Sun Java Web Server vulnerabilities and new updates

By N-Stalker Team on June 15, 2005

N-Stalker has made available the latest database update (v153) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner.

to manually download it, use the url:
https://secure.nstalker.com/customercenter/

 

 

If you need any additional assistance during this process, please, contact us at:
E-mail: support at nstalker (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

– Datenbank Module For PHPBB Remote Mod.PHP Cross-Site Scripting Vulnerability
– PHPBB Remote Mod.PHP SQL Injection Vulnerability
– Ariadne CMS Remote File Include Vulnerability
– PHP-Nuke 7.6 Surveys Module HTTP Response Splitting Vulnerability
– Xerox MicroServer Web Server Default Account Authentication Bypass Vulnerability
– Mafia Blog Administrator Authentication Bypass Vulnerability
– MyBloggie 2.1.1 Comment HTML Injection Vulnerability
– Monkey 0.9.1 HTTP Daemon CGI Processor Format String Vulnerability
– PHPMyAdmin 2.6.1 Convcharset Cross-Site Scripting Vulnerability
– IlohaMail 0.8.14rc2 Email Message Remote HTML Injection Vulnerability
– SPHPBlog 0.4.0 Search.PHP Cross-Site Scripting Vulnerability
– S9Y Serendipity 0.8 Exit.PHP SQL injection Vulnerability
– All4WWW-HomePageCreator 1.0 Index.PHP Arbitrary Remote File Include Vulnerability
– Sun Java System Web Server 6.0 Unspecified Denial of Service Vulnerability
– PHPBB Photo Album 2.0.53 Module Album_Comment.PHP Cross-Site Scripting Vulnerability
– PHPBB Photo Album Module Album_Cat.PHP Cross-Site Scripting Vulnerability
– PHPBB2 Plus 1.52 ViewTopic.PHP Cross-Site Scripting Vulnerability
– PHPBB2 Plus 1.52 ViewForum.PHP Cross-Site Scripting Vulnerability
– PHPBB2 Plus 1.52 Portal.PHP Multiple Cross-Site Scripting Vulnerabilities
– PHPBB2 Plus 1.52 GroupCP.PHP Cross-Site Scripting Vulnerability
– PHPBB2 Plus 1.52 Index.PHP Multiple Cross-Site Scripting Vulnerabilities
– ACNews 1.0 Login.ASP SQL Injection Vulnerability
– PostNuke Phoenix 0.760 SID Parameter Remote SQL Injection Vulnerability
– Pinnacle Cart Index.PHP Cross-Site Scripting Vulnerability
– XAMPP 1.4.13 Insecure Default Password Disclosure Vulnerability
– XAMPP 1.4.13 Guestbook-EN.PL Remote HTML Injection Vulnerability
– IBM Lotus Domino Server 6.5.3 Malformed POST Request Remote Buffer Overflow Vulnerability
– XAMPP 1.4.13 Phonebook.PHP Remote HTML Injection Vulnerability
– XAMPP 1.4.13 CDS.PHP Remote HTML Injection Vulnerability
– JPortal 2.3.1 Banner.PHP SQL Injection Vulnerability
– Comersus Cart 5.0.9 Comersus_Search_Item.ASP Cross-Site Scripting Vulnerability
– AEwebworks Dating Software AeDating 3.2 Index.PHP Local File Include Vulnerability
– AEwebworks Dating Software AeDating 3.2 Sdating.PHP SQL Injection Vulnerability
– TowerBlog 0.6 User Credential Exposure Weakness
– Azerbaijan Development Group AzDGDatingPlatinum 1.1.0 Multiple Vulnerabilities

N-Stealth DB General Information
Version: 153
Release Date: 06/15/2005

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.