Vulnerability Classification
Vulnerability Classification
Boolean Based SQL Injection PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
66, WASC-19, OWASP 2013-A1
Code Evaluation (Apache Struts S02- PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
53) 23, OWASP 2013-A1
Code Evaluation (Apache Struts) PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
23, OWASP 2013-A1
Code Evaluation (Apache Struts) S2- PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
045 23, OWASP 2013-A1
Code Evaluation (Apache Struts) S2- PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
046 23, OWASP 2013-A1
Code Evaluation (RoR - JSON) PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
356, WASC-23, OWASP 2013-A1
Code Evaluation via Local File PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
Inclusion (PHP) 251, WASC-33, OWASP 2013-A1
Code Execution via File Upload PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
210, WASC-42, OWASP 2013-A1
Code Execution via Local File PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
Inclusion 170, WASC-33, OWASP 2013-A1
Code Execution via Server-Side PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
Template Injection 23, OWASP 2013-A1
Code Execution via Server-Side PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
Template Injection (Java FreeMarker) 23, OWASP 2013-A1
Code Execution via Server-Side PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
Template Injection (Java Velocity) 23, OWASP 2013-A1
Code Execution via Server-Side PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
Template Injection (Node.js Dot) 23, OWASP 2013-A1
Code Execution via Server-Side PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
Template Injection (Node.js EJS) 23, OWASP 2013-A1
Code Execution via Server-Side PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
Template Injection (Node.js Marko) 23, OWASP 2013-A1
Code Execution via Server-Side PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
Template Injection (Node.js 23, OWASP 2013-A1
Nunjucks)
Vulnerability Name Classifications Severity
Code Execution via Server-Side PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
Template Injection (Node.js Pug 23, OWASP 2013-A1
(Jade))
Code Execution via Server-Side PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
Template Injection (PHP Smarty) 23, OWASP 2013-A1
Code Execution via Server-Side PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
Template Injection (PHP Twig) 23, OWASP 2013-A1
Code Execution via Server-Side PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
Template Injection (Python Jinja) 23, OWASP 2013-A1
Code Execution via Server-Side PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
Template Injection (Python Mako) 23, OWASP 2013-A1
Code Execution via Server-Side PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
Template Injection (Python Tornado) 23, OWASP 2013-A1
Code Execution via Server-Side PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
Template Injection (Ruby ERB) 23, OWASP 2013-A1
Code Execution via Server-Side PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
Template Injection (Ruby Slim) 23, OWASP 2013-A1
Code Execution via WebDAV PCI v3.1-6.5.8, PCI v3.2-6.5.8, CAPEC- Critical
17, WASC-17
Out of Band Code Evaluation (Apache PCI v3.1-6.5.1, PCI v3.2-6.5.1, OWASP Critical
Struts 2) 2013-A1
Vulnerability Name Classifications Severity
Out of Band Code Evaluation (Apache PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
Struts 2) S2-053 23, OWASP 2013-A1
Out of Band Code Evaluation (ASP) PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
23, OWASP 2013-A1
Out of Band Code Evaluation (Perl) PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
23, OWASP 2013-A1
Out of Band Code Evaluation (PHP) PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
