BEA WebLogic vulnerabilities and new updates

By N-Stalker Team on November 17, 2005

N-Stalker has made available the latest database update (v165) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner.

to manually download it, use the url:
https://secure.nstalker.com/customercenter/

 

 

If you need any additional assistance during this process, please, contact us at:
E-mail: support at nstalker (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

– Noah’s Classifieds 1.3 Index.PHP SQL Injection Vulnerability
– MIVA Merchant 5 Merchant.MVC Cross-Site Scripting Vulnerability
– Land Down Under 801 Multiple SQL Injection Vulnerabilities
– PHPTagCool 1.0.3 HTTP Header SQL Injection Vulnerability
– MyBulletinBoard 1.0 RateThread.PHP SQL Injection Vulnerability
– Stylemotion 1.4 WEB//NEWS Multiple SQL Injection Vulnerabilities
– Class-1 0.24.4 Forum SQL Injection Vulnerability
– PHPCommunityCalendar 4.0.3 Multiple Remote Cross-Site Scripting Vulnerabilities
– PHPLDAPAdmin 0.9.7 Welcome.PHP Multiple Vulnerabilities
– PHPCommunityCalendar 4.0.3 Multiple SQL Injection Vulnerabilities
– PBLang Bulletin Board System 4.65 SetCookie.PHP Directory Traversal Vulnerability
– Microsoft IIS 5.1 WebDAV HTTP Request Source Code Disclosure Vulnerability
– MyBulletinBoard 1.0 Multiple SQL Injection Vulnerabilities
– MyBulletinBoard 1.0 Forumdisplay.PHP Cross-Site Scripting Vulnerability
– MAXdev MD-Pro 1.0.73 Multiple Cross-Site Scripting Vulnerabilities
– Man2web 0.88 Multiple Scripts Command Execution Vulnerability
– Looking Glass Remote Command Execution Vulnerability
– Looking Glass Cross-Site Scripting Vulnerability
– PHPWebNotes 2.0 Api.PHP Remote File Include Vulnerability
– Land Down Under 800 Multiple Events.php & Index.php SQL Injection Vulnerabilities
– BEA WebLogic 8.1 SP4 Administration Console Cross-Site Scripting Vulnerability
– PostNuke 0.76 DL-viewdownload.PHP SQL Injection Vulnerability
– Land Down Under 800 Multiple SQL Injection Vulnerabilities
– Land Down Under 800 Multiple Cross-Site Scripting Vulnerabilities
– MyBulletinBoard RC4 Search.PHP SQL Injection Vulnerability
– NEPHP 3.0.4 Browse.PHP Cross Site Scripting Vulnerability
– RunCMS 1.2 NewBB_Plus and Messages Modules Multiple SQL Injection Vulnerabilities
– PHPKit 1.6.1 Multiple SQL Injection Vulnerabilities
– PostNuke 0.76 Multiple Cross Site Scripting Vulnerabilities
– ECW 6.0.2 Shop Index.PHP Cross Site Scripting Vulnerability
– PHPFreeNews 1.40 Multiple Cross-Site Scripting Vulnerabilities
– PHPTB 2.0 Topic Board Multiple Remote File Include Vulnerabilities
– W-Agora 4.2 Site Parameter Directory Traversal Vulnerability

N-Stealth DB General Information
Version: 165
Release Date: 11/17/2005

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.