Sometimes, I think these "bugs" are found when things are performed in a way no one actually does it in the real world.
Not necessarily a bad thing--bugs are found, after all--but it tends to inflate the severity of the found bugs.
Trust me. You have to frequently go around campus and ask people “Why are you running IIS/Apache/FTP on your server?”. The usual answer is “I don’t know. We asked a student to set it up”. Translation: No one is maintaining the server.