Ruby Vulnerabilities and new updates

By N-Stalker Team on November 3, 2005

N-Stalker has made available the latest database update (v164) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner.

to manually download it, use the url:
https://secure.nstalker.com/customercenter/

 

 

If you need any additional assistance during this process, please, contact us at:
E-mail: support at nstalker (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

or 1.5.1 Login.PHP Cross-Site Scripting Vulnerability
– PHPOutsourcing Zorum 3.5 Prod.PHP Arbitrary Command Execution Vulnerability
– My Image Gallery 1.4.1 Multiple Cross Site Scripting Vulnerabilities
– ECW Shop 6.0.2 Index.PHP SQL Injection Vulnerability
– PHPFreeNews 1.40 SearchResults.PHP Multiple SQL Injection Vulnerabilities
– FunkBoard 0.66CF Multiple Cross-Site Scripting Vulnerabilities
– Yukihiro Matsumoto Ruby 1.8.2 XMLRPC Server Unspecified Command Execution Vulnerability
– Simplicity oF Upload 1.3 Download.PHP Remote File Include Vulnerability
– PHPTB Topic Board 2.0 Multiple SQL Injection Vulnerabilities
– VegaDNS 0.9.8 Index.PHP Cross Site Scripting Vulnerability
– Fusebox 4.1.0 Index.CFM Cross-Site Scripting Vulnerability
– Jax DWT Editor v1.0 Multiple Cross-site scripting Vulnerabilities
– Jax Calendar 1.34 Multiple Cross-site Scripting Vulnerabilities
– Jax LinkLists v1.1 Client IP Address List Disclosure
– Jax LinkLists v1.1 Multiple Cross-site scripting Vulnerabilities
– Jax Newsletter v2.14 Multiple Cross-site Scripting Vulnerabilities
– Jax PHP Petitionbook Log File disclosure
– Jax Guestbook v3.31 Multiple Cross-site scripting vulnerabilities
– Comdev 3.0 eCommerce WCE.Download.PHP Directory Traversal Vulnerability
– FlatNuke 2.5.5 User Data Arbitrary PHP Code Execution Vulnerability
– FlatNuke 2.5.5 Multiple Cross Site Scripting Vulnerabilities
– Owl Intranet Engine Multiple 0.8 Cross-Site Scripting and SQL Injection Vulnerabilities
– PortailPHP 2.4 Index.PHP SQL Injection Vulnerability
– Invision Power Board 1.0.3 Attached File Cross-Site Scripting Vulnerability
– E107 Website System Attached File Cross-Site Scripting Vulnerability
– Gravity Board X 1.1 DeleteThread.PHP Cross-Site Scripting Vulnerability
– PHPBB 2.0.15 Viewtopic.PHP Remote Code Execution Vulnerability
– Calendar Express 2.0 Search.PHP Cross-Site Scripting Vulnerability
– DVBBS 7.1 Sp2 Multiple Cross Site Scripting Vulnerabilities
– Chipmunk CMS Fontcolor Cross Site Scripting Vulnerability
– @Mail 4.03/4.11 Multiple Cross Site Scripting Vulnerabilities
– Silvernews 2.0.3 Admin.PHP SQL Injection Vulnerability
– Web Content Management Multiple Cross-Site Scripting Vulnerabilities
– Web Content Management Administrator Account Unauthorized Access Vulnerability
– Naxtor E-directory Message.ASP Cross Site Scripting Vulnerability
– NetworkActiv Web Server 3.5.13 Cross-Site Scripting Vulnerability
– Comdev 3.0 ECommerce Config.PHP Remote File Include Vulnerability
– EMC Navisphere Manager 6.6 Directory Traversal And Information Disclosure Vulnerabilities

N-Stealth DB General Information
Version: 164
Release Date: 11/03/2005

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.