BEA WebLogic vulnerabilities and new updates

By N-Stalker Team on November 17, 2005

N-Stalker has made available the latest database update (v165) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner.

to manually download it, use the url:
https://secure.nstalker.com/customercenter/

 

 

If you need any additional assistance during this process, please, contact us at:
E-mail: support at nstalker (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

- Noah’s Classifieds 1.3 Index.PHP SQL Injection Vulnerability
- MIVA Merchant 5 Merchant.MVC Cross-Site Scripting Vulnerability
- Land Down Under 801 Multiple SQL Injection Vulnerabilities
- PHPTagCool 1.0.3 HTTP Header SQL Injection Vulnerability
- MyBulletinBoard 1.0 RateThread.PHP SQL Injection Vulnerability
- Stylemotion 1.4 WEB//NEWS Multiple SQL Injection Vulnerabilities
- Class-1 0.24.4 Forum SQL Injection Vulnerability
- PHPCommunityCalendar 4.0.3 Multiple Remote Cross-Site Scripting Vulnerabilities
- PHPLDAPAdmin 0.9.7 Welcome.PHP Multiple Vulnerabilities
- PHPCommunityCalendar 4.0.3 Multiple SQL Injection Vulnerabilities
- PBLang Bulletin Board System 4.65 SetCookie.PHP Directory Traversal Vulnerability
- Microsoft IIS 5.1 WebDAV HTTP Request Source Code Disclosure Vulnerability
- MyBulletinBoard 1.0 Multiple SQL Injection Vulnerabilities
- MyBulletinBoard 1.0 Forumdisplay.PHP Cross-Site Scripting Vulnerability
- MAXdev MD-Pro 1.0.73 Multiple Cross-Site Scripting Vulnerabilities
- Man2web 0.88 Multiple Scripts Command Execution Vulnerability
- Looking Glass Remote Command Execution Vulnerability
- Looking Glass Cross-Site Scripting Vulnerability
- PHPWebNotes 2.0 Api.PHP Remote File Include Vulnerability
- Land Down Under 800 Multiple Events.php & Index.php SQL Injection Vulnerabilities
- BEA WebLogic 8.1 SP4 Administration Console Cross-Site Scripting Vulnerability
- PostNuke 0.76 DL-viewdownload.PHP SQL Injection Vulnerability
- Land Down Under 800 Multiple SQL Injection Vulnerabilities
- Land Down Under 800 Multiple Cross-Site Scripting Vulnerabilities
- MyBulletinBoard RC4 Search.PHP SQL Injection Vulnerability
- NEPHP 3.0.4 Browse.PHP Cross Site Scripting Vulnerability
- RunCMS 1.2 NewBB_Plus and Messages Modules Multiple SQL Injection Vulnerabilities
- PHPKit 1.6.1 Multiple SQL Injection Vulnerabilities
- PostNuke 0.76 Multiple Cross Site Scripting Vulnerabilities
- ECW 6.0.2 Shop Index.PHP Cross Site Scripting Vulnerability
- PHPFreeNews 1.40 Multiple Cross-Site Scripting Vulnerabilities
- PHPTB 2.0 Topic Board Multiple Remote File Include Vulnerabilities
- W-Agora 4.2 Site Parameter Directory Traversal Vulnerability

N-Stealth DB General Information
Version: 165
Release Date: 11/17/2005

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.