Audit Features Comparison - Web Application Scanners:

The current information is based on the results of the *2011* benchmark (excpet for entries marked as updated or new )

Last updated: 27/08/2012
Sorted in a descending order according to the scanner's number of audit features.
Hint: hover over the marks and titles to get additional information on the various features.
Glossary
Unified List   Commercial Scanners   Free / Open Source Scanners


#
LogoVulnerability Scanner
C
O
U
N
T
S
Q
L
i
B
S
Q
L
i
S
S
J
S
i
R
X
S
S
P
X
S
S
D
X
S
S
J
S
O
N
h
L
F
I
R
F
I
C
M
D
E
x
e
c
U
P
L
O
A
D
R
E
D
I
R
E
C
T
C
R
L
F
i
L
D
A
P
i
X
P
A
P
H
i
M
X
i
S
S
I
F
O
R
M
A
T
i
C
O
D
E
i
X
M
L
i
E
L
i
B
U
F
F
E
R
o
I
N
T
E
G
E
R
o
C
O
D
E
D
i
s
c
B
A
C
K
U
P
f
P
A
D
D
I
N
G
A
U
T
H
b
P
R
I
V
e
X
X
E
S
E
S
S
I
O
N
F
I
X
A
T
I
O
N
C
S
R
F
A
D
o
S
1
IBM AppScan29
2
WebInspect26
3
Acunetix WVS (Commercial Edition)23
4
W3AF23
5
Nessus22
6
Burp Suite Professional16
7
Syhunt Mini (Sandcat Mini)16
8
Syhunt Dynamic (Sandcat Pro)16
9
IronWASP15
10
SkipFish15
#
LogoVulnerability Scanner
C
O
U
N
T
S
Q
L
i
B
S
Q
L
i
S
S
J
S
i
R
X
S
S
P
X
S
S
D
X
S
S
J
S
O
N
h
L
F
I
R
F
I
C
M
D
E
x
e
c
U
P
L
O
A
D
R
E
D
I
R
E
C
T
C
R
L
F
i
L
D
A
P
i
X
P
A
P
H
i
M
X
i
S
S
I
F
O
R
M
A
T
i
C
O
D
E
i
X
M
L
i
E
L
i
B
U
F
F
E
R
o
I
N
T
E
G
E
R
o
C
O
D
E
D
i
s
c
B
A
C
K
U
P
f
P
A
D
D
I
N
G
A
U
T
H
b
P
R
I
V
e
X
X
E
S
E
S
S
I
O
N
F
I
X
A
T
I
O
N
C
S
R
F
A
D
o
S
11
QualysGuard WAS15
12
arachni14
13
NTOSpider
(Obsolete Version / Results)
14
14
JSky (Commercial Edition)13
15
Netsparker (Commercial Edition)13
16
Wapiti13
17
Sandcat Free Edition13
18
Vega11
19
ZAP9
20
Grendel Scan9
#
LogoVulnerability Scanner
C
O
U
N
T
S
Q
L
i
B
S
Q
L
i
S
S
J
S
i
R
X
S
S
P
X
S
S
D
X
S
S
J
S
O
N
h
L
F
I
R
F
I
C
M
D
E
x
e
c
U
P
L
O
A
D
R
E
D
I
R
E
C
T
C
R
L
F
i
L
D
A
P
i
X
P
A
P
H
i
M
X
i
S
S
I
F
O
R
M
A
T
i
C
O
D
E
i
X
M
L
i
E
L
i
B
U
F
F
E
R
o
I
N
T
E
G
E
R
o
C
O
D
E
D
i
s
c
B
A
C
K
U
P
f
P
A
D
D
I
N
G
A
U
T
H
b
P
R
I
V
e
X
X
E
S
E
S
S
I
O
N
F
I
X
A
T
I
O
N
C
S
R
F
A
D
o
S
21
Ammonite9
22
ParosPro8
23
PowerFuzzer7
24
Andiparos7
25
JSky Free Edition6
26
Watobo6
27
Uber Web Security Scanner6
28
Oedipus6
29
Paros Proxy6
