BEA Vulnerabilities and new updates
N-Stalker has made available the latest database update (v157) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner.
![]() |
to manually download it, use the url: https://secure.nstalker.com/customercenter/ |
If you need any additional assistance during this process, please, contact us at:
E-mail: support at nstalker (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)
This release has included the following vulnerabilities:
– OS4E LOGIN.ASP SQL Injection Vulnerability
– BEA WebLogic 8.1 SP4 Administration Console Error Page Cross-Site Scripting Vulnerability
– BEA WebLogic 8.1 SP4 Administration Console LoginForm.jsp Cross-Site Scripting Vulnerability
– Hosting Controller 6.1 HF2.0 Multiple Vulnerabilities
– Invision Power Board 1.3 Unauthorized Access Vulnerability
– MyBloggie 2.1.2 Multiple Input Validation Vulnerabilities
– Newmad Technologies PicoWebServer 1.0 Remote Buffer Overflow Vulnerability
– PHPStat 1.5 Setup.PHP Authentication Bypass Vulnerability
– PostNuke 0.760 SQL Injection and Cross-Site Scripting Vulnerabilities
– ZonGG 1.2 Login.ASP SQL Injection Vulnerability
– BookReview 1.0 Multiple Cross-Site Scripting Vulnerabilities
– PHP Poll Creator 1.0.1 Poll_Vote.PHP Remote File Include Vulnerability
– Invision Power Board 2.0.3 Login.PHP SQL Injection Vulnerability
– MaxWebPortal 2.0 Password.ASP SQL Injection Vulnerability
– FunkyASP AD Systems 1.1 Login.ASP SQL Injection Vulnerability
– GForge 3.3 Remote Arbitrary Command Execution Vulnerability
– Spread The Word Multiple SQL Injection Vulnerabilities
– Spread The Word Multiple Cross-Site Scripting Vulnerabilities
– Blue Coat Reporter 7.1.1 License HTML Injection Vulnerability
– Sambar Server 6.1 beta2 Administrative Interface Multiple Cross-Site Scripting Vulnerabilities
– PostNuke 0.760rc3 Multiple Remote Input Validation Vulnerabilities
– EJ3 TOPo 2.2 Multiple Index.PHP Cross-Site Scripting Vulnerabilities
– PHP Advanced Transfer Manager 1.21 Arbitrary File Include Vulnerability
– PostNuke Phoenix Module 0.760 Parameter Remote Cross-Site Scripting Vulnerability
– PROMS 0.10 Project Members Unauthorized Access Vulnerability
– PROMS 0.10 Multiple SQL Injection Vulnerabilities
– S9Y Serendipity 0.8 Multiple Remote Vulnerabilities
– Help Center Live 1.2.7 Administrator Command Execution Vulnerability
– Help Center Live 1.2.7 Multiple Input Validation Vulnerabilities
– WordPress 1.5 Edit.PHP Cross-Site Scripting Vulnerability
– FusionPHP Fusion News 3.6.1 X-Forwarded-For PHP Script Code Injection Vulnerability
– WordPress 1.5 Post.PHP Cross-Site Scripting Vulnerability
– WordPress 1.5 WP-Trackback.PHP SQL Injection Vulnerability
– JGS-Portal 3.0.2 Multiple Cross-Site Scripting and SQL Injection Vulnerabilities
– WoltLab Burning Board 2.3.1 Verify_email Function SQL Injection Vulnerability
– NPDS 5.0 THOLD Parameter SQL Injection Vulnerability
– DotNetNuke User Registration Information HTML Injection Vulnerability
– Sigma ISP Manager 6.6 Sigmaweb.DLL SQL Injection Vulnerability
– MetaCart 2 E-Shop ProductsByCategory.ASP Cross-Site Scripting Vulnerability
– WebAPP 0.9.9.2.1 Apage.CGI Remote Command Execution Vulnerability
– PostNuke 0.76 Blocks Module Directory Traversal Vulnerability
– Pserv 3.2 Directory Traversal Vulnerability
– Shop-Script ProductID SQL Injection Vulnerability
– Shop-Script CategoryID SQL Injection Vulnerability
– SWSoft Confixx 3.0.8 Change User SQL Injection Vulnerability
– Skull-Splitter Guestbook 2.2 Multiple HTML Injection Vulnerabilities
– 1Two Livre D’Or 1.0 Guestbook.PHP Multiple HTML Injection Vulnerabilities
– Keyvan1 ImageGallery Database Download Vulnerability
– ASP Portal 2.0 Login.ASP Password Parameter SQL Injection Vulnerability
– PHPHeaven PHPMyChat 0.14.5 Style.CSS.PHP3 Cross-Site Scripting Vulnerability
– PHPHeaven PHPMyChat 0.14.5 Start-Page.CSS.PHP3 Cross-Site Scripting Vulnerability
– OpenBB 1.0.8 Member.PHP Cross-Site Scripting Vulnerability
– OpenBB 1.0.8 Read.PHP SQL Injection Vulnerability
– Ultimate PHP Board 1.9.6 ViewForum.PHP Cross-Site Scripting Vulnerability
N-Stealth DB General Information
Version: 157
Release Date: 07/27/2005