Page | Result | Pass | Fail | Ignore | Other |
BlindSQLInjectionVulnerability-LEVEL_1 | FAIL  | | AdvSqli | | |
BlindSQLInjectionVulnerability-LEVEL_2 | FAIL  | | AdvSqli | | |
CommandInjection-LEVEL_1 | PASS  | CommandInjection | SqliteSqli | | LDAPi ContentCache 90028 XContent 90004 |
CommandInjection-LEVEL_2 | FAIL  | | CommandInjection | | |
CommandInjection-LEVEL_3 | FAIL  | | CommandInjection | | |
CommandInjection-LEVEL_4 | FAIL  | | CommandInjection | | |
CommandInjection-LEVEL_5 | FAIL  | | SqliteSqli | | 90028 |
ErrorBasedSQLInjectionVulnerability-LEVEL_1 | FAIL  | | AdvSqli | | |
ErrorBasedSQLInjectionVulnerability-LEVEL_2 | FAIL  | | AdvSqli | | |
ErrorBasedSQLInjectionVulnerability-LEVEL_3 | FAIL  | | AdvSqli | | |
ErrorBasedSQLInjectionVulnerability-LEVEL_4 | FAIL  | | AdvSqli | | |
Http3xxStatusCodeBasedInjection-LEVEL_1 | FAIL  | | SqliteSqli | | 90028 |
Http3xxStatusCodeBasedInjection-LEVEL_2 | FAIL  | | OpenRedir | | |
Http3xxStatusCodeBasedInjection-LEVEL_3 | FAIL  | | OpenRedir | | |
Http3xxStatusCodeBasedInjection-LEVEL_4 | FAIL  | | OpenRedir | | |
Http3xxStatusCodeBasedInjection-LEVEL_5 | FAIL  | | SqliteSqli | | 90028 |
Http3xxStatusCodeBasedInjection-LEVEL_6 | FAIL  | | SqliteSqli | | 90028 |
Http3xxStatusCodeBasedInjection-LEVEL_7 | FAIL  | | OpenRedir | | |
JWTVulnerability-LEVEL_1 | FAIL  | | JWT | | |
JWTVulnerability-LEVEL_2 | FAIL  | | JWT | | |
JWTVulnerability-LEVEL_3 | FAIL  | | JWT | | |
JWTVulnerability-LEVEL_4 | FAIL  | | JWT | | |
JWTVulnerability-LEVEL_5 | FAIL  | | JWT | | |
JWTVulnerability-LEVEL_6 | FAIL  | | JWT | | |
JWTVulnerability-LEVEL_7 | FAIL  | | JWT | | |
JWTVulnerability-LEVEL_8 | FAIL  | | JWT | | |
JWTVulnerability-LEVEL_9 | FAIL  | | SqliteSqli | | 90028 |
PathTraversal-LEVEL_1 | FAIL  | | PathTrav | | |
PathTraversal-LEVEL_10 | FAIL  | | PathTrav | | |
PathTraversal-LEVEL_11 | FAIL  | | PathTrav | | |
PathTraversal-LEVEL_12 | FAIL  | | PathTrav | | |
PathTraversal-LEVEL_2 | FAIL  | | PathTrav | | |
PathTraversal-LEVEL_3 | FAIL  | | PathTrav | | |
PathTraversal-LEVEL_4 | FAIL  | | PathTrav | | |
PathTraversal-LEVEL_5 | FAIL  | | SqliteSqli | | 90028 |
PathTraversal-LEVEL_6 | FAIL  | | SqliteSqli | | 90028 |
PathTraversal-LEVEL_7 | FAIL  | | PathTrav | | |
PathTraversal-LEVEL_8 | FAIL  | | PathTrav | | |
PathTraversal-LEVEL_9 | FAIL  | | PathTrav | | |
PersistentXSSInHTMLTagVulnerability-LEVEL_1 | FAIL  | | PXSSS | | |
PersistentXSSInHTMLTagVulnerability-LEVEL_2 | FAIL  | | PXSSS | | |
PersistentXSSInHTMLTagVulnerability-LEVEL_3 | FAIL  | | PXSSS | | |
PersistentXSSInHTMLTagVulnerability-LEVEL_4 | FAIL  | | PXSSS | | |
PersistentXSSInHTMLTagVulnerability-LEVEL_5 | FAIL  | | PXSSS | | |
