11.05.2014 Views

Web Application Vulnerability Testing with Nessus - owasp

Web Application Vulnerability Testing with Nessus - owasp

Web Application Vulnerability Testing with Nessus - owasp

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Reviewing the Report for<br />

2007 OWASP Top Items<br />

2007 A3–Malicious File Execution<br />

• Command Execution (CGI abuses) > 39465, 44967<br />

2007 A6 –Information Leakage and Improper Error Handling<br />

• Directory Traversal (CGI abuses) > 39467, 46195, 46194<br />

• File Inclusion (CGI abuses) > 39469, 42056, 42872<br />

• Server Side Includes (CGI abuses) > 42423, 42054<br />

• Error Messages > 40406, 48926, 48927<br />

123

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!