Input Vector Support - Web Application Scanners:

The current information is based on the results of the *2011* benchmark (excpet for entries marked as updated or new )

Note: The content in this page is *incomplete* since the research is still in progress - the various scanners might support additional vectors.

Last updated: 27/08/2012
Sorted in a descending order according to the scanner's number of supported input vectors and the scanner name .
Hint: hover over the marks and titles to get additional information on the various features.
Note: the information refers to the ability of the scanners to scan the input vector, not simply to interpret it.
Glossary
Unified List   Commercial Scanners   Free / Open Source Scanners


#
LogoVulnerability Scanner
C
O
U
N
T
G
E
T
P
O
S
T
C
O
O
K
I
E
H
E
A
D
E
R
S
E
C
R
E
T
P
N
a
m
e
X
M
L
X
m
l
A
T
T
X
m
l
T
A
G
J
S
O
N
.
N
e
t
E
N
C
A
M
F
J
a
v
a
S
E
R
.
N
e
t
S
E
R
W
C
F
W
C
F
-
B
i
n
W
e
b
S
o
c
k
D
W
R
C
u
s
t
o
m
1
IBM AppScan13
2
WebInspect13
3
Burp Suite Professional11
4
IronWASP10
5
Acunetix WVS (Commercial Edition)7
6
Ammonite7
7
Acunetix WVS Free Edition5
8
Nessus5
9
NTOSpider
(Obsolete Version / Results)
5
10
QualysGuard WAS5
#
LogoVulnerability Scanner
C
O
U
N
T
G
E
T
P
O
S
T
C
O
O
K
I
E
H
E
A
D
E
R
S
E
C
R
E
T
P
N
a
m
e
X
M
L
X
m
l
A
T
T
X
m
l
T
A
G
J
S
O
N
.
N
e
t
E
N
C
A
M
F
J
a
v
a
S
E
R
.
N
e
t
S
E
R
W
C
F
W
C
F
-
B
i
n
W
e
b
S
o
c
k
D
W
R
C
u
s
t
o
m
11
W3AF5
12
arachni4
13
Netsparker (Commercial Edition)4
14
SkipFish4
15
SQLiX4
16
sqlmap4
17
XSSer4
18
JSky (Commercial Edition)3
19
ParosPro3
20
safe3wvs (limited free edition)3
#
LogoVulnerability Scanner
C
O
U
N
T
G
E
T
P
O
S
T
C
O
O
K
I
E
H
E
A
D
E
R
S
E
C
R
E
T
P
N
a
m
e
X
M
L
X
m
l
A
T
T
X
m
l
T
A
G
J
S
O
N
.
N
e
t
E
N
C
A
M
F
J
a
v
a
S
E
R
.
N
e
t
S
E
R
W
C
F
W
C
F
-
B
i
n
W
e
b
S
o
c
k
D
W
R
C
u
s
t
o
m
21
Syhunt Dynamic (Sandcat Pro)3
22
Vega3
23
WebCruiser Enterprise Edition3
24
WebCruiser Free Edition3
25
Andiparos2
26
Gamja2
27
Grabber2
28
Grendel Scan2
29
Mini MySqlat0r2
30
Netsparker Community Edition2
#
LogoVulnerability Scanner
C
O
U
N
T
G
E
T
P
O
S
T
C
O
O
K
I
E
H
E
A
D
E
R
S
E
C
R
E
T
P
N
a
m
e
X
M
L
X
m
l
A
T
T
X
m
l
T
A
G
J
S
O
N
.
N
e
t
E
N
C
A
M
F
J
a
v
a
S
E
R
.
N
e
t
S
E
R
W
C
F
W
C
F
-
B
i
n
W
e
b
S
o
c
k
D
W
R
C
u
s
t
o
m
31
N-Stalker 2009 Free Edition2
32
Oedipus2
33
openAcunetix2
34
Paros Proxy2
35
PowerFuzzer2
36
ProxyStrike2
37
Sandcat Free Edition2
38
ScreamingCSS2
39
Secubat2
40
Syhunt Mini (Sandcat Mini)2
#
LogoVulnerability Scanner
C
O
U
N
T
G
E
T
P
O
S
T
C
O
O
K
I
E
H
E
A
D
E
R
S
E
C
R
E
T
P
N
a
m
e
X
M
L
X
m
l
A
T
T
X
m
l
T
A
G
J
S
O
N
.
N
e
t
E
N
C
A
M
F
J
a
v
a
S
E
R
.
N
e
t
S
E
R
W
C
F
W
C
F
-
B
i
n
W
e
b
S
o
c
k
D
W
R
C
u
s
t
o
m
41
Uber Web Security Scanner2
42
VulnDetector2
43
Wapiti2
44
Watobo2
45
WebScarab2
46
WebSecurify (Opensource Version)2
47
WSTool2
48
Xcobra2
49
XSSploit2
50
XSSS2
#
LogoVulnerability Scanner
C
O
U
N
T
G
E
T
P
O
S
T
C
O
O
K
I
E
H
E
A
D
E
R
S
E
C
R
E
T
P
N
a
m
e
X
M
L
X
m
l
A
T
T
X
m
l
T
A
G
J
S
O
N
.
N
e
t
E
N
C
A
M
F
J
a
v
a
S
E
R
.
N
e
t
S
E
R
W
C
F
W
C
F
-
B
i
n
W
e
b
S
o
c
k
D
W
R
C
u
s
t
o
m
51
ZAP2
52
aidSQL1
53
crawlfish1
54
Damn Small SQLi Scanner (DSSS)1
55
iScan1
56
JSky Free Edition1
57
LoverBoy1
58
N-Stalker 2012 Free Edition1
59
Priamos1
60
Scrawlr1
#
LogoVulnerability Scanner
C
O
U
N
T
G
E
T
P
O
S
T
C
O
O
K
I
E
H
E
A
D
E
R
S
E
C
R
E
T
P
N
a
m
e
X
M
L
X
m
l
A
T
T
X
m
l
T
A
G
J
S
O
N
.
N
e
t
E
N
C
A
M
F
J
a
v
a
S
E
R
.
N
e
t
S
E
R
W
C
F
W
C
F
-
B
i
n
W
e
b
S
o
c
k
D
W
R
C
u
s
t
o
m
61
SQID (SQL Injection Digger)1
62
Web Injection Scanner (WIS)1