PersistentXSSInHTMLTagVulnerability-LEVEL_6 | FAIL  | | PXSSS | | |
PersistentXSSInHTMLTagVulnerability-LEVEL_7 | FAIL  | | SqliteSqli | | 90028 |
PersistentXSSInHTMLTagVulnerability-LEVEL_8 | FAIL  | | SqliteSqli | | 90028 |
UnionBasedSQLInjectionVulnerability-LEVEL_1 | FAIL  | | AdvSqli | | |
UnionBasedSQLInjectionVulnerability-LEVEL_2 | FAIL  | | AdvSqli | | |
UnionBasedSQLInjectionVulnerability-LEVEL_3 | PASS  | SqliteSqli | | | 90028 |
UnrestrictedFileUpload-LEVEL_1 | FAIL  | | PathTrav RXSS PXSSS | | |
UnrestrictedFileUpload-LEVEL_2 | FAIL  | | RXSS PXSSS | | |
UnrestrictedFileUpload-LEVEL_3 | FAIL  | | RXSS PXSSS | | |
UnrestrictedFileUpload-LEVEL_4 | FAIL  | | RXSS PXSSS | | |
UnrestrictedFileUpload-LEVEL_5 | FAIL  | | RXSS PXSSS | | |
UnrestrictedFileUpload-LEVEL_6 | FAIL  | | RXSS PXSSS | | |
UnrestrictedFileUpload-LEVEL_7 | FAIL  | | SqliteSqli | | 90028 |
UnrestrictedFileUpload-LEVEL_8 | FAIL  | | SqliteSqli | | 90028 |
XSSInImgTagAttribute-LEVEL_1 | PASS  | RXSS | SqliteSqli | | DXSS 90028 SrcInc |
XSSInImgTagAttribute-LEVEL_2 | PASS  | RXSS | SqliteSqli | | DXSS 90028 SrcInc |
XSSInImgTagAttribute-LEVEL_3 | PASS  | RXSS | | | 90028 SrcInc |
XSSInImgTagAttribute-LEVEL_4 | PASS  | RXSS | | | LDAPi 90028 SrcInc |
XSSInImgTagAttribute-LEVEL_5 | PASS  | RXSS | | | 90028 SrcInc |
XSSInImgTagAttribute-SECURE | FAIL  | | RXSS | | |
XSSWithHTMLTagInjection-LEVEL_1 | PASS  | RXSS | | | DXSS 90028 SrcInc |
XSSWithHTMLTagInjection-LEVEL_2 | FAIL  | | SqliteSqli | | 90028 |
XSSWithHTMLTagInjection-LEVEL_3 | FAIL  | | SqliteSqli | | 90028 |
XXEVulnerability-LEVEL_1 | FAIL  | | XXE | | |
XXEVulnerability-LEVEL_2 | FAIL  | | XXE | | |
XXEVulnerability-LEVEL_3 | FAIL  | | XXE | | |
Plugin | ms | Reqs | Quality |
Path Traversal | 0:01:49.969 | 36858 | release |
Remote File Inclusion | 0:01:12.677 | 29120 | release |
Source Code Disclosure - /WEB-INF folder | 0:00:00.016 | 0 | release |
External Redirect | 0:00:24.451 | 4576 | release |
Server Side Include | 0:00:16.559 | 1664 | release |
Cross Site Scripting (Reflected) | 0:00:15.081 | 1401 | release |
Cross Site Scripting (Persistent) - Prime | 0:00:15.414 | 416 | release |
Cross Site Scripting (Persistent) - Spider | 0:00:05.182 | 129 | release |
Cross Site Scripting (Persistent) | 0:00:14.822 | 0 | release |
SQL Injection | 0:01:49.498 | 23410 | release |
Server Side Code Injection | 0:00:22.712 | 3328 | release |
Remote OS Command Injection | 0:01:41.047 | 35193 | release |
Directory Browsing | 0:00:04.268 | 129 | release |
Buffer Overflow | 0:00:15.837 | 377 | release |
Format String Error | 0:00:15.939 | 1131 | release |
CRLF Injection | 0:00:22.241 | 2912 | release |
Parameter Tampering | 0:00:20.889 | 1844 | release |
