🚀 Just released:
Latio 2026 Application Security Market Report.
Read it in our Whitepapers.
100% Signal 0% Noise
Platform
Invicti Platform
Zero-noise AppSec platform
Scan Code
Secure code before runtime
SAST
Early static security analysis
Open Source (SCA)
Find vulnerable dependencies
SBOM & License Risk
Generate SBOMs and track licenses
Secrets
Detect exposed secrets in applications
Infrastructure as Code
Ingest IaC security findings
Container
Track container image vulnerabilities
Test Runtime
Test live applications like attackers
DAST & AI DAST
Test runtime, prove exploitability
Agentic Pentesting
Automate real-world attack techniques
API Security Testing
Discover and test APIs
Attack Surface Management
Identify exposed apps and endpoints
Cloud AppSec
Get a single-pane view of cloud app risk
AI AppSec
Scan smarter, accelerate remediation
Manage Vulnerabilities
See, prioritize, reduce AppSec risk
Vulnerability Management (ASPM)
Centralize and correlate AppSec findings
Compliance & Executive Reporting
Measure risk and impact
Threat Intelligence
Reachability, exploitability, and business logic
Solutions
API Discovery
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Invicti vs. Competitors
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Savings Calculator
Live Training
Partners
MSSP
Documentation
Vulnerability Database
Get a demo
Web Application Vulnerabilities Index
This page lists
X
vulnerabilities classified as 164.308(a) that can be detected by Invicti.
Select Category
Critical
High
Medium
Low
Best Practice
Information
Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Select Vulnerability
Vulnerability Name
Classification
Severity
ActiveMQ - Remote Code Execution (CVE-2023-46604)
ActiveMQ - Remote Code Execution (CVE-2023-46604)
PCI v3.2-6.5.1
,Â
CAPEC-242
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
,Â
Critical
Administration Page Detected
Administration Page Detected
PCI v3.2-6.5.8
,Â
CAPEC-87
,Â
CWE-425
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.9.4.1
,Â
WASC-34
,Â
OWASP 2013-A7
,Â
OWASP 2017-A5
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
,Â
Information
Backup File Disclosure
Backup File Disclosure
PCI v3.2-6.5.8
,Â
CAPEC-87
,Â
CWE-530
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
WASC-34
,Â
OWASP 2013-A7
,Â
OWASP 2017-A5
,Â
Low
Backup Source Code Detected
Backup Source Code Detected
PCI v3.2-6.5.8
,Â
CAPEC-87
,Â
CWE-530
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
WASC-34
,Â
OWASP 2013-A7
,Â
OWASP 2017-A5
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
,Â
High
Bash Command Injection Vulnerability (Shellshock Bug)
Bash Command Injection Vulnerability (Shellshock Bug)
PCI v3.2-6.5.1
,Â
CAPEC-88
,Â
CWE-78
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-31
,Â
OWASP 2013-A1
,Â
OWASP 2017-A9
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C
,Â
Critical
Blind Command Injection
Blind Command Injection
PCI v3.2-6.5.1
,Â
CAPEC-88
,Â
CWE-78
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-31
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
,Â
Critical
Blind MongoDB Injection
Blind MongoDB Injection
PCI v3.2-6.5.1
,Â
CWE-943
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
,Â
High
Blind SQL Injection
Blind SQL Injection
PCI v3.2-6.5.1
,Â
CAPEC-66
,Â
CWE-89
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-19
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
,Â
Critical
Boolean Based SQL Injection
Boolean Based SQL Injection
PCI v3.2-6.5.1
,Â
CAPEC-66
,Â
CWE-89
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-19
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Code Evaluation (Apache Struts)
Code Evaluation (Apache Struts)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/RL:O
,Â
Critical
Code Evaluation (Apache Struts S02-53)
Code Evaluation (Apache Struts S02-53)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Code Evaluation (Apache Struts) S2-016
Code Evaluation (Apache Struts) S2-016
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/RL:O
,Â
Critical
Code Evaluation (Apache Struts) S2-045
Code Evaluation (Apache Struts) S2-045
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/RL:O
,Â
Critical
Code Evaluation (Apache Struts) S2-046
Code Evaluation (Apache Struts) S2-046
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/RL:O
,Â
Critical
Code Evaluation (ASP)
Code Evaluation (ASP)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
,Â
Critical
Code Evaluation (Node.js)
Code Evaluation (Node.js)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
,Â
Critical
Drupal Core - Remote Code Execution (CVE-2019-6340)
Drupal Core - Remote Code Execution (CVE-2019-6340)
PCI v3.2-6.5.1
,Â
CAPEC-242
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
,Â
Critical
Elmah.axd / Errorlog.axd Detected
Elmah.axd / Errorlog.axd Detected
PCI v3.2-6.5.6
,Â
CAPEC-347
,Â
CWE-16
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
WASC-15
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C
,Â
High
Exception Report Disclosure (Tomcat)
Exception Report Disclosure (Tomcat)
PCI v3.2-6.5.5
,Â
