Oracle vulnerabilities and new updates

By N-Stalker Team on March 19, 2006

N-Stalker has made available the latest database update (v172) for N-Stealth Web Security Scanner.
You should be able to receive it automatically next time you execute the scanner.

to manually download it, use the url:
https://secure.nstalker.com/customercenter/

 

 

If you need any additional assistance during this process, please, contact us at:
E-mail: support at nstalker (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

– 88Scripts Event Calendar 2.0 Index.PHP SQL Injection Vulnerability
– Instant Photo Gallery 1.0 Multiple SQL Injection Vulnerabilities
– O-Kiraku Nikki 1.3 Nikki.PHP SQL Injection Vulnerability
– WSN Knowledge Base 1.2 Multiple SQL Injection Vulnerabilities
– Atlantis Knowledge Base 3.0 Search.PHP SQL Injection Vulnerability
– FAQRing 3.0 Answer.PHP SQL Injection Vulnerability
– Softbiz FAQ 1.1 Multiple SQL Injection Vulnerabilities
– Softbiz B2B Trading Marketplace 1.1 Multiple SQL Injection Vulnerabilities
– SocketKB 1.1 Index.PHP SQL Injection Vulnerability
– Basic Analysis And Security Engine 1.2 Base_qry_main.PHP SQL Injection Vulnerability
– Survey System 1.1 Survey.PHP SQL Injection Vulnerability
– PHP Apache 2 Virtual() Safe_Mode and Open_Basedir Restriction Bypass Vulnerability
– FAQ System 1.1 Multiple SQL Injection Vulnerabilities
– Orca Ringmaker 2.3c Ringmaker.PHP SQL Injection Vulnerability
– Orca Blog 1.3b Blog.PHP SQL Injection Vulnerability
– KBase Express 1.0 Multiple SQL Injection Vulnerabilities
– GhostScripter Amazon Shop 5.0 Search.PHP SQL Injection Vulnerability
– Post Affiliate Pro 2.0.4 Index.PHP SQL Injection Vulnerability
– BosDates 4.0 Multiple SQL Injection Vulnerabilities
– Entergal MX 2.0 Multiple SQL Injection Vulnerabilities
– N-13 News 1.2 SQL Injection Vulnerability
– DRZES HMS 3.2 Register_domain.PHP Cross-Site Scripting Vulnerability
– DRZES HMS 3.2 Multiple SQL Injection Vulnerabilities
– PHP Upload Center Directory Traversal Vulnerability
– DMANews 0.904 Multiple SQL Injection Vulnerabilities
– Fantastic Scripts Fantastic News 2.1.1 News.PHP SQL Injection Vulnerability
– Oracle Reports Server 10g 9.0.4.3.3 Multiple Remote Cross-Site Scripting Vulnerabilities
– ASP-Rider 1.6 Default.ASP SQL Injection Vulnerability
– WebCalendar 1.0.1 Export_Handler.PHP File Corruption Vulnerability
– FreeWebStat 1.0 rev37 Multiple Cross-Site Scripting Vulnerabilities
– Randshop Multiple SQL Injection Vulnerabilities
– OKBSYS Lite 1.0 Search.ASP Cross-Site Scripting Vulnerability
– OASYS Lite 1.0 Search.ASP Cross-Site Scripting Vulnerability
– SimpleBBS 1.1 Search Module Parameters SQL Injection Vulnerability
– JBB 0.9.9 SQL Injection Vulnerabilities
– Nicecoder iDesk 1.0 FAQ.PHP SQL Injection Vulnerability

N-Stealth DB General Information
Version: 172
Release Date: 03/19/2006

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.