30
Grabber5
#
LogoVulnerability Scanner
C
O
U
N
T
S
Q
L
i
B
S
Q
L
i
S
S
J
S
i
R
X
S
S
P
X
S
S
D
X
S
S
J
S
O
N
h
L
F
I
R
F
I
C
M
D
E
x
e
c
U
P
L
O
A
D
R
E
D
I
R
E
C
T
C
R
L
F
i
L
D
A
P
i
X
P
A
P
H
i
M
X
i
S
S
I
F
O
R
M
A
T
i
C
O
D
E
i
X
M
L
i
E
L
i
B
U
F
F
E
R
o
I
N
T
E
G
E
R
o
C
O
D
E
D
i
s
c
B
A
C
K
U
P
f
P
A
D
D
I
N
G
A
U
T
H
b
P
R
I
V
e
X
X
E
S
E
S
S
I
O
N
F
I
X
A
T
I
O
N
C
S
R
F
A
D
o
S
31
Netsparker Community Edition5
32
safe3wvs (limited free edition)5
33
WebSecurify (Opensource Version)5
34
WebCruiser Free Edition4
35
WebCruiser Enterprise Edition4
36
ProxyStrike4
37
iScan4
38
Xcobra3
39
WebScarab3
40
Acunetix WVS Free Edition3
#
LogoVulnerability Scanner
C
O
U
N
T
S
Q
L
i
B
S
Q
L
i
S
S
J
S
i
R
X
S
S
P
X
S
S
D
X
S
S
J
S
O
N
h
L
F
I
R
F
I
C
M
D
E
x
e
c
U
P
L
O
A
D
R
E
D
I
R
E
C
T
C
R
L
F
i
L
D
A
P
i
X
P
A
P
H
i
M
X
i
S
S
I
F
O
R
M
A
T
i
C
O
D
E
i
X
M
L
i
E
L
i
B
U
F
F
E
R
o
I
N
T
E
G
E
R
o
C
O
D
E
D
i
s
c
B
A
C
K
U
P
f
P
A
D
D
I
N
G
A
U
T
H
b
P
R
I
V
e
X
X
E
S
E
S
S
I
O
N
F
I
X
A
T
I
O
N
C
S
R
F
A
D
o
S
41
N-Stalker 2012 Free Edition2
42
Damn Small SQLi Scanner (DSSS)2
43
Mini MySqlat0r2
44
VulnDetector2
45
sqlmap2
46
SQLiX2
47
Priamos2
48
WSTool2
49
openAcunetix2
50
Gamja2
#
LogoVulnerability Scanner
C
O
U
N
T
S
Q
L
i
B
S
Q
L
i
S
S
J
S
i
R
X
S
S
P
X
S
S
D
X
S
S
J
S
O
N
h
L
F
I
R
F
I
C
M
D
E
x
e
c
U
P
L
O
A
D
R
E
D
I
R
E
C
T
C
R
L
F
i
L
D
A
P
i
X
P
A
P
H
i
M
X
i
S
S
I
F
O
R
M
A
T
i
C
O
D
E
i
X
M
L
i
E
L
i
B
U
F
F
E
R
o
I
N
T
E
G
E
R
o
C
O
D
E
D
i
s
c
B
A
C
K
U
P
f
P
A
D
D
I
N
G
A
U
T
H
b
P
R
I
V
e
X
X
E
S
E
S
S
I
O
N
F
I
X
A
T
I
O
N
C
S
R
F
A
D
o
S
51
XSSploit2
52
Secubat2
53
XSSer2
54
LoverBoy1
55
crawlfish1
56
N-Stalker 2009 Free Edition1
57
SQID (SQL Injection Digger)1
58
aidSQL1
59
Scrawlr1
60
ScreamingCSS1
#
LogoVulnerability Scanner
C
O
U
N
T
S
Q
L
i
B
S
Q
L
i
S
S
J
S
i
R
X
S
S
P
X
S
S
D
X
S
S
J
S
O
N
h
L
F
I
R
F
I
C
M
D
E
x
e
c
U
P
L
O
A
D
R
E
D
I
R
E
C
T
C
R
L
F
i
L
D
A
P
i
X
P
A
P
H
i
M
X
i
S
S
I
F
O
R
M
A
T
i
C
O
D
E
i
X
M
L
i
E
L
i
B
U
F
F
E
R
o
I
N
T
E
G
E
R
o
C
O
D
E
D
i
s
c
B
A
C
K
U
P
f
P
A
D
D
I
N
G
A
U
T
H
b
P
R
I
V
e
X
X
E
S
E
S
S
I
O
N
F
I
X
A
T
I
O
N
C
S
R
F
A
D
o
S
61
Web Injection Scanner (WIS)1
62
XSSS1


