BEA Vulnerabilities and new updates

By N-Stalker Team on July 27, 2005

N-Stalker has made available the latest database update (v157) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner.

to manually download it, use the url:
https://secure.nstalker.com/customercenter/

 

 

If you need any additional assistance during this process, please, contact us at:
E-mail: support at nstalker (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

- OS4E LOGIN.ASP SQL Injection Vulnerability
- BEA WebLogic 8.1 SP4 Administration Console Error Page Cross-Site Scripting Vulnerability
- BEA WebLogic 8.1 SP4 Administration Console LoginForm.jsp Cross-Site Scripting Vulnerability
- Hosting Controller 6.1 HF2.0 Multiple Vulnerabilities
- Invision Power Board 1.3 Unauthorized Access Vulnerability
- MyBloggie 2.1.2 Multiple Input Validation Vulnerabilities
- Newmad Technologies PicoWebServer 1.0 Remote Buffer Overflow Vulnerability
- PHPStat 1.5 Setup.PHP Authentication Bypass Vulnerability
- PostNuke 0.760 SQL Injection and Cross-Site Scripting Vulnerabilities
- ZonGG 1.2 Login.ASP SQL Injection Vulnerability
- BookReview 1.0 Multiple Cross-Site Scripting Vulnerabilities
- PHP Poll Creator 1.0.1 Poll_Vote.PHP Remote File Include Vulnerability
- Invision Power Board 2.0.3 Login.PHP SQL Injection Vulnerability
- MaxWebPortal 2.0 Password.ASP SQL Injection Vulnerability
- FunkyASP AD Systems 1.1 Login.ASP SQL Injection Vulnerability
- GForge 3.3 Remote Arbitrary Command Execution Vulnerability
- Spread The Word Multiple SQL Injection Vulnerabilities
- Spread The Word Multiple Cross-Site Scripting Vulnerabilities
- Blue Coat Reporter 7.1.1 License HTML Injection Vulnerability
- Sambar Server 6.1 beta2 Administrative Interface Multiple Cross-Site Scripting Vulnerabilities
- PostNuke 0.760rc3 Multiple Remote Input Validation Vulnerabilities
- EJ3 TOPo 2.2 Multiple Index.PHP Cross-Site Scripting Vulnerabilities
- PHP Advanced Transfer Manager 1.21 Arbitrary File Include Vulnerability
- PostNuke Phoenix Module 0.760 Parameter Remote Cross-Site Scripting Vulnerability
- PROMS 0.10 Project Members Unauthorized Access Vulnerability
- PROMS 0.10 Multiple SQL Injection Vulnerabilities
- S9Y Serendipity 0.8 Multiple Remote Vulnerabilities
- Help Center Live 1.2.7 Administrator Command Execution Vulnerability
- Help Center Live 1.2.7 Multiple Input Validation Vulnerabilities
- WordPress 1.5 Edit.PHP Cross-Site Scripting Vulnerability
- FusionPHP Fusion News 3.6.1 X-Forwarded-For PHP Script Code Injection Vulnerability
- WordPress 1.5 Post.PHP Cross-Site Scripting Vulnerability
- WordPress 1.5 WP-Trackback.PHP SQL Injection Vulnerability
- JGS-Portal 3.0.2 Multiple Cross-Site Scripting and SQL Injection Vulnerabilities
- WoltLab Burning Board 2.3.1 Verify_email Function SQL Injection Vulnerability
- NPDS 5.0 THOLD Parameter SQL Injection Vulnerability
- DotNetNuke User Registration Information HTML Injection Vulnerability
- Sigma ISP Manager 6.6 Sigmaweb.DLL SQL Injection Vulnerability
- MetaCart 2 E-Shop ProductsByCategory.ASP Cross-Site Scripting Vulnerability
- WebAPP 0.9.9.2.1 Apage.CGI Remote Command Execution Vulnerability
- PostNuke 0.76 Blocks Module Directory Traversal Vulnerability
- Pserv 3.2 Directory Traversal Vulnerability
- Shop-Script ProductID SQL Injection Vulnerability
- Shop-Script CategoryID SQL Injection Vulnerability
- SWSoft Confixx 3.0.8 Change User SQL Injection Vulnerability
- Skull-Splitter Guestbook 2.2 Multiple HTML Injection Vulnerabilities
- 1Two Livre D’Or 1.0 Guestbook.PHP Multiple HTML Injection Vulnerabilities
- Keyvan1 ImageGallery Database Download Vulnerability
- ASP Portal 2.0 Login.ASP Password Parameter SQL Injection Vulnerability
- PHPHeaven PHPMyChat 0.14.5 Style.CSS.PHP3 Cross-Site Scripting Vulnerability
- PHPHeaven PHPMyChat 0.14.5 Start-Page.CSS.PHP3 Cross-Site Scripting Vulnerability
- OpenBB 1.0.8 Member.PHP Cross-Site Scripting Vulnerability
- OpenBB 1.0.8 Read.PHP SQL Injection Vulnerability
- Ultimate PHP Board 1.9.6 ViewForum.PHP Cross-Site Scripting Vulnerability

N-Stealth DB General Information
Version: 157
Release Date: 07/27/2005

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.