Web Application Detections Published in July 2024

Hitesh Kadu

In July, the Qualys Web Application Scanning (WAS) team issued a critical security signatures update. This update expands the scope to detect vulnerabilities in several widely-used software applications, including GeoServer, Progress MOVEit Transfer, JetBrains TeamCity, Apache Tomcat, Joomla, Splunk, Oracle WebLogic Server, ServiceNow, Apache HTTP Server, Apache RocketMQ, Progress Telerik Report Server, Spring Cloud, OpenObserve, Ivanti Endpoint Manager Mobile (EPMM), PHP, Adobe Magento, pdoc, Atlassian Jira Data Center and Server, PublicCMS, Webmin, Atlassian Bamboo Data Center and Server.

QIDTitle
150222Reverse Tabnabbing
150858Default Web Directory Paths Found
150885Children Privacy Policy Act COPPA Found
150997WordPress Export WP Page to Static HTML/CSS Plugin: Open Redirect Vulnerability (CVE-2024-3597)
151040Polyfill JavaScript Detected
152000WordPress Media Library Assistant Plugin: Time-based SQL Injection Vulnerability (CVE-2024-5605)
152001WordPress Popup Builder Plugin: Unauthorized Access of Functionality Vulnerability (CVE-2023-6696)
152003WordPress Blog2Social Plugin: SQL Injection Vulnerability (CVE-2024-3549)
152004WordPress Ad Invalid Click Protector(AICP) Plugin: Injected Backdoor Vulnerability (CVE-2024-6297)
152005WordPress Dokan Pro Plugin: SQL Injection Vulnerability (CVE-2024-3922)
152006WordPress Blaze-Widget Plugin: Injected Backdoor Vulnerability (CVE-2024-6297)
152007WordPress Britetechs Companion Plugin: Injected Backdoor Vulnerability (CVE-2024-6297)
152008GeoServer Classpath Resource Disclosure Vulnerability (CVE-2024-24749)
152009GeoServer Sensitive Information Exposure Vulnerability (CVE-2024-34696)
152010GeoServer Remote Code Execution (RCE) Vulnerability (CVE-2024-36401)
152013Progress MOVEit Transfer Improper Authentication Vulnerability (CVE-2024-5806)
152014WordPress Contact Form 7 Multi-Step Addon Plugin: Injected Backdoor Vulnerability (CVE-2024-6297)
152015WordPress Pods Plugin: Injected Backdoor Vulnerability (CVE-2024-6297)
152016WordPress PowerPress Podcasting Plugin: Injected Backdoor Vulnerability (CVE-2024-6297)
152017WordPress W3 Total Cache Plugin: Directory Traversal Vulnerability (CVE-2019-6715)
152018WordPress Seo Optimized Images Plugin: Injected Backdoor Vulnerability (CVE-2024-6297)
152019WordPress UsersWP Plugin: Time-Based SQL Injection Vulnerability (CVE-2024-6265)
152020 JetBrains TeamCity Sensitive Credential Exposure Vulnerabilities (CVE-2024-39878, CVE-2024-39879)
152021WordPress Simply Show Hooks Plugin: Injected Backdoor Vulnerability (CVE-2024-6297)
152022Apache Tomcat Denial of Service Vulnerability (CVE-2024-34750)
152023Joomla! HikaShop Extension SQL Injection Vulnerability (CVE-2023-38044)
152024Splunk Enterprise Path Traversal Vulnerability (CVE-2024-36991)
152025WordPress JSON API User Plugin: Unauthenticated Privilege Escalation Vulnerability (CVE-2024-6624)
152026Joomla! Core Cross Site Scripting Vulnerability (CVE-2024-26278)
152027Joomla! Core Cross Site Scripting Vulnerability (CVE-2024-26279)
152029Oracle WebLogic Server Multiple Vulnerabilities (CPUJUL2024)
152030Splunk Enterprise Remote Code Execution (RCE) Vulnerability (CVE-2024-36985)
152033ServiceNow Template Injection Vulnerability (CVE-2024-4879)
152034ServiceNow Input Validation Vulnerability (CVE-2024-5217)