Statistics
#
S
Q
L
i
B
S
Q
L
i
S
S
J
S
i
R
X
S
S
P
X
S
S
D
X
S
S
J
S
O
N
h
L
F
I
R
F
I
C
M
D
E
x
e
c
U
P
L
O
A
D
R
E
D
I
R
E
C
T
C
R
L
F
i
L
D
A
P
i
X
P
A
P
H
i
M
X
i
S
S
I
F
O
R
M
A
T
i
C
O
D
E
i
X
M
L
i
E
L
i
B
U
F
F
E
R
o
I
N
T
E
G
E
R
o
C
O
D
E
D
i
s
c
B
A
C
K
U
P
f
P
A
D
D
I
N
G
A
U
T
H
b
P
R
I
V
e
X
X
E
S
E
S
S
I
O
N
F
I
X
A
T
I
O
N
C
S
R
F
A
D
o
S
Scanners:53383521711329142271725141769710628312265734148114



Glossary
AliasAudit FeatureDescriptionReferences
SQLiError Based SQL InjectionSyntax injection attack that can affect the structure of database queries1, 2, 3, 4, 5
BSQLiBlind/Time-Based SQL InjectionSyntax injection attack that can affect the structure of database queries1, 2
SSJSiServer Side Java Script
(SSJS/NoSQL) Injection
Syntax injection attack that can affect the structure of server side javascript in AJAX Servers/NoSQL DBs1, 2, 3, 4, 5
RXSSReflected Cross Site ScriptingBrowser-output targeted attack that can execute HTML, JS and VBS code on other browsers1, 2, 3, 4, 5
PXSSPersistent Cross Site ScriptingBrowser-output targeted attack that can execute HTML, JS and VBS code on other browsers1, 2, 3
DXSSDOM Based Cross Site ScriptingBrowser-output targeted attack that can execute HTML, JS and VBS code on other browsers1, 2, 3
JSONhJSON HijackingJSON Hijacking (Javascript Hijacking) is an attack in which a 3rd party website abuses the beheviour of script tags and JSON to gain private data1, 2, 3, 4
LFIPath Traversal &
Local File Inclusion
Attacks that can affect the application file & directory access/inclusion1, 2, 3, 4, 5, 6, 7
RFIRemote File InclusionAttacks that can include (and potentially execute) remote code in the application1, 2
CMDExecCommand InjectionSyntax injection attack that can execute system commands in the target host1, 2, 3, 4, 5, 6
UPLOADUnrestricted File UploadA vulnerability that can enable attackers to upload malicious files to the server1, 2
REDIRECTOpen RedirectBrowser-output targeted attack that can misled users and redirect them to spoofed content1, 2, 3, 4
CRLFiHTTP Header Injection &
HTTP Response Splitting
Browser-output targeted attack that affect the browser through header/response injection1, 2, 3, 4
LDAPiLDAP InjectionSyntax injection attack that can affect the structure of LDAP queries1, 2, 3, 4
XPATHiXPath/XQuery InjectionSyntax injection attack that can affect the structure of XPath queries1, 2, 3, 4, 5, 6, 7
MXiSMTP/IMAP/Email InjectionSyntax injection attack that can spoof semi-legitimate emails and execute mail commands1, 2, 3, 4
SSIServer-Side Includes InjectionSyntax injection attack that can execute scripts on the web server1, 2, 3, 4, 5
FORMATiFormat String AttackAn attack that can abuse formatting functions to crash programs or execute harmful code1, 2, 3, 4, 5
CODEiCode InjectionSyntax injection attack that can execute technology-specific code on the server1, 2, 3, 4, 5
XMLiXML InjectionAn injection attack that can manipulate the logic of XML dependant services1, 2
ELiEL InjectionExpression Language Injection is an injection attack that can execute limited rogue code in platforms that are using "double evaluation".1, 2
BUFFERoBuffer OverflowA memory corruption attack that can crash services and execute malicious code1, 2, 3, 4, 5, 6, 7, 8, 9
INTEGERoInteger OverflowA memory corruption attack that can wraparound numeric values, and indirectly affect resources1, 2, 3, 4, 5
CODEDiscSource Code DisclosureA collection of vulnerabilities that be used to disclose the server source code1
BACKUPfBackup FilesA dictionary attack that attempts to locate unrestricted access to obsolete & sensitive files1
PADDINGPadding OracleA cryptography attack on the CBC mode of operation that can decrypt messages without the encryption key1, 2
AUTHbForceful Browsing /
Authentication Bypass
An attack that can bypass the authentication enforcement using direct resource access1, 2, 3, 4, 5
PRIVePrivilege EscalationAn attack that can enable access to restricted/private content (via parameter tampering / direct access)1, 2, 3, 4, 5, 6, 7
XXEXml External EntityAn attack that abuses the XML dynamic processing features of webservices by introducing xml structures with links to content outside of the sphere of control.1, 2, 3, 4
SESSIONWeak Session IdentifierA vulnerability that can be exploited to impersonate application users1, 2, 3, 4, 5, 6
FIXATIONSession FixationA vulnerability that can fixate (set) another person's session identifier in order to elevate further attacks1, 2, 3, 4, 5, 6
CSRFCross Site Request ForgeryA vulnerability that can enable malicious 3rd parties to perform operations on behalf of users1, 2, 3, 4, 5, 6
ADoSApplication Denial of ServiceAn attack that can deny services from legitimate users via application-level issues1, 2, 3, 4, 5, 6, 7



Copyright © 2012 by Shay Chen (sectooladdict). All rights reserved.
Click here to learn how this information may be published or reused.