PHP-Fusion vulnerabilities and new updates

By N-Stalker Team on June 21, 2006

N-Stalker has made available the latest database update (v176) for N-Stealth Web Security Scanner.

You should be able to receive it automatically next time you execute the scanner.

To manually download it, use the url: https://customer.nstalker.com/

If you need any additional assistance during this process, please, contact us at:
E-mail: support at nstalker (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

  • PHPSlash 0.8.1 Article.PHP SQL Injection Vulnerability
  • Papoo 2.1.2 Multiple SQL Injection Vulnerabilities
  • Sitekit CMS 6.6 Multiple Cross-Site Scripting Vulnerabilities
  • Commercial Interactive Media SCOOP! 2.3 Multiple Cross-Site Scripting Vulnerabilities
  • Scoop 1.1RC1 Multiple Cross-Site Scripting Vulnerabilities
  • ComputerOil Redakto CMS 3.2 Multiple Cross-Site Scripting Vulnerabilities
  • ProjectApp 3.3 Multiple Cross-Site Scripting Vulnerabilities
  • IntranetApp 3.3 Multiple Cross-Site Scripting Vulnerabilities
  • SiteEnable 3.3 Login.ASP Cross-Site Scripting Vulnerability
  • PortalApp 3.3 Login.ASP Cross-Site Scripting Vulnerability
  • OpenEdit 4.0 Results.HTML Cross-Site Scripting Vulnerability
  • Tolva 0.1.0 Usermods.PHP Remote File Include Vulnerability
  • AbleDesign D-Man 3.0 Title Parameter Cross-Site Scripting Vulnerability
  • E-Publish 2.0 Multiple Input Validation Vulnerabilities
  • Miraserver 1.0RC4 Multiple SQL Injection Vulnerabilities
  • Marwel 2.7 Index.PHP SQL Injection Vulnerability
  • ODFaq 2.1.0 FAQ.PHP SQL Injection Vulnerability
  • Direct News 4.9 Index.PHP SQL Injection Vulnerability
  • ContentServ 3.1 Index.PHP SQL Injection Vulnerability
  • Magnolia 2.1 Search Module Cross-Site Scripting Vulnerability
  • Lighthouse CMS 1.1 Search Cross-Site Scripting Vulnerability
  • Liferay Portal Enterprise 3.6.1 Multiple Cross-Site Scripting Vulnerabilities
  • FLIP 0.9.0.1029 Multiple Cross-Site Scripting Vulnerabilities
  • Cofax 2.0RC3 Search.HTM Cross-Site Scripting Vulnerability
  • Caravel CMS 3.0beta1 Multiple Cross-Site Scripting Vulnerabilities
  • Box UK Amaxus CMS 3.0 Cross-Site Scripting Vulnerability
  • Allinta CMS 2.3.2 Multiple Cross-Site Scripting Vulnerabilities
  • ELOG Web Logbook 2.6.0 Multiple Remote Buffer Overflow Vulnerabilities
  • PHP-Fusion 6.0.0.3 Members.PHP Cross-Site Scripting Vulnerability
  • PlaySMS Index.PHP Cross-Site Scripting Vulnerability
  • Advanced Guestbook 2.3.1 Multiple Cross-Site Scripting Vulnerabilities
  • PHP Fusebox 3.0 Index.PHP Cross-Site Scripting Vulnerability
  • WebCal 3.0.4 Multiple HTML Injection and Cross-Site Scripting Vulnerabilities
  • WebGlimpse 2.14.1 Cross-Site Scripting Vulnerability
  • ScareCrow 2.13 Multiple Cross-Site Scripting Vulnerabilities
  • Binary Board System 0.2.5 Multiple Cross-Site Scripting Vulnerabilities
  • PHP Arena PAFileDB Extreme Edition RC5 SQL Injection Vulnerability
  • IHTML Merchant 2.0 SQL Injection Vulnerability
  • IHTML Merchant Mall SQL Injection Vulnerability
  • Dick Copits PDEstore 1.8 Multiple Cross-Site Scripting Vulnerabilities
  • Kryptronic ClickCartPro 5.1 CP-APP.CGI Cross-Site Scripting Vulnerability

N-Stealth DB General Information
Version: 176
Release Date: 06/21/2006

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.