Apache vulnerabilities and new updates

By N-Stalker Team on October 29, 2004

N-Stalker has made available the latest database update (v136) for N-Stealth Web Security Scanner.

You should be able to receive it automatically next time you execute the scanner.
To manually download it, use the url:
https://secure.nstalker.com/customercenter/.

If you need any additional assistance during this process, please, contact us at:
E-mail: support at nstalker com (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

– Apache 1.3.32 mod_include Local Buffer Overflow Vulnerability
– YaPiG Comment Field HTML Injection Vulnerability
– Best Software SalesLogix Multiple Remote Vulnerabilities
– cPanel 9.4.x Multiple Vulnerabilities
– IBM Lotus Domino 6.5.2 Cross-Site Scripting and HTML Injection Vulnerabilities
– CoolPHP 1.0 Multiple Remote Input Validation Vulnerabilities
– AliveSites Forum 2.0 Multiple Unspecified Remote Input Validation Vulnerabilities
– Express-Web Content Management System Cross-Site Scripting Vulnerability
– CyberStrong eShop ASP Shopping Cart 4.6 Unspecified Cross-Site Scripting Vulnerability
– DevoyBB Forum 1.0 Multiple Unspecified Remote Input Validation Vulnerabilities
– Ideal Science IdealBB 1.5.3 Multiple Unspecified Remote Input Validation Vulnerabilities
– DMXReady Site Chassis Manager Cross-Site Scripting And SQL Injection Vulnerabilities
– Pinnacle Systems ShowCenter 1.51 SettingsBase.PHP Cross-Site Scripting Vulnerability
– Macromedia JRun 4.0 Session ID Cookie HTTP Response Splitting Vulnerability
– MediaWiki 1.3.5 Multiple Remote Input Validation Vulnerabilities
– Macromedia JRun 4.0 Management Console Administrative Session Fixation Vulnerability
– NatterChat 1.12 SQL Injection Vulnerability
– SCT Campus Pipeline 3.2 Render.UserLayoutRootNode.uP Cross-Site Scripting Vulnerability
– FuseTalk Forum 4.0 Multiple Cross-Site Scripting Vulnerabilities
– 3Com 3CRADSL72 ADSL Wireless Router Information Disclosure and Authentication Bypass Vulnerabilities
– OCPortal 1.0.3 Content Management System Remote File Include Vulnerability
– IceWarp Web Mail 5.2.8 Multiple Remote Input Validation Vulnerabilities
– CJOverkill 4.0.3 Multiple Cross-Site Scripting Vulnerabilities
– Turbo Traffic Trader PHP 1.0 Multiple Input Validation Vulnerabilities
– Go Smart Inc GoSmart Message Board Multiple Input Validation Vulnerabilities
– Zanfi CMS Lite 1.1 Remote File Include Vulnerability
– Apache mod_ssl SSLCipherSuite Restriction Bypass Vulnerability

N-Stealth DB General Information
Version: 136
Release Date: 11/01/2004

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.