23, OWASP 2013-A1
Out of Band Code Evaluation (RoR - PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
JSON) 356, WASC-23, OWASP 2013-A1
Out of Band Code Evaluation (RoR) PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
356, WASC-23, OWASP 2013-A1
Out of Band Command Injection PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
88, WASC-31, OWASP 2013-A1
Out of Band Remote File Inclusion PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
193, WASC-5, OWASP 2013-A1
Out of Band SQL Injection PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
66, WASC-19, OWASP 2013-A1
Remote Code Execution and DoS in PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- Critical
HTTP.sys (IIS) 340, WASC-7, OWASP 2013-A1
Server-Side Template Injection (Java PCI v3.1-6.5.1, PCI v3.2-6.5.1, OWASP Critical
FreeMarker) 2013-A1
Server-Side Template Injection (Java PCI v3.1-6.5.1, PCI v3.2-6.5.1, OWASP Critical
Velocity) 2013-A1
Server-Side Template Injection (Ruby PCI v3.1-6.5.1, PCI v3.2-6.5.1, OWASP Critical
ERB) 2013-A1
Backup Source Code Detected PCI v3.1-6.5.8, PCI v3.2-6.5.8, CAPEC- High
87, WASC-34, OWASP 2013-A7
Basic Authorization over HTTP PCI v3.1-6.5.4, PCI v3.2-6.5.4, CAPEC- High
65, WASC-4, OWASP 2013-A6
Certificate is Signed Using a Weak PCI v3.1-6.5.4, PCI v3.2-6.5.4, CAPEC- High
Signature Algorithm 459, WASC-4, OWASP PC-C7, OWASP
2013-A6
Vulnerability Name Classifications Severity
Cross-site Scripting (DOM based) PCI v3.1-6.5.7, PCI v3.2-6.5.7, CAPEC- High
19, WASC-8, OWASP 2013-A3
Cross-site Scripting via Remote File PCI v3.1-6.5.7, PCI v3.2-6.5.7, CAPEC- High
Inclusion 19, WASC-8, OWASP 2013-A3
Database User Has Admin Privileges PCI v3.1-6.5.6, PCI v3.2-6.5.6, WASC- High
14, OWASP 2013-A5
Out of Band XML External Entity PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- High
Injection 376, WASC-43, OWASP 2013-A1
Out-of-date Version (Microsoft SQL PCI v3.1-6.2, PCI v3.2-6.2, CAPEC- High
Server) 310, OWASP 2013-A9
Password Transmitted over HTTP PCI v3.1-6.5.4, PCI v3.2-6.5.4, CAPEC- High
65, WASC-4, OWASP 2013-A6
ROBOT Attack Detected (Strong PCI v3.1-6.5.4, PCI v3.2-6.5.4, CAPEC- High
Oracle) 217, WASC-4, OWASP 2013-A6
ROBOT Attack Detected (Weak PCI v3.1-6.5.4, PCI v3.2-6.5.4, CAPEC- High
Oracle) 217, WASC-4, OWASP 2013-A6
Server-Side Request Forgery (elmah PCI v3.1-6.5.6, PCI v3.2-6.5.6, CAPEC- High
MVC) 347, WASC-15, OWASP 2013-A5
Server-Side Request Forgery (elmah) PCI v3.1-6.5.6, PCI v3.2-6.5.6, CAPEC- High
347, WASC-15, OWASP 2013-A5
WebDAV Directory Has Write PCI v3.1-6.5.8, PCI v3.2-6.5.8, WASC- High
Permissions 17
XML External Entity Injection PCI v3.1-6.5.1, PCI v3.2-6.5.1, CAPEC- High
376, WASC-43, OWASP 2013-A1
Critical Form Send to HTTP PCI v3.1-6.5.4, PCI v3.2-6.5.4, CAPEC- Medium
65, WASC-4, OWASP 2013-A6
Critical Form Served over HTTP PCI v3.1-6.5.4, PCI v3.2-6.5.4, CAPEC- Medium
65, WASC-4, OWASP 2013-A6
Microsoft Access Database File PCI v3.1-6.5.8, PCI v3.2-6.5.8, WASC- Medium
Detected 2, OWASP 2013-A7
Password Transmitted over Query PCI v3.1-6.5.4, PCI v3.2-6.5.4, WASC- Medium
String 13, OWASP 2013-A6
SQLite Database File Found PCI v3.1-6.5.8, PCI v3.2-6.5.8, WASC- Medium
2, OWASP 2013-A7
Stack Trace Disclosure (ColdFusion) PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC- Medium
214, WASC-14, OWASP 2013-A5
Vulnerability Name Classifications Severity
Stack Trace Disclosure (Django) PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC- Medium
214, WASC-14, OWASP 2013-A5
Stack Trace Disclosure (Java) PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC- Medium
214, WASC-14, OWASP 2013-A5
Stack Trace Disclosure (Laravel) PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC- Medium
214, WASC-14, OWASP 2013-A5
Stack Trace Disclosure (Python) PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC- Medium
214, WASC-14, OWASP 2013-A5
