README.md in yawast-0.7.0.beta2 vs README.md in yawast-0.7.0.beta3
- old
+ new
@@ -51,11 +51,11 @@
* *(Generic)* Presence of WS_FTP.LOG
* *(Generic)* Presence of RELEASE-NOTES.txt
* *(Generic)* Presence of readme.html
* *(Generic)* Presence of CHANGELOG.txt
* *(Generic)* Missing cookie flags (Secure, HttpOnly, and SameSite)
-* *(Generic)* Search for 14,169 common files (via `--files`) & 21,332 common directories (via `--dir`)
+* *(Generic)* Search for 14,405 common files (via `--files`) & 21,332 common directories (via `--dir`)
* *(Apache)* Info Disclosure: Module listing enabled
* *(Apache)* Info Disclosure: Server version
* *(Apache)* Info Disclosure: OpenSSL module version
* *(Apache)* Presence of /server-status
* *(Apache)* Presence of /server-info
@@ -63,18 +63,22 @@
* *(Apache Tomcat)* Presence of Tomcat Host Manager
* *(Apache Tomcat)* Tomcat Manager Weak Password
* *(Apache Tomcat)* Tomcat Host Manager Weak Password
* *(Apache Tomcat)* Tomcat version detection via invalid HTTP verb
* *(Apache Tomcat)* Tomcat PUT RCE (CVE-2017-12617)
+* *(Apache Tomcat)* Tomcat Windows RCE (CVE-2019-0232)
* *(Apache Struts)* Sample files which may be vulnerable
+* *(Nginx)* Info Disclosure: Server version
+* *(Nginx)* Info Disclosure: Server status
* *(IIS)* Info Disclosure: Server version
* *(ASP.NET)* Info Disclosure: ASP.NET version
* *(ASP.NET)* Info Disclosure: ASP.NET MVC version
* *(ASP.NET)* Presence of Trace.axd
* *(ASP.NET)* Presence of Elmah.axd
* *(ASP.NET)* Debugging Enabled
* *(nginx)* Info Disclosure: Server version
* *(PHP)* Info Disclosure: PHP version
+* *(Rails)* File Content Disclosure: CVE-2019-5418
CMS Detection:
* Generic (Generator meta tag) *[Real detection coming as soon as I get around to it...]*