- Apache Axis2 is installed on this application server. By accessing a specific URL (/services/listServices) it's possible to list all the available web services deployed in this server.
- If you don't want these services to be publicly available you need to restrict access to the /services/listServices URL.
- WordPress REST API User Enumeration
- WordPress Plugin CP Image Store with Slideshow Arbitrary File Download (1.0.5)
- WordPress Plugin Advanced XML Reader XML External Entity Information Disclosure (0.3.4)
- ColdFusion Request Debugging information disclosure
- Joomla! Core Information Disclosure (1.5.0 - 3.8.1)