Stack Trace Disclosure (RoR) PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC- Medium
214, WASC-14, OWASP 2013-A5
Stack Trace Disclosure (Ruby-Sinatra PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC- Medium
Framework) 214, WASC-14, OWASP 2013-A5
WordPress Setup Configuration File PCI v3.1-6.5.8, PCI v3.2-6.5.8, CAPEC- Medium
212, WASC-14, OWASP 2013-A5
Cross-site Request Forgery in Login PCI v3.1-6.5.9, PCI v3.2-6.5.9, CAPEC- Low
Form 62, WASC-9, OWASP 2013-A8
Database Error Message Disclosure PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC- Low
118, WASC-13, OWASP 2013-A5
Database Name Disclosure (MySQL) PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC- Low
118, WASC-13, OWASP 2013-A5
Django Debug Mode Enabled PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC- Low
214, WASC-14, OWASP 2013-A5
Exception Report Disclosure (Tomcat) PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC- Low
214, WASC-14, OWASP 2013-A5
Laravel Debug Mode Enabled PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC- Low
214, WASC-14, OWASP 2013-A5
Microsoft IIS Log File Detected PCI v3.1-6.5.8, PCI v3.2-6.5.8, CAPEC- Low
87, WASC-34, OWASP 2013-A7
Microsoft Outlook Personal Folders PCI v3.1-6.5.8, PCI v3.2-6.5.8, WASC- Low
File (.pst) Found 2, OWASP 2013-A7
RoR Development Mode Enabled PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC- Low
214, WASC-14, OWASP 2013-A5
Social Security Number Disclosure PCI v3.1-6.5.3, PCI v3.2-6.5.3, CAPEC- Low
118, WASC-13, OWASP 2013-A6
Stack Trace Disclosure (Apache PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC- Low
MyFaces) 214, WASC-14, OWASP 2013-A5
Stack Trace Disclosure (ASP.NET) PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC- Low
214, WASC-14, OWASP 2013-A5
Stack Trace Disclosure (Grails) PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC- Low
214, WASC-14, OWASP 2013-A5
Vulnerability Name Classifications Severity
Struts2 Development Mode Enabled PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC- Low
214, WASC-14, OWASP 2013-A5
Username Disclosure (Microsoft SQL PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC- Low
Server) 118, WASC-13, OWASP 2013-A5
Out-of-date Version (Form Tools) PCI v3.1-6.2, PCI v3.2-6.2, CAPEC- Information
310, OWASP PC-C1, OWASP 2013-A9
Out-of-date Version (Fuel UX) PCI v3.1-6.2, PCI v3.2-6.2, CAPEC- Information
310, OWASP PC-C1, OWASP 2013-A9
Vulnerability Name Classifications Severity
Out-of-date Version (HTML5 Shiv) PCI v3.1-6.2, PCI v3.2-6.2, CAPEC- Information
310, OWASP PC-C1, OWASP 2013-A9
Out-of-date Version (jQuery Mask) PCI v3.1-6.2, PCI v3.2-6.2, CAPEC- Information
310, OWASP PC-C1, OWASP 2013-A9
Out-of-date Version (jQuery Migrate) PCI v3.1-6.2, PCI v3.2-6.2, CAPEC- Information
310, OWASP PC-C1, OWASP 2013-A9
Vulnerability Name Classifications Severity
Out-of-date Version (jQuery Mobile) PCI v3.1-6.2, PCI v3.2-6.2, CAPEC- Information
310, OWASP PC-C1, OWASP 2013-A9
Out-of-date Version (Movable Type) PCI v3.1-6.2, PCI v3.2-6.2, CAPEC- Information
310, OWASP PC-C1, OWASP 2013-A9
Out-of-date Version (Php Address PCI v3.1-6.2, PCI v3.2-6.2, CAPEC- Information
Book) 310, OWASP PC-C1, OWASP 2013-A9
Out-of-date Version (Prototype JS) PCI v3.1-6.2, PCI v3.2-6.2, CAPEC- Information
310, OWASP PC-C1, OWASP 2013-A9
Out-of-date Version (Semantic UI) PCI v3.1-6.2, PCI v3.2-6.2, CAPEC- Information
310, OWASP PC-C1, OWASP 2013-A9
Out-of-date Version (Vanilla Forums) PCI v3.1-6.2, PCI v3.2-6.2, CAPEC- Information
310, OWASP PC-C1, OWASP 2013-A9
Out-of-date Version (YetiForce CRM) PCI v3.1-6.2, PCI v3.2-6.2, CAPEC- Information
310, OWASP PC-C1, OWASP 2013-A9
Out-of-date Version (Zen Cart) PCI v3.1-6.2, PCI v3.2-6.2, CAPEC- Information
310, OWASP PC-C1, OWASP 2013-A9
UNC Server and Share Disclosure WASC-15, OWASP PC-C7, OWASP Information
2013-A5