Cisco vulnerability and new updates for Jan 12, 2004
N-Stalker has made available the latest database update (v119) for N-Stealth Web Security Scanner.
This updates are available for the N-Stealth 5.5 version. If you are currently using an old version, please, contact us at:
E-mail: support@nstalker.com (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)
Download: https://secure.nstalker.com/customercenter/release.php
This release has included the following vulnerabilities:
– Hand-Crafted Software FreeProxy FreeWeb Directory Traversal Vulnerability
– Accipiter DirectServer Remote File Disclosure Vulnerability
– Hand-Crafted Software FreeProxy FreeWeb CreateFile Function Denial of Service Vulnerability
– Cisco Personal Assistant Web Interface 14.x User Password Bypass Vulnerability
– PhpGedView 2.61 Multiple PHP Remote File Include Vulnerabilities
– Sysbotz SimpleData 4.0.1 Unspecified Authentication Bypass Vulnerability
– PhpGedView 2.61 Search Script Cross-Site Scripting Vulnerability
– PhpGedView 2.61 PHPInfo Information Disclosure Weakness
– ZyXEL ZyWALL 10 Management Interface Cross-Site Scripting Vulnerability
– Edimax AR-6004 ADSL Router Management Interface Cross-Site Scripting Vulnerability
– SnapStream PVS Lite Cross-Site Scripting Vulnerability
– HotNews Multiple PHP File Include Vulnerabilities
– vBulletin 2.3.x Calendar Script SQL Injection Vulnerability
– Phorum Registration Script hide_email SQL Injection Vulnerability
– Webcam Corp Webcam Watchdog Web Server Buffer Overflow Vulnerability
– Invision Power Board 1.3 Calendar.PHP SQL Injection Vulnerability
– ASPApp PortalAPP Remote User Database Access Vulnerability
– ASP-Nuke Remote User Database Access Vulnerability
– FreznoShop 1.3 Search Script Cross-Site Scripting Vulnerability
– EasyDynamicPages config_page.php Remote PHP File Include Vulnerability
– YaSoft Switch Off swnet.dll Remote Buffer Overflow Vulnerability
– Athena Web Registration Remote Command Execution Vulnerability
– Canon VB-C10R Network Camera Cross-Site Scripting Vulnerability
– php-ping Count Parameter Command Execution Vulnerability
– BulletScript MailList bsml.pl Information Disclosure Vulnerability
– NETObserve Authentication Bypass Vulnerability
– PHPCatalog ID Parameter SQL Injection Vulnerability
– PHP-Nuke 7.0 Survey Module SQL Injection Vulnerability
– OpenBB Board.PHP Cross-Site Scripting Vulnerability
– Private Message System 2.3 index.php Page Parameter Cross-Site Scripting Vulnerability
– OpenBB 1.06 Index.PHP Remote SQL Injection Vulnerability
– Surfboard httpd Remote Buffer Overflow Vulnerability
– Web Merchant Services Storefront Shopping Cart login.asp SQL Injection Vulnerability
– L-Soft Listserv Multiple Cross-Site Scripting Vulnerabilities
– ViewCVS Viewcvs.py Cross-Site Scripting Vulnerability
– KnowledgeBuilder Remote File Include Vulnerability
– Psychoblogger beta1 Multiple HTML/SQL Injection Vulnerabilities
– iSoft-Solutions QuikStore 2.12 Shopping Cart store Parameter Path Disclosure Vulnerability
– iSoft-Solutions QuikStore 2.12 Shopping Cart Remote Command Execution Vulnerability
– iSoft-Solutions QuikStore Shopping Cart template Parameter Directory Traversal Vulnerability
– My Little Forum Email.PHP Cross-Site Scripting Vulnerability
– Webfroot Shoutbox Viewshoutbox.PHP Cross-Site Scripting Vulnerability
– phpBB Privmsg.PHP Cross-Site Scripting Vulnerability
– BN Soft BoastMachine 2.6 Comment Form HTML Injection Vulnerability
– ProjectForum 8.4.2 HTML Injection Vulnerability
– DCAM WebCam Server Personal Web Server Directory Traversal Vulnerability
– osCommerce products_id URI Parameter SQL Injection Vulnerability
– PServ Web Server Directory Traversal Vulnerability
– osCommerce 2.2 ms1 manufacturers_id Parameter Cross-Site Scripting Vulnerability
– Xoops 2.0.5 MyLinks Myheader.php Cross-Site Scripting Vulnerability
– BES-CMS 0.5 rc3 Multiple Module File Include Vulnerability
– Xerox MicroServer 0.19.5.509 Web Server Remote Directory Traversal Vulnerability
– PY Software Active Webcam Webserver Directory Traversal Vulnerability
– PY Software Active Webcam Webserver Cross-Site Scripting Vulnerability
– ECW-Shop 5.5 Cat Parameter Cross-Site Scripting Vulnerability
– Alt-N MDaemon/WorldClient Form2Raw Raw Message Handler Buffer Overflow Vulnerability
– DUware DUportal 3.2 Multiple Vulnerabilities
– SOLMETRA SPAW Editor 1.0.3 spaw_control.class.PHP Remote PHP File Include Vulnerability
– Multiple ASPapp Portal 2.3 Vulnerabilities
– SiteInteractive Subscribe Me Setup.PL Arbitrary Command Execution Vulnerability
– osCommerce 2.2 ms2 osCsid Parameter Cross-Site Scripting Vulnerability
– GoAhead Webserver ASP Script File Source Code Disclosure Vulnerability
– Aardvark Topsites PHP 4.1 Multiple Vulnerabilities
– Invision Power Board 1.3/2.0aIndex.PHP SQL Injection Vulnerability
– Michael Dean Double Choco Latte 0.9.3 Multiple Module Remote File Include Vulnerability
– Markus Triska CGINews 1.0.7 and CGIForum 1.0.9 Information Disclosure Vulnerability
– Invision Power Top Site List Offset SQL Injection Vulnerability
– Elektropost 4.2 EPIServer Multiple Vulnerabilities
– osCommerce 2.2 ms1 SQL Injection Vulnerability
N-Stealth DB General Information
Version: 119
Release Date: 01/12/2004