CAPEC-214
,Â
CWE-248
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
WASC-14
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
HTTP Header Injection
HTTP Header Injection
PCI v3.2-6.5.1
,Â
CAPEC-105
,Â
CWE-93
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-24
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
,Â
Medium
HTTP Header Injection (IAST)
HTTP Header Injection (IAST)
PCI v3.2-6.5.1
,Â
CAPEC-105
,Â
CWE-93
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-24
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
,Â
Medium
Installation File Detected
Installation File Detected
PCI v3.2-6.5.8
,Â
CAPEC-87
,Â
CWE-425
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
WASC-34
,Â
OWASP 2013-A7
,Â
OWASP 2017-A5
,Â
Information
Internal Path Disclosure (*nix)
Internal Path Disclosure (*nix)
CAPEC-118
,Â
CWE-200
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.9.4.1
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
Internal Path Disclosure (Windows)
Internal Path Disclosure (Windows)
CAPEC-118
,Â
CWE-200
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.8.1.1
,Â
WASC-13
,Â
Information
Ivanti ICS and IPS Command Injection - CVE-2024-21887
Ivanti ICS and IPS Command Injection - CVE-2024-21887
PCI v3.2-6.5.1
,Â
CAPEC-88
,Â
CWE-78
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-31
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
LDAP Injection (IAST)
LDAP Injection (IAST)
PCI v3.2-6.5.1
,Â
CAPEC-66
,Â
CWE-89
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-19
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Log File Detected
Log File Detected
PCI v3.2-6.5.8
,Â
CAPEC-87
,Â
CWE-425
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
WASC-34
,Â
OWASP 2013-A7
,Â
OWASP 2017-A5
,Â
Information
Mail Header Injection (IAST)
Mail Header Injection (IAST)
PCI v3.2-6.5.1
,Â
CAPEC-66
,Â
CWE-20
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-19
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
,Â
Critical
Microsoft IIS Log File Detected
Microsoft IIS Log File Detected
PCI v3.2-6.5.8
,Â
CAPEC-87
,Â
CWE-425
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
WASC-34
,Â
OWASP 2013-A7
,Â
OWASP 2017-A5
,Â
Low
MongoDB Injection (IAST)
MongoDB Injection (IAST)
PCI v3.2-6.5.1
,Â
CAPEC-66
,Â
CWE-89
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-19
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Oracle WebLogic Remote Code Execution (CVE-2020-14882)
Oracle WebLogic Remote Code Execution (CVE-2020-14882)
PCI v3.2-6.5.1
,Â
CAPEC-242
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
,Â
Critical
Out of Band Code Evaluation (Apache Struts 2)
Out of Band Code Evaluation (Apache Struts 2)
PCI v3.2-6.5.1
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H/RL:O
,Â
Critical
Out of Band Code Evaluation (Apache Struts 2) S2-053
Out of Band Code Evaluation (Apache Struts 2) S2-053
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Evaluation (ASP)
Out of Band Code Evaluation (ASP)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Evaluation (Log4j)
Out of Band Code Evaluation (Log4j)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-502
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Evaluation (Node.js)
Out of Band Code Evaluation (Node.js)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Evaluation (Perl)
Out of Band Code Evaluation (Perl)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Evaluation (PHP)
Out of Band Code Evaluation (PHP)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Evaluation (Python)
Out of Band Code Evaluation (Python)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Evaluation (RoR)
Out of Band Code Evaluation (RoR)
PCI v3.2-6.5.1
,Â
CAPEC-356
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-23
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/RL:O
,Â
Critical
Out of Band Code Evaluation (RoR - JSON)
Out of Band Code Evaluation (RoR - JSON)
PCI v3.2-6.5.1
,Â
CAPEC-356
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-23
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
,Â
Critical
Out of Band Code Evaluation (Ruby)
Out of Band Code Evaluation (Ruby)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Execution via SSTI
Out of Band Code Execution via SSTI
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Execution via SSTI (Java FreeMarker)
Out of Band Code Execution via SSTI (Java FreeMarker)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Execution via SSTI (Java Velocity)
Out of Band Code Execution via SSTI (Java Velocity)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Execution via SSTI (Node.js Dot)
Out of Band Code Execution via SSTI (Node.js Dot)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Execution via SSTI (Node.js EJS)
Out of Band Code Execution via SSTI (Node.js EJS)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Execution via SSTI (Node.js Marko)
Out of Band Code Execution via SSTI (Node.js Marko)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Execution via SSTI (Node.js Nunjucks)
