IBM Tivoli vulnerability and new updates
N-Stalker has made available the latest database update (v132) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner (to manually download it, use the url https://secure.nstalker.com/customercenter/).
If you need any additional assistance during this process, please, contact us at:
E-mail: Click Here (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)
This release has included the following vulnerabilities:
– YaPiG 0.9.2 Remote Server-Side Script Execution Vulnerability
– PluggedOut Blog 1.60 Blog_Exec.PHP Cross-Site Scripting Vulnerability
– phpBB 2.0.9 Login.PHP Cross-Site Scripting Vulnerability
– Moodle 1.3.3 post.php Cross-Site Scripting Vulnerability
– CVSTrac 1.1.3 filediff Remote Command Execution Vulnerability
– eNdonesia 8.3 Search Form Cross-Site Scripting Vulnerability
– Jetbox One 2.0.8 Remote Server-Side Script Execution Vulnerability
– Acme thttpd 2.0.7 Directory Traversal Vulnerability
– PHP-Nuke 7.3 Delete God Admin Access Control Bypass Vulnerability
– Multiple Free Web Chat Denial Of Service Vulnerabilities
– WHM AutoPilot 2.4.5 Clogin.PHP Username/Password Information Disclosure Vulnerability
– BreakCalendar 1.4 Multiple Remote Vulnerabilities
– Webcam Corp Webcam 4.0.1a Watchdog sresult.exe Cross-Site Scripting Vulnerability
– U.S. Robotics USR808054 Wireless Access Point Web Administration Denial Of Service Vulnerability
– IBM Tivoli Directory Server LDACGI Directory Traversal Vulnerability
– Webbsyte Chat 0.9 Denial Of Service Vulnerability
– MyServer 0.6.2 Multiple Remote math_sum.mscgi Example Script Vulnerabilities
– PowerPortal 1.3 Private Message HTML Injection Vulnerability
– FusionPHP 3.6.1 Fusion News Administrator Command Execution Vulnerability
– TikiWiki 1.8.3 Unauthorized Page Access Vulnerability
– Comersus Cart 5.0.9 SQL Injection Vulnerability
– Verylost LostBook 1.1 Message Entry HTML Injection Vulnerability
– LinPHA 0.9.4 Session Cookie SQL Injection Vulnerability
– Hitachi Web Page Generator Cross-Site Scripting and Information Disclosure Vulnerabilities
– AntiBoard 0.7.2 Multiple Input Validation Vulnerabilities
– Phorum 5.0.7 Search Script Cross-Site Scripting Vulnerability
N-Stealth DB General Information
Version: 132
Release Date: 08/28/2004