Peoplesoft & Microsoft vulnerabilities and updates for Nov 24, 2003
N-Stalker has made available the latest database update (v116) for N-Stealth Web Security Scanner.
This updates are available for the N-Stealth 5.2 version.
If you are currently using an old version, please, contact us at (customers only):
E-Mail: support@nstalker.com(24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)
This release has included the following vulnerabilities:
– phpWebFileManager 2.0 index.php Directory Traversal Vulnerability
– Koch Roland Rolis Guestbook 1.0 $path Remote File Include Vulnerability
– Justin Hagstrom Auto Directory 1.2.3 Index Cross-Site Scripting
Vulnerability
– SqWebMail 3.6.1 Session Hijacking Vulnerability
– PHPList 2.6.2 Remote File Include Vulnerability
– Multiple Peoplesoft 8.43 Peoplebooks Vulnerabilities
– Web Wiz Forums 7.0 location HTML Injection Vulnerability
– FortiGate Firewall 2.36 Web Interface Cross-Site Scripting Vulnerabilities
– Microsoft FrontPage Server Extensions Remote Debug Buffer Overrun
Vulnerability
– PHP-Coolfile 1.4 Unauthorized Administrative Access Vulnerability
– OnlineArts DailyDose 1.1 dose.pl Remote Command Execution Vulnerability
– nCube Server Manager 1.0 Directory Traversal Vulnerability
– phpBB 2.0.3 Profile.PHP SQL Injection Vulnerability
– OpenSSL 0.9.6k/0.9.7b ASN.1 Large Recursion Remote Denial Of Service
Vulnerability
– OpenAutoClassifieds 1.0 Listing Parameter Cross-Site Scripting
Vulnerability
– John Beatty Easy PHP Photo Album 1.0 dir Parameter HTML Injection
Vulnerability
– Bugzilla 2.16.3/2.17.4 Multiple Vulnerabilities
– Synthetic Reality SymPoll 1.5 Cross-Site Scripting Vulnerability
– Web Wiz Forum 7.5 Unauthorized Private Forum Access Vulnerability
– MPM Guestbook 1.2 Cross-Site Scripting Vulnerability
– ThWboard 2.81 SQL Injection Vulnerability
– PHPRecipeBook 2.17 Unspecified Cross-Site Scripting/HTML Injection
Vulnerabilities
– VieNuke VieBoard 2.6 SQL Injection Vulnerability
– PHPKit 1.6 Include.PHP Cross-Site Scripting Vulnerability
– BRS WebWeaver 1.06 httpd User-Agent Remote Denial of Service Vulnerability
– HTTP Commander 4.0 Directory Traversal Vulnerability
– HTTP Commander 4.0 Path Disclosure Vulnerability
N-Stealth DB General Information
Version: 116
Release Date: 11/23/2003