PHP Vulnerabilities and new updates
N-Stalker has made available the latest database update (v170) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner.
![]() |
to manually download it, use the url: https://secure.nstalker.com/customercenter/ |
If you need any additional assistance during this process, please, contact us at:
E-mail: support at nstalker (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)
This release has included the following vulnerabilities:
- PHP 4.4.1/5.5.1 MySQLI Error Logging Remote Format String Vulnerability
- PHP 4.4.1/5.5.1 PHPInfo Cross-Site Scripting Vulnerability
- PmWiki 2.0.12 Search Cross-Site Scripting Vulnerability
- Virtual Hosting Control System 2.4.6.2 Error Message Cross-Site Scripting Vulnerability
- PHPPost 1.0 Multiple Cross-Site Scripting Vulnerabilities
- Tru-Zone Nuke ET 3.2 Search Module SQL Injection Vulnerability
- PHP Download Manager 1.1.3 Files.PHP SQL Injection Vulnerability
- APBoard Thread.PHP SQL Injection Vulnerability
- Apache Struts 1.2.7 Error Response Cross-Site Scripting Vulnerability
- PHPComasy 0.7.5 Index.PHP SQL Injection Vulnerability
- SimplePoll Results.PHP SQL Injection Vulnerability
- Advanced Poll 2.0.3 Popup.PHP Cross-Site Scripting Vulnerability
- MediaWiki 1.5 beta3 HTML Inline Style Attributes Unspecified Cross-Site Scripting Vulnerability
- PHPMyAdmin 2.6.4 Multiple Cross-Site Scripting Vulnerabilities
- PHPMyAdmin 2.6.3-pl1 Error.PHP Cross-Site Scripting Vulnerability
- VP-ASP Shopping Cart 5.50 Shopadmin.ASP HTML Injection Vulnerability
- Revize CMS HTTPTranslatorServlet Cross-Site Scripting Vulnerability
- FUDForum 2.6.15 Tree View Access Validation Vulnerability
- Revize CMS Query_results.JSP SQL Injection Vulnerability
- Revize CMS Revize.XML Information Disclosure Vulnerability
- PHPLDAPAdmin 0.9.7 Welcome.PHP Multiple Vulnerabilities
- Pmachine Pro 2.4 Email This Entry Mail_autocheck.PHP Remote File Include Vulnerability
- PHPLDAPAdmin 0.9.5 Unauthorized Access Vulnerability
- Uresk Links 2.0 Admin Index.PHP Authentication Bypass Vulnerability
- Arki-DB 2.0 Index.PHP SQL Injection Vulnerability
- Unclassified 1.5.3a NewsBoard Forum.PHP SQL Injection Vulnerability
- PHPWebThings 1.4 MSG Parameter SQL Injection Vulnerability
- Antharia OnContent // CMS Index.PHP SQL Injection Vulnerability
- PHPWebThing 0.4.4 Forum.PHP SQL Injection Vulnerability
- AudienceView Error.ASP Cross-Site Scripting Vulnerability
- JAWS 0.5.2 Remote File Include Vulnerability
- GeSHI 1.0.7.2 Example.PHP Local File Include Vulnerability
- Pearl Forums 2.0 Index.PHP Local File Include Vulnerability
- MyBulletinBoard 1.0PR2 Multiple HTML Injection Vulnerabilities
- PHPMyAdmin 2.7.0-beta1 Header_HTTP_Inc.PHP HTTP Response Splitting Vulnerability
- MyBulletinBoard 1.0 Usercp.PHP SQL Injection Vulnerability
- PHPNuke 7.8 Search Module SQL Injection Vulnerability
- phpAdsNew 2.0.6 Lib-sessions.inc.PHP SQL Injection Vulnerability
- Peel 2.7 rubid Parameter SQL Injection Vulnerability
- TikiWiki 1.8.5 Tiki-User_Preferences.PHP Directory Traversal Vulnerability
- TikiWiki 1.8.5 Tiki-Editpage.PHP Directory Traversal Vulnerability
- YaBB 2.0 Image Upload HTML Injection Vulnerability
- YaBB SE 1.5.1 News.PHP Remote File Include Vulnerability
N-Stealth DB General Information
Version: 170
Release Date: 01/29/2006


