Confixx vulnerabilities and new updates for Mar 14, 2004
N-Stalker has made available the latest database update (v122) for N-Stealth Web Security Scanner.
This updates are available for the N-Stealth 5.5 version. If you are currently using an old version, please, contact us at:
E-mail: support@nstalker.com (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)
Download: https://secure.nstalker.com/customercenter/release.php
This release has included the following vulnerabilities:
– cPanel 9.1 dir Parameter Cross-Site Scripting Vulnerability
– cPanel 9.1 Login Script Remote Command Execution Vulnerability
– Dogpatch Software CFWebstore 5.0 SQL Injection Vulnerability
– Dogpatch Software CFWebstore 5.0 Cross-Site Scripting Vulnerability
– IP3 Networks IP3 NetAccess Appliance SQL Injection Vulnerability
– Emumail EMU Webmail 5.2.7 Multiple Vulnerabilities
– Chaogic Systems VHost 3.0 Unspecified Cross-Site Scripting Vulnerability
– GNU MyProxy Cross-Site Scripting Vulnerability
– Pegasi Web Server Multiple Input Validation Vulnerabilities
– cPanel 9.1 Resetpass Remote Command Execution Vulnerability
– Invicta WMCam Server Remote Denial Of Service Vulnerability
– Invision Power Board 1.3final Pop Parameter Cross-Site Scripting Vulnerability
– Confixx Pro2 Perl Debugger Remote Command Execution Vulnerability
– Confixx Pro2 DB Parameter SQL Injection Vulnerability
– PWebServer Remote Directory Traversal Vulnerability
– VirtuaSystems VirtuaNews 1.0.3 Admin.PHP Cross-Site Scripting Vulnerability
– Seattle Lab Software SLWebMail 2.0.9 Multiple Buffer Overflow Vulnerabilities
– VirtuaSystems VirtuaNews 1.0.3 Multiple Module Cross-Site Scripting Vulnerabilities
– SmarterTools SmarterMail 3.1 Multiple Vulnerabilities
– SandSurfer 1.7.0 Multiple Undisclosed Cross-Site Scripting Vulnerabilities
– SpiderSales Shopping Cart 2.0 Multiple Vulnerabilities
– Magic Winmail Server 3.6 LDapLib.PHP Remote Installation Path Disclosure Vulnerability
– Hot Open Tickets 2.0 Unspecified Privilege Escalation Vulnerability
– NetScreen SA 5000 Series delhomepage.cgi Cross-Site Scripting Vulnerability
– SureCom Network Device Malformed Web Authorization Request Denial Of Service Vulnerability
– IGeneric Free Shopping Cart SQL Injection Vulnerability
– IGeneric Free Shopping Cart 1.4 Cross-Site Scripting Vulnerability
– Software602 602Pro LAN Suite Web Mail Cross-Site Scripting Vulnerability
– YABB SE 1.5.5 Multiple Input Validation Vulnerabilities
– Software602 602Pro LAN Suite Web Mail Installation Path Disclosure Vulnerability
– Invision Power Board 1.3 final Multiple Cross-Site Scripting Vulnerabilities
N-Stealth DB General Information
Version: 122
Release Date: 03/14/2004