152035Apache HTTP Server Source Code Disclosure Vulnerability (CVE-2024-40725)
152036Apache HTTP Server Server-Side Request Forgery (SSRF) Vulnerability (CVE-2024-40898)
152037WordPress WPCafe Plugin: Local File Inclusion(LFI) Vulnerability (CVE-2024-5431)
152038WordPress Auto Featured Image Plugin: Arbitrary File Upload Vulnerability (CVE-2024-6054)
152039WordPress Profile-Builder Plugin: Privilege Escalation Vulnerability (CVE-2024-6695)
152040Atlassian Confluence Data Center and Server Stored Cross-Site Scripting (XSS) Vulnerability (CVE-2024-21686)
152041WordPress Modern Events Calendar Plugin: Arbitrary File Upload Vulnerability (CVE-2024-5441)
152042WordPress Redux Framework Plugin: Unauthenticated JSON File Upload Vulnerability (CVE-2024-6828)
152043Apache RocketMQ Sensitive Information Disclosure Vulnerability (CVE-2024-23321)
152044WordPress Wallet for WooCommerce Plugin: SQL Injection Vulnerability (CVE-2024-6353)
152045WordPress Keydatas Plugin: Arbitrary File Upload Vulnerability (CVE-2024-6220)
152046Progress Telerik Report Server Insecure Deserialization Vulnerability (CVE-2024-6327)
152047JetBrains TeamCity Insufficient Session Expiration Vulnerability (CVE-2024-41827)
152048JetBrains TeamCity Sensitive Data Leakage in Build Logs Vulnerability (CVE-2024-41824)
152049JetBrains TeamCity Stored Cross-Site Scripting (XSS) Vulnerabilities (CVE-2024-41825,CVE-2024-41826)
152050JetBrains TeamCity Inconsistent Token Timing Vulnerability (CVE-2024-41828)
152051JetBrains TeamCity OAuth Code Exposure Vulnerability (CVE-2024-41829)
152055Spring Cloud Data Flow Remote Code Execution Vulnerability (CVE-2024-37084)
152056OpenObserve Cross-Site Scripting (XSS) Vulnerability (CVE-2024-41808)
152057Progress MOVEit Transfer Improper Authentication Vulnerability (CVE-2024-6576)
152060Ivanti Endpoint Manager Mobile (EPMM) Insufficient Authorization Vulnerability (CVE-2024-36130)
152061Ivanti Endpoint Manager Mobile (EPMM) Insecure Deserialization Vulnerability (CVE-2024-36131)
152062Ivanti Endpoint Manager Mobile (EPMM) Improper Authentication Vulnerabilities (CVE-2024-36132,CVE-2024-34788)
152064WordPress Yoast SEO Plugin: Stored Cross-Site Scripting (XSS) Vulnerability (CVE-2024-4984)
152100PHP Insufficient Verification of Data Authenticity (CVE-2024-5458)
152102Malicious Polyfill.io Source Detected
152103Apache HTTP Server Prior to 2.4.60 Multiple Security Vulnerabilities
152104Adobe Magento XML External Entity (XXE) Vulnerability (CVE-2024-34102)
152105JavaScript in pdoc uses polyfill.io (CVE-2024-38526)
520018Atlassian Jira Data Center and Server Information Disclosure Vulnerability (CVE-2024-21685)
520019PublicCMS Multiple SSRF Vulnerabilities (CVE-2024-40543,CVE-2024-40544)
520020PublicCMS Arbitrary File Upload Vulnerability (CVE-2024-40545)
520021Webmin Cross-Site Scripting Vulnerability (CVE-2024-36450)
520022Webmin Improper Authorization Vulnerability (CVE-2024-36451)
520023Webmin Cross-Site Scripting Vulnerability (CVE-2024-36452)
520024Webmin Cross-Site Scripting Vulnerability (CVE-2024-36453)
520025Atlassian Bamboo Data Center and Server File Inclusion Vulnerability (CVE-2024-21687)
520026Atlassian Bamboo Data Center and Server SSRF (Server-Side Request Forgery) Vulnerability (CVE-2024-22262)
Share your Comments

Comments

Your email address will not be published. Required fields are marked *