Yes – all the pages that the public can access, without credentials, can be scanned. In addition to this, the tools also look for the presence of other pages and resources that are possible to access without following the website’s hyperlinks. Typical findings include:
- Vulnerable web components that have not been patched.
- Old or backup copies of web pages that have been renamed to html.old for example.
- Unprotected directories that contain sensitive information.
- Pages that allow SQL injection or Cross Site Scripting attacks.
- The ability to upload malicious files to the site.