005-3537 02 Nov 2005 7.5 (v2) High Pass vCard define.inc.php match Parameter Remote File Inclusion CVE-2005-3332 02 Nov 2005 7.3 (v3) High Pass VERITAS NetBackup Agent Detection 07 Nov 2005 None Pass Cheops NG Agent Detection 08 Nov 2005 None Pass PHPFM Arbitrary File Upload CVE-2005-4423 08 Nov 2005 8.8 (v3) High Pass Horde Admin Account Default Password CVE-2005-3344 08 Nov 2005 10 (v2) Critical Pass MailWatch authenticate() Function SQL Injection CVE-2005-3470 10 Nov 2005 6.8 (v2) Medium Pass GO-Global for Windows _USERSA_ Remote Overflow CVE-2005-3483 10 Nov 2005 10 (v2) Critical Pass VERITAS NetBackup Volume Manager Daemon Buffer Overflow CVE-2005-3116 11 Nov 2005 10 (v2) Critical Pass SolarWinds Dameware Mini Remote Control Client Public Key Buffer Over-read CVE-2019-3956 27 Jun 2019 7.4 (v3) High Pass TikiWiki < 1.8.6 / 1.9.1 Multiple Vulnerabilities CVE-2005-1925 14 Nov 2005 6.4 (v2) Medium Pass StreamSets Data Collector Web Detection 10 Jul 2019 None Pass Sonatype Nexus Repository Manager Missing Access Controls RCE CVE-2019-7238 26 Jul 2019 9.8 (v3) Critical Pass Xerox WorkCentre Multiple Vulnerabilities (XRX19-016) (URGENT/11) CVE-2019-12255 CVE-2019-12256 CVE-2019-12257 CVE-2019-12258 CVE-2019-12259 CVE-2019-12260 CVE-2019-12261 CVE-2019-12262 CVE-2019-12263 CVE-2019-12264 CVE-2019-1226529 Jul 2019 9.8 (v3) Critical Pass OpenSSL 1.1.1 < 1.1.1m Vulnerability CVE-2021-4160 28 Jan 2022 5.9 (v3) Medium Pass Moodle < 1.5.3 Multiple SQL Injection Vulnerabilities CVE-2005-3648 16 Nov 2005 7.5 (v2) High Pass Exponent CMS < 0.96.4 Multiple Remote Vulnerabilities (XSS, SQLi, Code Exe, Disc) CVE-2005-3762 CVE-2005-3763 CVE-2005-3764 CVE-2005-3765 CVE-2005-3766 CVE-2005-3767 16 Nov 2005 10 (v2) Critical Pass XOOPS xoopsConfig[language] Parameter Local File Inclusion (XOOPS_WFd205_xpl) CVE-2005-3680 16 Nov 2005 6.4 (v2) Medium Pass CodeGrrl Applications Remote File Inclusion Vulnerabilities CVE-2005-3571 16 Nov 2005 5 (v2) Medium Pass phpSysInfo < 2.4.1 Multiple Vulnerabilities CVE-2003-0536 CVE-2005-0870 CVE-2005-3347 CVE-2005-3348 16 Nov 2005 6.8 (v2) Medium Pass phpwcms 1.2.5 Multiple Vulnerabilities CVE-2005-3789 16 Nov 2005 5 (v2) Medium Pass Mambo Open Source / Joomla! GLOBALS Variable Remote File Include CVE-2005-3738 17 Nov 2005 8.1 (v3) High Pass Help Center Live module.php file Parameter Local File Inclusion CVE-2005-3639 18 Nov 2005 7.5 (v2) High Pass PHP Doc System index.php show Parameter Local File Inclusion CVE-2005-3878 29 Nov 2005 6.4 (v2) Medium Pass GuppY <= 4.5.9 Multiple Remote Vulnerabilities (Traversal, Code Exec) CVE-2005-3926 CVE-2005-3927 29 Nov 2005 8.8 (v3) High Pass PHPX admin/index.php username Parameter SQL Injection CVE-2005-3968 02 Dec 2005 7.5 (v2) High Pass Trac Ticket Query Module group Parameter SQL Injection CVE-2005-3980 02 Dec 2005 7.5 (v2) High Pass DUware Multiple Products type.asp iType Parameter SQL Injection CVE-2005-3976 CVE-2006-6354 CVE-2006-6367 02 Dec 2005 7.5 (v2) High Pass MediaWiki Language Option eval() Function Arbitrary PHP Code Execution CVE-2005-4031 05 Dec 2005 7.5 (v2) High Pass SugarCRM <= 4.0 beta acceptDecline.php Remote File Inclusion CVE-2005-4086 CVE-2005-4087 10 Dec 2005 7.5 (v2) High Pass Contenido contenido/classes/class.inuse.php Multiple Parameter Remote File Inclusion CVE-2005-4132 12 Dec 2005 7.5 (v2) High Pass FlatNuke index.php id Parameter Traversal Arbitrary File Access CVE-2005-2813 CVE-2005-4208 12 Dec 2005 5 (v2) Medium Pass The Includer includer.cgi Arbitrary Command Execution CVE-2005-0689 12 Dec 2005 7.5 (v2) High Pass phpCOIN < 1.2.2 2005-12-13 Fix-File Multiple Vulnerabilities CVE-2005-4211 CVE-2005-4212 CVE-2005-4213 14 Dec 2005 7.5 (v2) High Pass VMware ESX/GSX Server detection 14 Dec 2005 None Pass SimpleBBS topics.php name Parameter Arbitrary Command Execution CVE-2005-4135 14 Dec 2005 8.8 (v3) High Pass vTiger < 4.5a2 Multiple Vulnerabilities CVE-2005-3818 CVE-2005-3819 CVE-2005-3820 CVE-2005-3821 CVE-2005-3822 CVE-2005-3823 CVE-2005-3824 16 Dec 2005 7.5 (v2) High Pass ELOG Remote Buffer Overflow Vulnerabilities CVE-2005-4439 19 Dec 2005 7.8 (v2) High Pass Plogger plog-admin-functions.php config Parameter Remote File Inclusion CVE-2005-4573 21 Dec 2005 7.5 (v2) High Pass PhpGedView PGV_BASE_DIRECTORY Parameter Remote File Inclusion CVE-2005-4467 CVE-2005-4468 CVE-2005-4469 21 Dec 2005 7.5 (v2) High Pass Network Block Device (NBD) Server Request Handling Remote Overflow CVE-2005-3534 24 Dec 2005 7.5 (v2) High Pass MyBB calendar.php 'month' Parameter SQLi CVE-2005-4199 CVE-2005-4200 24 Dec 2005 10 (v2) Critical Pass Cerberus Support Center Multiple Remote Vulnerabilities (SQLi, XSS) CVE-2005-4427 CVE-2005-4428 29 Dec 2005 7.5 (v2) High Pass phpDocumentor <= 1.3.0 RC4 Local And Remote File Inclusion CVE-2005-4593 02 Jan 2006 7.5 (v2) High Pass Web Wiz check_user.asp txtUserName Parameter SQL Injection CVE-2005-4606 03 Jan 2006 7.5 (v2) High Pass PHP Support Tickets index.php Multiple Parameter SQL Injection CVE-2005-4264 04 Jan 2006 7.5 (v2) High Pass ADOdb server.php sql Parameter SQL Injection CVE-2006-0146 10 Jan 2006 7.5 (v2) High Pass Juniper NetScreen Security Manager (NSM) guiSrv/devSrv Crafted String Remote DoS CVE-2005-4587 10 Jan 2006 7.8 (v2) High Pass Eudora Internet Mail Server Admin Server Detection 16 Jan 2006 None Pass RCBlog index.php post Parameter Traversal Arbitrary File Access CVE-2006-0370 CVE-2006-0371 30 Jan 2006 5 (v2) Medium Pass Snitz Forums 2000 post.asp type Parameter XSS CVE-2005-3411 01 Feb 2006 4.3 (v2) Medium Pass Invision Power Board Dragoran Portal Module index.php site Parameter SQL Injection CVE-2006-0520 01 Feb 2006 7.5 (v2) High Pass MyBB index.php 'referrer' Parameter SQLi CVE-2006-1974 02 Feb 2006 7.5 (v2) High Pass Website Baker Admin Login SQL Injection CVE-2005-4140 02 Feb 2006 7.5 (v2) High Pass Grandstream Networks UCM6200 Series SQLi (Web UI) CVE-2020-5722 05 May 2022 9.8 (v3) Critical Pass Loudblog backend_settings.php Multiple Parameter Remote File Inclusion CVE-2006-0565 05 Feb 2006 7.5 (v2) High Pass PHP iCalendar Multiple Script Remote File Inclusion CVE-2006-0648 09 Feb 2006 5 (v2) Medium Pass PHP Xdebug Module Unauthenticated RCE (exploit) 31 Aug 2018 9.8 (v3) Critical Pass AXIS Multiple Vulnerabilities (ACV-128401) CVE-2018-10658 CVE-2018-10659 CVE-2018-10660 CVE-2018-10661 CVE-2018-10662 CVE-2018-10663 CVE-2018-10664 02 Oct 2018 9.8 (v3) Critical Pass Supermicro IPMI Baseboard Management Controller Default Credentials 05 Oct 2018 9.8 (v3) Critical Pass Rockwell Automation RSLinx Classic ENGINE.dll Stack Buffer Overflow CVE-2018-14829 28 Nov 2018 9.8 (v3) Critical Pass Rockwell Automation RSLinx Classic ENGINE.dll Stack Buffer Overflow (CVE-2019-6553) CVE-2019-6553 22 Mar 2019 9.8 (v3) Critical Pass AVEVA InduSoft Web Studio / InTouch Edge HMI TCP/IP Server Detection 22 Jan 2018 None Pass CyberArk Password Vault Web Access Detection 10 Apr 2018 None Pass GE Multilin UR / URPlus / B95Plus Protection Relay Cryptographic Algorithm Weakness Information DisclosurCVE-2017-7905e (UR-2017-0001) 26 May 2017 9.8 (v3) Critical 34
RELAYTO Penetration Test Results Page 33 Page 35