ELMAH Information Leak | 0:00:00.022 | 1 | release |
.htaccess Information Leak | 0:00:04.450 | 25 | release |
Script Active Scan Rules | 0:00:00.008 | 0 | release |
Source Code Disclosure - Git | 0:00:04.165 | 0 | beta |
Source Code Disclosure - File Inclusion | 0:00:55.591 | 382 | beta |
Remote Code Execution - Shell Shock | 0:00:15.119 | 832 | beta |
Httpoxy - Proxy Header Misuse | 0:00:14.510 | 645 | beta |
Anti-CSRF Tokens Check | 0:00:01.236 | 0 | beta |
Cross-Domain Misconfiguration | 0:00:00.034 | 2 | beta |
Heartbleed OpenSSL Vulnerability | 0:00:00.049 | 2 | beta |
Source Code Disclosure - CVE-2012-1823 | 0:00:04.751 | 103 | beta |
Remote Code Execution - CVE-2012-1823 | 0:00:11.777 | 258 | beta |
Session Fixation | 0:00:01.430 | 0 | beta |
SQL Injection - MySQL | 0:00:45.736 | 9152 | beta |
SQL Injection - Hypersonic SQL | 0:00:36.300 | 7072 | beta |
SQL Injection - Oracle | 0:00:33.774 | 5408 | beta |
SQL Injection - PostgreSQL | 0:00:36.437 | 7072 | beta |
SQL Injection - SQLite | 0:02:42.094 | 35482 | beta |
Cross Site Scripting (DOM Based) | 0:13:15.167 | 1673 | beta |
SQL Injection - MsSQL | 0:00:34.450 | 6386 | beta |
Advanced SQL Injection | 1:39:25.087 | 1549063 | beta |
XPath Injection | 0:00:16.408 | 1248 | beta |
XML External Entity Attack | 0:00:01.478 | 0 | beta |
Generic Padding Oracle | 0:00:14.912 | 2 | beta |
Expression Language Injection | 0:00:14.392 | 416 | beta |
Cloud Metadata Potentially Exposed | 0:00:00.043 | 1 | beta |
Source Code Disclosure - SVN | 0:00:10.527 | 261 | beta |
Relative Path Confusion | 0:00:02.491 | 18 | beta |
Apache Range Header DoS (CVE-2011-3192) | 0:00:04.934 | 145 | beta |
Backup File Disclosure | 0:01:54.259 | 26639 | beta |
HTTP Only Site | 0:00:00.103 | 0 | beta |
Integer Overflow Error | 0:00:20.185 | 1508 | beta |
Proxy Disclosure | 0:00:03.822 | 129 | beta |
Trace.axd Information Leak | 0:00:03.795 | 25 | beta |
.env Information Leak | 0:00:03.632 | 25 | beta |
Hidden File Finder | 0:00:00.356 | 38 | beta |
XSLT Injection | 0:00:17.580 | 2896 | beta |
Insecure HTTP Method | 0:00:33.918 | 1548 | beta |
HTTPS Content Available via HTTP | 0:00:01.668 | 0 | beta |
GET for POST | 0:00:01.788 | 0 | beta |
User Agent Fuzzer | 0:00:32.674 | 903 | beta |
HTTP Parameter Pollution | 0:00:01.714 | 0 | beta |
Possible Username Enumeration | 0:00:00.022 | 0 | beta |
Cookie Slack Detector | 0:00:01.084 | 0 | beta |
LDAP Injection | 0:02:50.175 | 1135 | alpha |
NoSQL Injection - MongoDB | 0:00:47.772 | 9296 | alpha |
Example Active Scan Rule: Denial of Service | 0:00:14.663 | 0 | alpha |
An example active scan rule which loads data from a file | 0:00:14.613 | 0 | alpha |
JWT Scan Rule | 0:00:15.126 | 0 | alpha |
| | | |
Total | 2:19:32 | - | - |