Novel iChain vulnerability and new updates
N-Stalker has made available the latest database update (v131) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner (to manually download it, use the url https://secure.nstalker.com/customercenter/).
If you need any additional assistance during this process, please, contact us at:
E-mail: Click Here(24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)
This release has included the following vulnerabilities:
– phpMyFAQ 1.4 Image Manager Authentication Bypass Vulnerability
– RiSearch/RiSearch Pro Open Proxy Vulnerability
– Nucleus CMS 3.0 Action.PHP SQL Injection Vulnerability
– PostNuke Reviews Module Cross-Site Scripting Vulnerability
– MoinMoin 1.2.2 PageEditor Privilege Escalation Vulnerability
– Subversion mod_authz_svn Access Control Bypass Vulnerabilities
– PostNuke Install Script Administrator Password Disclosure Vulnerability
– EasyIns Stadtportal 4.0 Site Parameter Remote File Include Vulnerability
– EasyWeb FileManager 1.0 RC-1 Module Directory Traversal Vulnerability
– Imatix Xitami 2.5c1 Malformed Header Remote Denial of Service Vulnerability
– Imatix Xitami Server 2.5c1 Side Includes Cross-Site Scripting Vulnerability
– Samba Web Administration Tool 3.0.4 Base64 Decoder Buffer Overflow Vulnerability
– Novell iChain 2.2 SP2 Multiple Unspecified Potential Vulnerabilities
– Internet Software Sciences Web+Center 4.0.1 Cookie Object SQL Injection Vulnerability
– Conceptronic CADSLR1 ADSL Router Denial Of Service Vulnerability
– Serena TeamTrack 6.6.1 Remote Authentication Bypass Vulnerability
– NetSupport DNA HelpDesk 1.0.1 Problist Script SQL Injection Vulnerability
– Leigh Business Enterprises 4.0.0.80 Web HelpDesk SQL Injection Vulnerability
– Mensajeitor 1.8.9 Tag Board Authentication Bypass Vulnerability
– Polar Helpdesk Cookie Based Authentication System Bypass Vulnerability
– Layton Technology HelpBox 3.0.1 Multiple SQL Injection Vulnerabilities
– Nucleus CMS/Blog:CMS/PunBB 3.0/1.1.4 Unspecified Remote File Include Vulnerability
– Lexmark Network Printer T522 HTTP Server Denial Of Service Vulnerability
– Artmedic Webdesign Kleinanzeigen Script File Include Vulnerability
– Anton Raharja PlaySMS 0.6 Multiple Vulnerabilities
– PHP-Nuke 7.3 Reviews Module title Parameter Cross-Site Scripting Vulnerability
– CuteNews 1.3.1 Comment HTML Injection Vulnerability
– Adam Ismay Print Topic Mod 1.0 SQL Injection Vulnerability
– Extropia WebStore 2.0 Remote Command Execution Vulnerability
N-Stealth DB General Information
Version: 131
Release Date: 08/08/2004