Statistics
#
G
E
T
P
O
S
T
C
O
O
K
I
E
H
E
A
D
E
R
S
E
C
R
E
T
P
N
a
m
e
X
M
L
X
m
l
A
T
T
X
m
l
T
A
G
J
S
O
N
.
N
e
t
E
N
C
A
M
F
J
a
v
a
S
E
R
.
N
e
t
S
E
R
W
C
F
W
C
F
-
B
i
n
W
e
b
S
o
c
k
D
W
R
C
u
s
t
o
m
Scanners:62512118297538030021004



Glossary
AliasGeneral FeatureDescriptionReferences
GETHTTP Query String ParametersInput parameters sent in the URL1
POSTHTTP Body ParametersInput parameters sent in the HTTP body1
COOKIEHTTP Cookie ParametersInput parameters sent in the HTTP cookie1
HEADERHTTP HeadersHTTP request headers used by the application1
SECRETSecret HTTP ParametersNon-visible valid HTTP parameters (such as GET to POST, etc)
PNameHTTP Parameter NamesHTTP parameter names used by the application
XMLXML Element ContentThe content of XML elements1
XmlATTXML AttributesXML attributes1
XmlTAGXML TagsThe names of XML tags1
JSONJSON ParametersParameters sent in JSON format1
.NetENC.Net PostBack Encoded ParametersParameters sent after undergoing .net PostBack encoding1
AMFFlash Action Message FormatParameters sent in Flash AMF format1
JavaSERJava Serialized ObjectsParameters sent within Java serialized objects1
.NetSER.Net Serialized Objects / RemotingParameters sent within .Net serialized objects / remoting1
WCF.Net WCF ObjectsParameters sent in WCF requests1
WCF-Bin.Net Binary WCF ObjectsParameters sent in binary WCF requests1
WebSockHTML5 WebSocketsDirect Socket Browser-Server Communication1
DWRJava Direct Web RemotingParameters sent in DWR format1
CustomCustom Input VectorSupport for defining custom input vectors in the HTTP request



Copyright © 2012 by Shay Chen (sectooladdict). All rights reserved.
Click here to learn how this information may be published or reused.