vish07 / WackoPicko

WackoPicko is a vulnerable web application used to test web application vulnerability scanners.
MIT License
0 stars 0 forks source link

Update README.markdown #55

Closed vish07 closed 4 years ago

vish07 commented 4 years ago

Scan submitted to Checkmarx

vish07 commented 4 years ago

Checkmarx scan completed

Full Scan Details

Violation Summary

Severity Count
High 77

Details

Lines Severity Category File Link
8 High Command_Injection website/users/check_pass.php Checkmarx
18 High Command_Injection website/pictures/high_quality.php Checkmarx
9 High Command_Injection website/passcheck.php Checkmarx
18 High Command_Injection website/pictures/conflictview.php Checkmarx
3 High File_Inclusion website/admin/index.php Checkmarx
27 29 High File_Manipulation website/pictures/upload.php Checkmarx
44 High Reflected_XSS_All_Clients website/comments/preview_comment.php Checkmarx
19 22 High Reflected_XSS_All_Clients website/pictures/search.php Checkmarx
22 35 High Reflected_XSS_All_Clients website/comments/add_comment.php Checkmarx
144 High Reflected_XSS_All_Clients website/include/html_functions.php Checkmarx
19 High Reflected_XSS_All_Clients website/submitname.php Checkmarx
16 High Reflected_XSS_All_Clients website/comments/delete_preview_comment.php Checkmarx
16 39 High Reflected_XSS_All_Clients website/users/login.php Checkmarx
83 High Reflected_XSS_All_Clients website/pictures/upload.php Checkmarx
49 High Reflected_XSS_All_Clients website/users/register.php Checkmarx
5 High Reflected_XSS_All_Clients website/error.php Checkmarx
35 High Reflected_XSS_All_Clients website/pictures/conflict.php Checkmarx
9 36 High Reflected_XSS_All_Clients website/passcheck.php Checkmarx
2 3 4 5 High Reflected_XSS_All_Clients website/test.php Checkmarx
12 High Reflected_XSS_All_Clients website/piccheck.php Checkmarx
3 High Remote_File_Inclusion website/admin/index.php Checkmarx
24 30 High SQL_Injection website/users/view.php Checkmarx
16 High SQL_Injection website/pictures/view_flymake.php Checkmarx
14 High SQL_Injection website/guestbook.php Checkmarx
14 High SQL_Injection website/comments/delete_preview_comment.php Checkmarx
10 High SQL_Injection website/admin/login.php Checkmarx
102 High SQL_Injection website/include/admins.php Checkmarx
29 30 39 47 High SQL_Injection website/pictures/upload.php Checkmarx
18 24 High SQL_Injection website/comments/preview_comment.php Checkmarx
16 High SQL_Injection website/pictures/view.php Checkmarx
31 71 104 High SQL_Injection website/cart/action.php Checkmarx
16 25 High SQL_Injection website/pictures/conflict.php Checkmarx
16 High SQL_Injection website/comments/add_comment.php Checkmarx
18 High SQL_Injection website/pictures/high_quality.php Checkmarx
18 High SQL_Injection website/users/register.php Checkmarx
18 High SQL_Injection website/pictures/conflictview.php Checkmarx
11 High SQL_Injection website/users/login.php Checkmarx
15 High SQL_Injection website/pictures/search.php Checkmarx
37 97 High Second_Order_SQL_Injection website/include/cart.php Checkmarx
22 102 157 High Second_Order_SQL_Injection website/include/users.php Checkmarx
117 197 High Second_Order_SQL_Injection website/include/pictures.php Checkmarx
60 High Second_Order_SQL_Injection website/include/comments.php Checkmarx
87 High Second_Order_SQL_Injection website/include/admins.php Checkmarx
28 High Stored_XSS website/include/comments.php Checkmarx
97 136 High Stored_XSS website/include/cart.php Checkmarx
19 39 60 79 98 117 132 221 High Stored_XSS website/include/pictures.php Checkmarx
15 High Stored_XSS website/include/guestbook.php Checkmarx
22 132 High Stored_XSS website/include/users.php Checkmarx
vish07 commented 4 years ago

hgfg