Oracle SSO vulnerability and new updates for Apr 10, 2004

By N-Stalker Team on April 12, 2004

N-Stalker has made available the latest database update (v124) for N-Stealth Web Security Scanner.

This updates are available for the N-Stealth 5.5 version. If you are currently using an old version, please, contact us at:
E-mail: support@nstalker.com (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)
Download: https://secure.nstalker.com/customercenter/release.php

This release has included the following vulnerabilities:

– NukeCalendar 1.1a Multiple Vulnerabilities
– OpenBB 1.0.6 MyHome.PHP SQL Injection Vulnerability
– ADA IMGSVR 0.4 GET Request Buffer Overflow Vulnerability
– ADA IMGSVR 0.4 Directory Traversal Vulnerability
– Aborior Encore Web Forum Remote Arbitrary Command Execution Vulnerability
– ADA IMGSVR 0.4 Remote File Download Vulnerability
– ADA IMGSVR 0.4 Remote Directory Listing Vulnerability
– Cactusoft CactuShop 5.1 SQL Injection Vulnerability
– CactuSoft CactuShop 5.1 Cross-Site Scripting Vulnerability
– cPanel 9.1.0-R85 Multiple Module Cross-Site Scripting Vulnerabilities
– PSInclude 1.41 Remote Arbitrary Command Execution Vulnerability
– Oracle Single Sign-On Login Page Authentication Credential Disclosure Vulnerability
– PHPKit 1.6.03 Multiple HTML Injection Vulnerabilities
– Interchange 5.0 Remote Information Disclosure Vulnerability
– All Enthusiast Photopost 4.6 PHP Pro Multiple Input Validation Vulnerabilities
– Alan Ward A-Cart 2.0 Multiple Input Validation Vulnerabilities
– Cloisterblog 1.2.2 Journal.pl Directory Traversal Vulnerability
– WebCT 4.1.1 Campus Edition HTML Injection Vulnerability
– XMB 1.8sp3/1.9beta Forum Multiple Vulnerabilities
– NSTX 1.0 Remote Denial Of Service Vulnerability
– PHPBB 2.0.8 Privmsg.PHP SQL Injection Vulnerability
– Trend Micro Interscan Viruswall localweb Directory Traversal Vulnerability
– CPanel 9.1 Multiple Cross-Site Scripting Vulnerabilities
– Virtual Programming VP-ASP Shopping Cart 5.0 CatalogID SQL Injection Vulnerability
– HP Web Jetadmin 7.5.2456 Printer Firmware Update Script Arbitrary File Upload Weakness
– HP Web Jetadmin 7.5.2456 setinfo.hts Script Directory Traversal Vulnerability
– HP Web Jetadmin 7.5.2456 Remote Arbitrary Command Execution Vulnerability
– Hibyte HiGuest Message Field HTML Injection Vulnerability
– XWeb 1.0 Directory Traversal Vulnerability
– JelSoft VBulletin 2.3.4 Private.PHP Cross-Site Scripting Vulnerability
– JelSoft VBulletin 3.0.0 Multiple Module Index.PHP Cross-Site Scripting Vulnerabilities
– Invision Gallery 1.0.1 Multiple SQL Injection Vulnerabilities
– Joel Palmius Mod_Survey 3.2.0 Survey Input Field HTML Injection Vulnerability
– Invision Power Top Site List 1.1 Comments function id Parameter SQL Injection Vulnerability
– PHP-Nuke MS-Analysis Module 2.0 Multiple Cross-Site Scripting Vulnerabilities
– PHP-Nuke MS-Analysis Module 2.0 Multiple Remote Path Disclosure Vulnerabilities
– phpBB 2.0.7 Multiple Input Validation Vulnerabilities
– Centrinity FirstClass 7.1 HTTP Server TargetName Parameter Cross-Site Scripting Vulnerability
– ReGet Software 3.0 build 121 ReGet Directory Traversal Vulnerability
– phpBB 2.0.6d profile.php avatarselect Cross-Site Scripting Vulnerability
– Expinion.net 2.5 News Manager Lite Multiple Vulnerabilities
– Expinion.net 2.1 Member Management System Multiple Cross-Site Scripting Vulnerabilities
– Expinion.net 2.1 Member Management System ID Parameter SQL Injection Vulnerability

N-Stealth DB General Information
Version: 124
Release Date: 04/09/2004

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.