Novell & Oracle vulnerabilities and new updates for Feb, 09 2004

By N-Stalker Team on February 9, 2004


N-Stalker has made available the latest database update (v120) for N-Stealth Web Security Scanner.

This updates are available for the N-Stealth 5.5 version. If you are currently using an old version, please, contact us at:
E-mail: support@nstalker.com (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)
Download: https://secure.nstalker.com/customercenter/release.php

This release has included the following vulnerabilities:

– Cactusoft CactuShop Lite 5.0 Remote Arbitrary File Deletion Backdoor Vulnerability
– Joe Lumbroso Formmail.php 5.0 Unauthorized Remote File Upload Vulnerability
– OpenJournal 2.0.5 Authentication Bypassing Vulnerability
– Crossday Discuz! HTML Injection Vulnerability
– Mambo Open Source 4.6 Itemid Parameter Cross-Site Scripting Vulnerability
– All Enthusiast ReviewPost PHP Pro 2.5.1 Multiple SQL Injection Vulnerabilities
– RXGoogle.CGI Cross Site Scripting Vulnerability
– Web Crossing Web Server Component Remote Denial Of Service Vulnerability
– All Enthusiast Photopost PHP Pro 4.6 SQL Injection Vulnerability
– Qualiteam X-Cart Remote Command Execution Vulnerability
– Qualiteam X-Cart Multiple Remote Information Disclosure Vulnerabilities
– phpMyAdmin 2.5.5-p1 Export.PHP File Disclosure Vulnerability
– PHPX 3.2.3 Multiple Vulnerabilities
– PHP-Nuke 6.9 Multiple Module SQL Injection Vulnerabilities
– MiniHTTPServer WebForums Forum HTML Injection Vulnerability
– SurgeFTP Surgeftpmgr.CGI Denial Of Service Vulnerability
– Niti Telecom Caravan Business Server Remote Directory Traversal Vulnerability
– Leif M. Wright Web Blog Remote Command Execution Vulnerability
– Aprox Portal File Disclosure Vulnerability
– PhpGedView 2.65.1 Editconfig_gedcom.php Directory Traversal Vulnerability
– PhpGedView 2.65.1 [GED_File]_conf.php Remote File Include Vulnerability
– JBrowser 2.2 Browser.PHP Directory Traversal Vulnerability
– Laurent Adda Les Commentaires PHP Script Multiple Module File Include Vulnerability
– JBrowser Unauthorized Admin Access Vulnerability
– PJ CGI Neo Review Directory Traversal Vulnerability
– BRS WebWeaver 1.07 ISAPISkeleton.dll Cross-Site Scripting Vulnerability
– DotNetNuke 1.0.10d Multiple Vulnerabilities
– Loom Software SurfNow Remote HTTP GET Request Denial Of Service Vulnerability
– Novell Groupwise Webacc 6.5 Cross Site Scripting Vulnerability
– IBM Net.Data db2www Error Message Cross-Site Scripting Vulnerability
– Gallery 1.4.1 Remote Global Variable Injection Vulnerability
– Herberlin BremsServer Directory Traversal Vulnerability
– Mbedthis Software AppWeb HTTP Server Empty Options Request Denial Of Service Vulnerability
– Antologic Antolinux Administrative Interface NDCR Parameter Remote Command Execution Vulnerability
– Cherokee Error Page Cross Site Scripting Vulnerability
– Xoops 2.x Viewtopic.php Cross-Site Scripting Vulnerability
– Kietu Index.PHP Remote File Include Vulnerability
– Oracle HTTP Server isqlplus Cross-Site Scripting Vulnerability
– TinyServer Multiple Vulnerabilities
– Borland Webserver for Corel Paradox Directory Traversal Vulnerability
– Novell Netware Enterprise Web Server Multiple Vulnerabilities
– QuadComm Q-Shop Cross Site Scripting Vulnerabilities
– Acme thttpd CGI Test Script Cross-Site Scripting Vulnerability
– McAfee ePolicy Orchestrator Agent HTTP POST Buffer Mismanagement Vulnerability
– Darkwet Network WebcamXP Cross-Site Scripting Vulnerability
– Mephistoles HTTPD Cross-Site Scripting Vulnerability
– AIPTEK NETCam Webserver Directory Traversal Vulnerability
– PHPix Remote Arbitrary Command Execution Vulnerability
– WebTrends Reporting Center Management Interface Path Disclosure Vulnerability
– DUware Software Multiple Vulnerabilities
– Anteco Visual Technologies OwnServer Directory Traversal Vulnerability
– 2Wire HomePortal Series Directory Traversal Vulnerability
– Leif M. Wright Web Blog File Disclosure Vulnerability
– Mambo Open Source 4.6 mod_mainmenu.php Remote File Include Vulnerability
– YABB SE SSI.PHP ID_MEMBER SQL Injection Vulnerability
– GetWare Web Server Component Content-Length Value Remote Denial Of Service Vulnerability
– GoAhead WebServer Post Content-Length Remote Resource Consumption Vulnerability
– XtremeASP PhotoGallery Adminlogin.ASP SQL Injection Vulnerability
– MetaDot Corporation MetaDot Portal Server Multiple Vulnerabilities
– Vicomsoft RapidCache Server Host Argument Denial of Service Vulnerability
– Vicomsoft RapidCache Server Directory Traversal Vulnerability
– Real Networks Helix Server/Gateway 9.0.2.881 Admin Service HTTP Post DoS Vulnerability
– PHPDig 1.6.x Config.PHP Include Remote Command Execution Vulnerability
– LionMax Software WWW File Share Pro 2.45 Multiple Remote Vulnerabilities
– Microsoft Exchange Server 2003 Outlook Web Access Random Mailbox Access Vulnerability
– Novell iChain Web Server 2.2.113 Failed Login Page Cross-Site Scripting Vulnerability
– LionMax Software WWW File Share Pro Remote Denial of Service Vulnerability
– DansGuardian 0.5.8 Webmin Module Edit.CGI Remote Directory Traversal Vulnerability
– Andy’s PHP Projects Man Page Lookup Script Information Disclosure Vulnerability
– VisualShapers EZContents Module.PHP Remote Command Execution Vulnerability

N-Stealth DB General Information
Version: 120
Release Date: 02/09/2004

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.