XML-RPC vulnerability and new updates
N-Stalker has made available the latest database update (v168) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner.
![]() |
to manually download it, use the url: https://secure.nstalker.com/customercenter/ |
If you need any additional assistance during this process, please, contact us at:
E-mail: support at nstalker (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)
This release has included the following vulnerabilities:
– PHPNuke 7.9 Modules.PHP Search Module Remote Directory Traversal Vulnerability
– MySource 2.14.0 Multiple Cross-Site Scripting Vulnerabilities
– NetFlow Analyzer 4 Cross-Site Scripting Vulnerability
– E107 0.6172 Resetcore.PHP SQL Injection Vulnerability
– Comersus BackOffice Plus Multiple Cross-Site Scripting Vulnerabilities
– PunBB 1.2.8 Search.PHP SQL Injection Vulnerability
– Gallery 2.0 Main.PHP Directory Traversal Vulnerability
– Complete PHP Counter Cross-Site Scripting Vulnerability
– Complete PHP Counter SQL Injection Vulnerability
– Yapig 0.95b View.PHP Cross-Site Scripting Vulnerability
– Xeobook 0.93 Multiple HTML Injection Vulnerabilities
– XML-RPC for PHP 4.3.11 Remote Code Injection Vulnerability (update)
– PHPWebSite 0.10.1 Search Module SQL Injection Vulnerability
– GFI MailSecurity for Exchange/SMTP Web Interface Remote Buffer Overflow Vulnerability
– SquirrelMail 1.4.2 Address Add Plugin Add.PHP Cross-Site Scripting Vulnerability
– PHP-Fusion 6.0.107 Multiple SQL Injection Vulnerabilities
– MediaWiki 1.4.8 Multiple Cross-Site Scripting Vulnerabilities
– IceWarp 5.5.1 Web Mail Directory Traversal Vulnerability
– EasyGuppy 4.5.5 Printfaq.PHP Directory Traversal Vulnerability
– IceWarp 5.5.1 Multiple Cross-Site Scripting Vulnerabilities
– lucidCMS 1.0.11 Login SQL Injection Vulnerability
– Polipo 0.9.8 Web Root Restriction Bypass Vulnerability
– PunBB 1.2.6 BBCode URL Tag HTML Injection Vulnerability
– PunBB 1.2.6 Multiple SQL Injection Vulnerabilities
– MyBulletinBoard 1.0 Forumdisplay.PHP Cross-Site Scripting Vulnerability
– GuppY 4.5.3 PrintFAQ.PHP Cross-Site Scripting Vulnerability
– Land Down Under 801 Events.PHP HTML Injection Vulnerability
– MyBloggie 2.1.0 login.php SQL Injection Vulnerability
– Plain Black Software WebGUI 6.7.2 Remote Perl Command Execution Vulnerabilities
N-Stealth DB General Information
Version: 168
Release Date: 01/04/2006