PHP Forum vulnerabilities and new updates

By N-Stalker Team on July 11, 2006

N-Stalker has made available the latest database update (v177) for N-Stealth Web Security Scanner.

You should be able to receive it automatically next time you execute the scanner.

To manually download it, use the url: Customer Center.

If you need any additional assistance during this process, please, contact us at:
E-mail: support at nstalker (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

  • e-moBLOG 1.3 Multiple SQL Injection Vulnerabilities
  • SleeperChat 0.3f Index.PHP Cross-Site Scripting Vulnerability
  • AndoNET Blog 2004.9.2 Comentarios.PHP SQL Injection Vulnerability
  • SPIP 1.9 Alpha2 Index.PHP3 Cross-Site Scripting Vulnerability
  • sPaiz-Nuke Modules.PHP Cross-Site Scripting Vulnerability
  • NewsPHP Index.PHP Multiple SQL Injection Vulnerabilities
  • Ashwebstudio Ashnews 0.83 Cross-Site Scripting Vulnerability
  • Calendarix 0.6.20050830 Multiple SQL Injection Vulnerabilities
  • SoftMaker Shop Multiple Cross-Site Scripting Vulnerabilities
  • GA’s Forum Light Archive.ASP SQL Injection Vulnerability
  • MyBB 1.0.3 Moderation.PHP SQL Injection Vulnerability
  • Loudblog 0.4 Backend_settings.PHP Remote File Include Vulnerability
  • cPanel Multiple Cross-Site Scripting Vulnerabilities
  • UBB.Threads 6.3 Showflat.PHP SQL Injection Vulnerability
  • AZ Bulletin Board 1.0.8 Post.PHP HTML Injection Vulnerabilities
  • HTMLtoNuke HTMLtonuke.PHP Remote File Include Vulnerability
  • PowerPortal 1.3b Multiple Cross-Site Scripting Vulnerabilities
  • PHP Fusebox 4.0.6 Index.PHP Cross-Site Scripting Vulnerability
  • microBlog 2.0RC10 Index.PHP Multiple SQL Injection Vulnerabilities
  • phpXplorer 0.9.33 Action.PHP Directory Traversal Vulnerability
  • RedKernel 1.1.0-3 Referrer Tracker Rkrt_stats.PHP Cross-Site Scripting Vulnerability
  • PHPDocumentor 1.3RC4 Forum Lib Variable Cross-Site Scripting Vulnerability
  • Kayako SupportSuite 3.0.26 Multiple Cross-Site Scripting Vulnerabilities
  • OOApp Guestbook Home Script 2.1 Cross-Site Scripting Vulnerability
  • Ades Design AdesGuestbook 2.0 Read Script Cross-Site Scripting Vulnerability
  • Web Wiz 3.0.6 Multiple Products SQL Injection Vulnerability
  • Jevontech PHPenpals 310704 PersonalID SQL Injection Vulnerability
  • GMailSite 1.0.4 Cross-Site Scripting Vulnerability
  • PHPDocumentor 1.3RC4 Remote and Local File Include Vulnerabilities
  • VEGO Web Forum 1.26 Theme_ID SQL Injection Vulnerability
  • FatWire UpdateEngine 6.2 Multiple Cross-Site Scripting Vulnerabilities
  • PaperThin 4.5 CommonSpot Content Server Cross-Site Scripting Vulnerability
  • Tangora Portal CMS 4.0 Action Parameter Cross-Site Scripting Vulnerability
  • SyntaxCMS 1.2.1 Search Query Cross-Site Scripting Vulnerability
  • Quantum Art QP7.Enterprise Multiple SQL Injection Vulnerabilities

N-Stealth DB General Information
Version: 177
Release Date: 07/11/2006

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.