Apache mod_ssl vulnerabilities and new updates

By N-Stalker Team on September 27, 2004

N-Stalker has made available the latest database update (v134) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner(to manually download it, use the url https://secure.nstalker.com/customercenter/).

If you need any additional assistance during this process, please, contact us at:
E-mail: click here (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

– MyServer Directory Traversal Vulnerability
– BBS E-Market Professional 1.3.0 Multiple File Disclosure Vulnerabilities
– Apache Mod_DAV LOCK Denial Of Service Vulnerability
– PHP Remote Arbitrary Location File Upload Vulnerability
– SnipSnap 0.5.2 HTTP Response Splitting Vulnerability
– Pingtel Xpressa Handset 2.1.11 Remote Denial Of Service Vulnerability
– FocalMedia.net Turbo Seek 1.7.1 Information Disclosure Vulnerability
– PostNuke Modules Factory 2.0 Subjects Module SQL Injection Vulnerability
– GetSolutions GetIntranet Multiple Remote Input Validation Vulnerabilities
– GetSolutions GetInternet Multiple SQL Injection Vulnerabilities
– BBS E-Market Professional 1.3.0 Remote File Include Vulnerability
– UtilMind Solutions Site News 1.1 Authentication Bypass Vulnerability
– Tutti Nova 0.9.4 Cross-site Scripting Vulnerabilities
– eZ/eZphotoshare 3.4 Remote Denial Of Service Vulnerability
– SAFE TEAM Regulus Customer Statistics Information Disclosure Vulnerability
– SAFE TEAM Regulus 2.2.95 Staffile Information Disclosure Vulnerability
– OpenCA 0.9.2 HTML Injection Vulnerability
– PSnews 1.1 No Parameter Cross-Site Scripting Vulnerability
– Keene Digital Media Server 1.0.2 Cross-Site Scripting Vulnerabilities
– Ipswitch WhatsUp Gold 8.0.3 prn.htm Denial Of Service Vulnerability
– Apache 2.0.51 mod_ssl Denial Of Service Vulnerability
– SiteCubed MailWorks Professional Authentication Bypass Vulnerability
– CuteNews 1.3.6 index.php Cross-Site Scripting Vulnerability
– Comersus Cart 5.0.9 SQL Injection Vulnerability
– pLog 0.3.2 User Registration HTML Injection Vulnerability
– TorrentTrader 2.0 Download.PHP SQL Injection Vulnerability
– Cerbère Proxy Server 1.2 Long Host Header Field Remote Denial of Service Vulnerability
– Newtelligence DasBlog 1.6 Request Log HTML Injection Vulnerability
– PHPWebSite 0.9.3 Multiple Input Validation Vulnerabilities
– Web Animations Password Protect Multiple Input Validation Vulnerabilities
– PHPScheduleIt 1.0 HTML Injection Vulnerability
– Xedus Web Server 1.0 Multiple Vulnerabilities
– Nagl XOOPS Dictionary Module 1.0 Multiple Cross-Site Vulnerabilities
– Novell iChain 2.3 Multiple Remote Vulnerabilities
– Keene Digital Media Server 1.0.2 Directory Traversal Variant Vulnerability
– SugarCRM 1.1 Unspecified Login Authentication Vulnerability

N-Stealth DB General Information
Version: 134
Release Date: 09/27/2004

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.