PHP Vulnerabilities and new updates
N-Stalker has made available the latest database update (v170) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner.
![]() |
to manually download it, use the url: https://secure.nstalker.com/customercenter/ |
If you need any additional assistance during this process, please, contact us at:
E-mail: support at nstalker (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)
This release has included the following vulnerabilities:
– PHP 4.4.1/5.5.1 MySQLI Error Logging Remote Format String Vulnerability
– PHP 4.4.1/5.5.1 PHPInfo Cross-Site Scripting Vulnerability
– PmWiki 2.0.12 Search Cross-Site Scripting Vulnerability
– Virtual Hosting Control System 2.4.6.2 Error Message Cross-Site Scripting Vulnerability
– PHPPost 1.0 Multiple Cross-Site Scripting Vulnerabilities
– Tru-Zone Nuke ET 3.2 Search Module SQL Injection Vulnerability
– PHP Download Manager 1.1.3 Files.PHP SQL Injection Vulnerability
– APBoard Thread.PHP SQL Injection Vulnerability
– Apache Struts 1.2.7 Error Response Cross-Site Scripting Vulnerability
– PHPComasy 0.7.5 Index.PHP SQL Injection Vulnerability
– SimplePoll Results.PHP SQL Injection Vulnerability
– Advanced Poll 2.0.3 Popup.PHP Cross-Site Scripting Vulnerability
– MediaWiki 1.5 beta3 HTML Inline Style Attributes Unspecified Cross-Site Scripting Vulnerability
– PHPMyAdmin 2.6.4 Multiple Cross-Site Scripting Vulnerabilities
– PHPMyAdmin 2.6.3-pl1 Error.PHP Cross-Site Scripting Vulnerability
– VP-ASP Shopping Cart 5.50 Shopadmin.ASP HTML Injection Vulnerability
– Revize CMS HTTPTranslatorServlet Cross-Site Scripting Vulnerability
– FUDForum 2.6.15 Tree View Access Validation Vulnerability
– Revize CMS Query_results.JSP SQL Injection Vulnerability
– Revize CMS Revize.XML Information Disclosure Vulnerability
– PHPLDAPAdmin 0.9.7 Welcome.PHP Multiple Vulnerabilities
– Pmachine Pro 2.4 Email This Entry Mail_autocheck.PHP Remote File Include Vulnerability
– PHPLDAPAdmin 0.9.5 Unauthorized Access Vulnerability
– Uresk Links 2.0 Admin Index.PHP Authentication Bypass Vulnerability
– Arki-DB 2.0 Index.PHP SQL Injection Vulnerability
– Unclassified 1.5.3a NewsBoard Forum.PHP SQL Injection Vulnerability
– PHPWebThings 1.4 MSG Parameter SQL Injection Vulnerability
– Antharia OnContent // CMS Index.PHP SQL Injection Vulnerability
– PHPWebThing 0.4.4 Forum.PHP SQL Injection Vulnerability
– AudienceView Error.ASP Cross-Site Scripting Vulnerability
– JAWS 0.5.2 Remote File Include Vulnerability
– GeSHI 1.0.7.2 Example.PHP Local File Include Vulnerability
– Pearl Forums 2.0 Index.PHP Local File Include Vulnerability
– MyBulletinBoard 1.0PR2 Multiple HTML Injection Vulnerabilities
– PHPMyAdmin 2.7.0-beta1 Header_HTTP_Inc.PHP HTTP Response Splitting Vulnerability
– MyBulletinBoard 1.0 Usercp.PHP SQL Injection Vulnerability
– PHPNuke 7.8 Search Module SQL Injection Vulnerability
– phpAdsNew 2.0.6 Lib-sessions.inc.PHP SQL Injection Vulnerability
– Peel 2.7 rubid Parameter SQL Injection Vulnerability
– TikiWiki 1.8.5 Tiki-User_Preferences.PHP Directory Traversal Vulnerability
– TikiWiki 1.8.5 Tiki-Editpage.PHP Directory Traversal Vulnerability
– YaBB 2.0 Image Upload HTML Injection Vulnerability
– YaBB SE 1.5.1 News.PHP Remote File Include Vulnerability
N-Stealth DB General Information
Version: 170
Release Date: 01/29/2006