Apache mod_ssl vulnerabilities and new updates
N-Stalker has made available the latest database update (v134) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner(to manually download it, use the url https://secure.nstalker.com/customercenter/).
If you need any additional assistance during this process, please, contact us at:
E-mail: click here (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)
This release has included the following vulnerabilities:
- MyServer Directory Traversal Vulnerability
- BBS E-Market Professional 1.3.0 Multiple File Disclosure Vulnerabilities
- Apache Mod_DAV LOCK Denial Of Service Vulnerability
- PHP Remote Arbitrary Location File Upload Vulnerability
- SnipSnap 0.5.2 HTTP Response Splitting Vulnerability
- Pingtel Xpressa Handset 2.1.11 Remote Denial Of Service Vulnerability
- FocalMedia.net Turbo Seek 1.7.1 Information Disclosure Vulnerability
- PostNuke Modules Factory 2.0 Subjects Module SQL Injection Vulnerability
- GetSolutions GetIntranet Multiple Remote Input Validation Vulnerabilities
- GetSolutions GetInternet Multiple SQL Injection Vulnerabilities
- BBS E-Market Professional 1.3.0 Remote File Include Vulnerability
- UtilMind Solutions Site News 1.1 Authentication Bypass Vulnerability
- Tutti Nova 0.9.4 Cross-site Scripting Vulnerabilities
- eZ/eZphotoshare 3.4 Remote Denial Of Service Vulnerability
- SAFE TEAM Regulus Customer Statistics Information Disclosure Vulnerability
- SAFE TEAM Regulus 2.2.95 Staffile Information Disclosure Vulnerability
- OpenCA 0.9.2 HTML Injection Vulnerability
- PSnews 1.1 No Parameter Cross-Site Scripting Vulnerability
- Keene Digital Media Server 1.0.2 Cross-Site Scripting Vulnerabilities
- Ipswitch WhatsUp Gold 8.0.3 prn.htm Denial Of Service Vulnerability
- Apache 2.0.51 mod_ssl Denial Of Service Vulnerability
- SiteCubed MailWorks Professional Authentication Bypass Vulnerability
- CuteNews 1.3.6 index.php Cross-Site Scripting Vulnerability
- Comersus Cart 5.0.9 SQL Injection Vulnerability
- pLog 0.3.2 User Registration HTML Injection Vulnerability
- TorrentTrader 2.0 Download.PHP SQL Injection Vulnerability
- Cerbère Proxy Server 1.2 Long Host Header Field Remote Denial of Service Vulnerability
- Newtelligence DasBlog 1.6 Request Log HTML Injection Vulnerability
- PHPWebSite 0.9.3 Multiple Input Validation Vulnerabilities
- Web Animations Password Protect Multiple Input Validation Vulnerabilities
- PHPScheduleIt 1.0 HTML Injection Vulnerability
- Xedus Web Server 1.0 Multiple Vulnerabilities
- Nagl XOOPS Dictionary Module 1.0 Multiple Cross-Site Vulnerabilities
- Novell iChain 2.3 Multiple Remote Vulnerabilities
- Keene Digital Media Server 1.0.2 Directory Traversal Variant Vulnerability
- SugarCRM 1.1 Unspecified Login Authentication Vulnerability
N-Stealth DB General Information
Version: 134
Release Date: 09/27/2004

