PHPBB Vulnerabilities and new updates

By N-Stalker Team on June 30, 2005

N-Stalker has made available the latest database update (v154) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner.

to manually download it, use the url:
https://secure.nstalker.com/customercenter/

 

 

If you need any additional assistance during this process, please, contact us at:
E-mail: support at nstalker (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

– Black Knight Forum 4.0 Member.ASP SQL Injection Vulnerability
– WoltLab Burning Board 2.3.1 Thread.PHP Cross-Site Scripting Vulnerability
– WebCT 4.1 Campus Edition Discussion Board HTML Injection Vulnerability
– ASPNuke 0.80 Select.ASP Cross-Site Scripting Vulnerability
– ASPNuke 0.80 Profile.ASP Cross-Site Scripting Vulnerability
– OneWorldStore CHKSettings.ASP Remote Denial Of Service Vulnerability
– PixySoft E-Cart 1.1 Cat Parameter Remote Command Execution Vulnerability
– ASPNuke 0.80 Detail.ASP SQL Injection Vulnerability
– ASPNuke 0.80 Comments.ASP SQL Injection Vulnerability
– ProfitCode Software PayProCart 3.0 AdminShop TaskID Cross-Site Scripting Vulnerability
– ProfitCode Software PayProCart 3.0 AdminShop ModID Cross-Site Scripting Vulnerability
– ProfitCode Software PayProCart 3.0 AdminShop HDoc Cross-Site Scripting Vulnerability
– ProfitCode Software PayProCart 3.0 Ckprvd Cross-Site Scripting Vulnerability
– ProfitCode Software PayProCart 3.0 Username Cross-Site Scripting Vulnerability
– FlexPHPNews 0.0.3 News.PHP SQL Injection Vulnerability
– Yawcam 0.2.5 Directory Traversal Vulnerability
– AZ Bulletin Board 1.0.7 Remote File Include Vulnerability
– DUportal/DUportal 3.1.2 SQL Multiple SQL Injection Vulnerabilities
– PHProjekt 4.2 Chatroom Text Submission HTML Injection Vulnerability
– Coppermine Photo Gallery 1.3.2 Favs SQL Injection Vulnerability
– DUportal Pro 3.4 Multiple SQL Injection Vulnerabilities
– PHP Labs proFile File URI Variable Cross-Site Scripting Vulnerability
– PHP Labs proFile Dir URI Variable Cross-Site Scripting Vulnerability
– PHPBB-Auction 1.2 Module Auction_Offer.PHP SQL Injection Vulnerability
– PHPBB-Auction 1.2 Module Auction_Rating.PHP SQL Injection Vulnerability
– Netref 4.2 Cat_for_gen.PHP Remote PHP Script Injection Vulnerability
– ECommPro 3.0 Admin/Login.ASP SQL Injection Vulnerability
– OneWorldStore DisplayResults.ASP Cross-Site Scripting Vulnerability
– WheresJames Webcam Publisher Web Server Buffer Overflow Vulnerability
– CityPost PHP Image Editor 52 URI Parameter Cross-Site Scripting Vulnerability
– CityPost PHP LNKX 52 Message.PHP Cross-Site Scripting Vulnerability
– WebcamXP 1.7.80 Chat Name HTML Code Injection Vulnerability
– UBBCentral UBB.threads 6.0 Printthread.PHP SQL Injection Vulnerability
– JAWS 0.5 Glossary HTML Injection Vulnerability
– Info2www 1.2.2.9 Cross-Site Scripting Vulnerability
– OneWorldStore OWListProduct.ASP Cross-Site Scripting Vulnerability
– OneWorldStore OWContactUs.ASP Cross-Site Scripting Vulnerability
– OneWorldStore OWListProduct.ASP Multiple SQL Injection Vulnerabilities
– OneWorldStore OWAddItem.ASP SQL Injection Vulnerability
– OneWorldStore DisplayResults.ASP SQL Injection Vulnerability
– PHPBB 2.0.13 Knowledge Base Module KB.PHP SQL Injection Vulnerability
– MVNForum 1.0 Search Cross-Site Scripting Vulnerability

N-Stealth DB General Information
Version: 154
Release Date: 06/30/2005

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.