[WebsiteBaker]
url=http://www.websitebaker.org/
safe=2.6.6
vuln=CVE-2007-0527
file=version.php
variable=VERSION
extra_match=Website Baker Project
subdir=3

[toendaCMS]
url=http://www.toendacms.com/
safe=
vuln=CVE-2007-1872
file=tcms_version.xml
variable=release
subdir=2

[Drupal]
url=http://www.drupal.org/
safe=6.3
old_safe=5.9,5.10
vuln=CVE-2008-3222
file=system.module
variable=define('VERSION'
subdir=1

[PHPNuke]
url=http://phpnuke.org/
# I'm not really sure about that, but 8.0 is at least vulnerable
# Versions pre 8.0 aren't easily detectable
safe=8.1
vuln=CVE-2007-1519
file=version.php
variable=$version_number
extra_match=PHP-Nuke $version_number
subdir=2

[Typo3]
url=http://typo3.org/
safe=4.2.1
old_safe=4.0.9,4.1.7
vuln=CVE-2008-2717
file=config_default.php
variable=$TYPO_VERSION
subdir=1

[Joomla]
url=http://www.joomla.org/
safe=1.5.4
old_safe=1.0.15
vuln=CVE-2008-3225
file=version.php
variable=var $RELEASE,var $DEV_LEVEL
extra_match=@package Joomla
subdir=1

# 1.5 has changed identification
[Joomla]
url=http://www.joomla.org/
safe=1.5.4
old_safe=1.0.15
vuln=CVE-2008-3225
file=version.php
variable=var $RELEASE,var $DEV_LEVEL
extra_match=@package	Joomla.Framework
subdir=1

[Mambo]
url=http://www.source.mambo-foundation.org/
safe=4.6.5
vuln=CVE-2008-2905
file=version.php
variable=var $RELEASE,var $DEV_LEVEL
extra_match=@package Mambo
subdir=1

[w-Agora]
url=http://www.w-agora.net/
# last release 4.2.1 in 2006-07-12
safe=
vuln=CVE-2007-0607
file=misc_func.php
variable=$v =
subdir=1
extra_match=w-agora version $v

[MODx]
url=http://www.modxcms.com/
safe=
# 0.9.6.1 as of 2008-02-05
vuln=CVE-2008-0094
file=version.inc.php
variable=$version
subdir=2
extra_match=$full_appname = 'MODx'

[PostNuke]
# This one is a hell to detect, not sure for how many versions this works
url=http://www.postnuke.com
# 0.764 last stable in 2006-11-20, 0.8.0.0 rcs available
safe=
vuln=CVE-2007-0385
file=global.php
variable=_MESSAGE_00_a
subdir=2
extra_match=http://www.pn-cms.de

[Contenido]
url=http://www.contenido.org/
safe=4.8.7
old_safe=4.6.24
vuln=http://www.contenido.org/
file=config.misc.php
variable=$cfg['version']
subdir=1
extra_match=Contenido Misc Configurations