Out of Band Code Execution via SSTI (Node.js Nunjucks)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Execution via SSTI (Node.js Pug (Jade))
Out of Band Code Execution via SSTI (Node.js Pug (Jade))
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Execution via SSTI (PHP Smarty)
Out of Band Code Execution via SSTI (PHP Smarty)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Execution via SSTI (PHP Twig)
Out of Band Code Execution via SSTI (PHP Twig)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Execution via SSTI (Python Jinja)
Out of Band Code Execution via SSTI (Python Jinja)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Execution via SSTI (Python Mako)
Out of Band Code Execution via SSTI (Python Mako)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Code Execution via SSTI (Python Tornado)
Out of Band Code Execution via SSTI (Python Tornado)
PCI v3.2-6.5.1
,Â
CAPEC-23
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band Command Injection
Out of Band Command Injection
PCI v3.2-6.5.1
,Â
CAPEC-88
,Â
CWE-78
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-31
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band SAML Consumer Service XML Entity Injection
Out of Band SAML Consumer Service XML Entity Injection
PCI v3.2-6.5.1
,Â
CAPEC-376
,Â
CWE-611
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-43
,Â
OWASP 2013-A1
,Â
OWASP 2017-A4
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
,Â
High
Out of Band SAML Consumer Service XSLT Injection
Out of Band SAML Consumer Service XSLT Injection
PCI v3.2-6.5.1
,Â
CAPEC-376
,Â
CWE-611
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-43
,Â
OWASP 2013-A1
,Â
OWASP 2017-A4
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
,Â
High
Out of Band SQL Injection
Out of Band SQL Injection
PCI v3.2-6.5.1
,Â
CAPEC-66
,Â
CWE-89
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-19
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
Out of Band XML External Entity Injection
Out of Band XML External Entity Injection
PCI v3.2-6.5.1
,Â
CAPEC-376
,Â
CWE-611
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-43
,Â
OWASP 2013-A1
,Â
OWASP 2017-A4
,Â
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:H
,Â
High
Out-of-date Component ({applicationName})
Out-of-date Component ({applicationName})
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
WASC-13
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
PossibleBlindMongoDB
PossibleBlindMongoDB
PCI v3.2-6.5.1
,Â
CAPEC-66
,Â
CWE-89
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-19
,Â
OWASP 2013-A1
,Â
Critical
Possible Boolean Mongo Db Injection
Possible Boolean Mongo Db Injection
PCI v3.2-6.5.1
,Â
CAPEC-66
,Â
CWE-89
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-19
,Â
OWASP 2013-A1
,Â
Critical
Programming Error Message
Programming Error Message
PCI v3.2-6.5.5
,Â
CAPEC-118
,Â
CWE-210
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
WASC-13
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
Programming Error Message (Ruby)
Programming Error Message (Ruby)
PCI v3.2-6.5.5
,Â
CAPEC-118
,Â
CWE-210
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
WASC-13
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
Progress MOVEit Transfer SQL Injection
Progress MOVEit Transfer SQL Injection
PCI v3.2-6.5.1
,Â
CAPEC-66
,Â
CWE-89
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-19
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
High
Readme/Help File Detected
Readme/Help File Detected
PCI v3.2-6.5.8
,Â
CAPEC-87
,Â
CWE-425
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
WASC-34
,Â
OWASP 2013-A7
,Â
OWASP 2017-A5
,Â
Information
RegreSSHion Attack (CVE-2024-6387)
RegreSSHion Attack (CVE-2024-6387)
PCI v3.2-6.5.1
,Â
CAPEC-26
,Â
CWE-366
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A9
,Â
OWASP 2017-A9
,Â
Critical
Remote Code Execution and DoS in HTTP.sys (IIS)
Remote Code Execution and DoS in HTTP.sys (IIS)
PCI v3.2-6.5.1
,Â
CAPEC-340
,Â
CWE-20
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-7
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H/RL:W/RC:C
,Â
Critical
Remote Code Execution (Spring4Shell)
Remote Code Execution (Spring4Shell)
PCI v3.2-6.5.1
,Â
CAPEC-242
,Â
CWE-94
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
,Â
Critical
Server-Side Request Forgery (elmah)
Server-Side Request Forgery (elmah)
PCI v3.2-6.5.6
,Â
CAPEC-347
,Â
CWE-918
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-15
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C
,Â
High
Server-Side Request Forgery (elmah MVC)
Server-Side Request Forgery (elmah MVC)
PCI v3.2-6.5.6
,Â
CAPEC-347
,Â
CWE-918
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-15
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C
,Â
High
Server-Side Request Forgery (trace.axd)
Server-Side Request Forgery (trace.axd)
PCI v3.2-6.5.6
,Â
CAPEC-347
,Â
CWE-918
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-15
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C
,Â
Critical
Server-Side Template Injection
Server-Side Template Injection
PCI v3.2-6.5.1
,Â
CWE-74
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
1