PHP Vulnerabilities and new updates

By N-Stalker Team on August 9, 2005

N-Stalker has made available the latest database update (v158) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner.

to manually download it, use the url:
https://secure.nstalker.com/customercenter/

 

 

If you need any additional assistance during this process, please, contact us at:
E-mail: support at nstalker (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

– YaPiG 0.94 Upload.PHP Directory Traversal Vulnerability
– YaPiG 0.94 View.PHP Multiple HTML Injection Vulnerabilities
– YaPiG 0.94 Remote and Local File Include Vulnerabilities
– Sawmill 7.1.5 Add User Cross-Site Scripting Vulnerability
– Popper Webmail 1.41 ChildWindow.Inc.PHP Remote File Include Vulnerability
– WWWeb Concepts Events System LOGIN.ASP SQL Injection Vulnerability
– MWChat 6.7 Start_Lobby.PHP Remote File Include Vulnerability
– FlatNuke 2.5.4 Multiple Input Validation Vulnerabilities
– PHPThumb 1.5.3 Arbitrary File Information Disclosure Vulnerability
– Exhibit Engine 1.54 List.php Cross-site Scripting Vulnerability
– Exhibit Engine 1.54 List.php SQL Injection Vulnerability
– phpCMS 1.2.1 Parser.PHP File Disclosure Vulnerability
– JiRo’s Upload System 1.0 Login.ASP SQL Injection Vulnerability
– NextWeb (i)Site Database Exposure
– Liberum Help Desk 0.97.3 Multiple SQL Injection Vulnerabilities
– I-Man 1.0 File Attachments Remote Arbitrary PHP Script Execution Vulnerability
– I-Man 0.9 Login Cross-Site Script Vulnerabilities
– Hosting Controller 6.1 HF2 SendPassword.ASP Cross-Site Scripting Vulnerability
– Calendarix 1.5 CalPath Remote File Include Vulnerability
– Calendarix 1.5 Multiple SQL Injection and Cross-Site Scripting Vulnerabilities
– FreeStyle Wiki 3.5.7 Attachment HTML Injection Vulnerability
– PHP Group PHP 4.3.10 Multiple Vulnerabilities
– MyBB RC4 Multiple Cross-Site Scripting and SQL Injection Vulnerabilities
– Zeroboard 4.1pl5 Preg_replace Remote Command Execution Vulnerability
– Boa Webserver 0.94.12 File Disclosure Vulnerability
– PowerDownload 3.0.3 IncDir Remote File Include Vulnerability
– NewLife Blogger 3.3 Multiple SQL Injection Vulnerabilities
– ZPanel 2.5 Multiple SQL Injection and File Include Vulnerabilities
– PHP-Nuke 7.3 Direct Script Access Security Bypass Vulnerability
– ServersCheck 5.10.0 Directory Traversal Vulnerability
– India Software Solution Shopping Cart SQL Injection Vulnerability
– NikoSoft WebMail 0.10.4 Cross-Site Scripting Vulnerability

N-Stealth DB General Information
Version: 158
Release Date: 08/09/2005

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.