Apache vulnerabilities and new updates

By N-Stalker Team on July 12, 2004

N-Stalker has made available the latest database update (v129) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner (to manually download it, use the url
https://secure.nstalker.com/customercenter/).

If you need any additional assistance during this process, please, contact us at:
E-mail: support at nstalker-dot-com (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

– JAWS 0.3 Multiple Input Validation Vulnerabilities
– Fastream NetFile FTP/Web Server 6.7.2 Directory Traversal Vulnerability
– Tri Dung Nguyen Free Perl Guestbook 1.25 BBCode HTML Injection Vulnerability
– Qbik WinGate 6.0 Information Disclosure Vulnerability
– SCI Photo Chat Server 3.4.9 Cross-Site Scripting Vulnerability
– Easy Chat Server 1.2 Multiple Denial Of Service Vulnerabilities
– IBM Websphere Edge Server 5.0.2 Denial Of Service Vulnerability
– Netegrity IdentityMinder 5.6 Multiple Cross-Site Scripting Vulnerabilities
– Open WebMail 2.32 Vacation.PL Remote Command Execution Variant Vulnerability
– I-Mall Commerce I-mall Script Remote Command Execution Vulnerability
– McMurtrey/Whitaker Associates Cart32 5.0 GetLatestBuilds Script Cross-Site Scripting Vulnerability
– CGIScript.net CSFAQ Script 1.0 Path Disclosure Vulnerability
– PHPMyFamily 1.3 Authentication Bypass Vulnerability
– CuteNews 1.3.1 Multiple Cross-site Scripting Vulnerabilities
– PowerPortal 1.3b Multiple Input Validation Vulnerabilities
– Apache ap_escape_html Memory Allocation Denial Of Service Vulnerability
– VBulletin 3.0.1 Multiple Module HTML Injection Vulnerability
– giFT-FastTrack HTTP 0.8.6 Header Parser Remote Denial Of Service Vulnerability
– PHP-Nuke 7.3 Multiple Vulnerabilities
– ArbitroWeb 0.6 PHP Proxy Cross-Site Scripting Vulnerability
– OSTicket 1.2 New Ticket Attachment Remote Command Execution Vulnerability
– MoinMoin Group 1.2.1 Name Privilege Escalation Vulnerability
– Snitz Forums 3.4.04 Register Script HTML Injection Vulnerability
– Thy HTTP Daemon 0.9.2 Null Pointer Exception Denial Of Service Vulnerability
– Pivot Web Log 1.10 Remote File Include Vulnerability
– Web Wiz Forums 7.8 Registration_Rules.ASP Cross-Site Scripting Vulnerability
– PHPHeaven PHPMyChat 0.14.5 Multiple Remote Vulnerabilities
– Linksys Web Camera Software 2.10 Next_file Parameter Cross-Site Scripting Vulnerability
– Invision Power Board 1.3 SSI.PHP Cross-Site Scripting Vulnerability
– Virtual Programming VP-ASP 5.0 Shoperror Script Cross-Site Scripting Vulnerability
– Horde Chora 1.2.1 Viewer Remote Command Execution Vulnerability
– Virtual Programming VP-ASP 5.0 Shopproductselect Script SQL Injection Vulnerability
– Virtual Programming VP-ASP Shopping Cart 5.0 Shop$DB.ASP Cross-Site Scripting Vulnerability
– Webmin 1.140 Configuration Module Information Disclosure Vulnerability
– PHP-Nuke 7.3 Multiple Input Validation Vulnerabilities
– Invision Power Board 1.3.1 SSI.PHP SQL Injection Vulnerability
– Usermin 1.0.7 HTML Email Script Code Execution Vulnerability

N-Stealth DB General Information
Version: 129
Release Date: 07/12/2004

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.