Security Findings

Prioritized vulnerabilities discovered during penetration testing

1
Critical
1
High
1
Medium
1
Low
ImpactFindingDescriptionProofActions
CRITICALWeak Active Directory PasswordsMultiple user accounts have weak passwords that can be cracked within minutes using common password lists.Proof of vulnerability
HIGHUnpatched Apache Server (CVE-2021-41773)Apache HTTP Server 2.4.49 is vulnerable to path traversal and remote code execution.Proof of vulnerability
MEDIUMSQL Injection in Login FormThe login form is vulnerable to SQL injection attacks, allowing unauthorized database access.Proof of vulnerability
LOWMissing Security HeadersWeb application is missing critical security headers (CSP, X-Frame-Options, HSTS).Proof of vulnerability

Remediation Guidance