Difference between revisions of "OWASP Joomla Vulnerability Scanner Limitations"

From OWASP
Jump to: navigation, search
(Limitations on Current Release)
 
Line 1: Line 1:
 
==Limitations on Current Release==
 
==Limitations on Current Release==
  
* The vulnerability database still lacks of unknown exploit checks. If the exploit check is not available, the scanner verify based on deduced version.  
+
* The vulnerability database still lacks of unknown exploit checks. If the exploit check is not available, the scanner verify based on deduced version. If deduced version is not available, it then cannot verify the vulnerability
    If deduced version is not available, it then cannot verify the vulnerability
+
 
* The Scanner lacks IDS evasion bypass
 
* The Scanner lacks IDS evasion bypass
 
* The Scanner lacks sophisticated fuzzing
 
* The Scanner lacks sophisticated fuzzing

Latest revision as of 12:58, 15 July 2009

Limitations on Current Release

  • The vulnerability database still lacks of unknown exploit checks. If the exploit check is not available, the scanner verify based on deduced version. If deduced version is not available, it then cannot verify the vulnerability
  • The Scanner lacks IDS evasion bypass
  • The Scanner lacks sophisticated fuzzing
  • The Scanner is not a full fledged SQL Injection tool