Mod_SSL vulnerabilities and new updates
N-Stalker has made available the latest database update (v128) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner (to manually download it, use the url https://secure.nstalker.com/customercenter/).
If you need any additional assistance during this process, please, contact us at:
E-mail: support@nstalker.com (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)
This release has included the following vulnerabilities:
– cPanel 9.1 Passwd Remote SQL Injection Vulnerability
– AspDotNetStorefront 3.3 Access Validation Vulnerability
– AspDotNetStorefront 3.3 ReturnURL Parameter Cross-Site Scripting Vulnerability
– Blosxom 2.0 Writeback Plug-in HTML Injection Vulnerability
– Roundup 0.6.11 Remote File Disclosure Vulnerability
– PHP-Nuke 7.3 Reviews Module Cross-Site Scripting Vulnerability
– Linksys Web Camera Software Next_file Parameter File Disclosure Vulnerability
– NetWin SurgeMail/WebMail 3.1d Multiple Input Validation Vulnerabilities
– PHP Microsoft Windows Shell Escape Functions Command Execution Vulnerability
– cPanel 9.1 Killacct Script Customer Account DNS Information Deletion Vulnerability
– Multiple Linksys Routers 1.44 Gozila.CGI Denial Of Service Vulnerabilities
– Mail Manage EX MMEX 3.1.8 Script Settings Parameter Remote PHP File Include Vulnerability
– Sambar Server 6.1 Multiple Vulnerabilities
– PHP-Nuke 7.3 Direct Script Access Security Bypass Vulnerability
– Land Down Under 700-03 BBCode HTML Injection Vulnerability
– e107 Website System 0.603 User.PHP HTML Injection Vulnerability
N-Stealth DB General Information
Version: 128
Release Date: 06/14/2004