MS ASP.NET Vulnerability and new updates
N-Stalker has made available the latest database update (v126) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner.
To manually download it, use the url https://secure.nstalker.com/customercenter/.
If you need any additional assistance during this process, please, contact us at:
E-mail: support@nstalker.com (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)
This release has included the following vulnerabilities:
– Open WebMail 2.21 Remote Command Execution Variant Vulnerability
– Tutorials Manager 1.0 Multiple Remote SQL Injection Vulnerabilities
– MailEnable Mail Server HTTPMail 1.116 Remote Heap Overflow Vulnerability
– Adam Webb NukeJokes 1.7 Module For PHP-Nuke Multiple Input Validation Vulnerabilities
– MyWeb 3.3 HTTP Server GET Request Buffer Overflow Vulnerability
– Microsoft ASP.NET 1.1 Malformed HTTP Request Information Disclosure Vulnerability
– Verity Ultraseek 5.2.1 Error Message Path Disclosure Vulnerability
– E-Zone Media FuzeTalk 2.0 AddUser.CFM Administrator Command Execution Vulnerability
– JelSoft VBulletin 3.3.0 Forum Creation HTML Injection Vulnerability
– PHPNuke 7.2 Modules.php Multiple SQL Injection Vulnerabilities
– PHPX 3.2.6 Multiple Cross-Site Scripting Vulnerabilities
– PHPX 3.2.6 Multiple Administrator Command Execution Vulnerability
– Simple Machines Forum 1.0 Size Tag HTML Injection Vulnerability
– SurgeLDAP 1.0g Web Administration Authentication Bypass Vulnerability
– OMail Webmail 0.98.5 Remote Command Execution Vulnerability
– Aldo’s Web Server Multiple Input Validation Vulnerabilities
– PROPS 0.6.1 SQL Injection and Cross-Site Scripting Vulnerabilities
– JForum RC2 Unauthorized Forum Access Vulnerability
– Rosiello Security Sphiro HTTPD 0.1b Remote Heap Buffer Overflow Vulnerability
– Moodle 1.2.1 Cross Site Scripting Vulnerability
– SquirrelMail 1.4.2 Folder Name Cross-Site Scripting Vulnerability
– Coppermine Photo Gallery 1.2.2 Multiple Input Validation Vulnerabilities
– ReciPants 1.1.1 SQL Injection and Cross-Site Scripting Vulnerabilities
– Web Wiz Forum Multiple Vulnerabilities
– Admin Access With Levels Plug-in For osCommerce 1.5.1 Access Control Bypass Vulnerability
– PAFileDB 3.1 ID Variable Cross-Site Scripting Vulnerability
– DiGi Compieuw 1 WWW Server Remote Denial Of Service Vulnerability
– HP Web Jetadmin 7.0 Multiple Vulnerabilities
N-Stealth DB General Information
Version: 126
Release Date: 05/16/2004