IBM Lotus Notes vulnerabilities and new updates
N-Stalker has made available the latest database update for its Web Application Security Assessment Products. Following the support life-cycle, we are still distributing updates for previous version.
You will be able to download it automatically in the following versions:
- N-Stalker Web Application Security Scanner 2006 (Enterprise, QA and Infrastructure Edition)
- WSI Update (N-Stalker Update Manager)
- N-Stealth HTTP Security Scanner (database update 178)
- Automatic DB Update
You should be able to receive it automatically next time you execute the scanner.
If you prefer to download it manually, please, use the following url: https://customer.nstalker.com.
If you need any additional assistance during this process, please, contact us at:
Web: Open new support ticket at https://customer.nstalker.com
E-mail: support@nstalker.com (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)
This release has included the following vulnerabilities:
- Siteframe Beaumont 5.0.1 Search.PHP Q Parameter Cross-Site Scripting Vulnerability
- IBM Lotus Domino iNotes 6.5.4 Multiple HTML and Script Injection Vulnerabilities
- DataparkSearch Engine Search 4.36 Template Cross-Site Scripting Vulnerability
- GA’s Forum Light Archive.ASP SQL Injection Vulnerability
- AshWebStudio AshNews 0.83 Remote File Include Vulnerability
- My Amazon Store Manager 1.0 Search.PHP Cross-Site Scripting Vulnerability
- My Little Homepage Products 2004.4.20 BBCode Link Tag Script Injection Vulnerability
- Papoo 2.1.2 Multiple Cross-Site Scripting Vulnerabilities
- Indexu 5.0.1 Application.PHP Remote File Include Vulnerability
- SPIP 1.9 Multiple SQL Injection Vulnerabilities
- PmWiki 2.1 Multiple Input Validation Vulnerabilities
- Phpclanwebsite 1.23.1 Multiple Input Validation Vulnerabilities
- FarsiNews 2.1 Loginout.PHP Remote File Include Vulnerability
- Rockliffe MailSite HTTP Mail Management 7.0.3 Agent Denial Of Service Vulnerability
- Eggblog 2.0 Multiple Input Validation Vulnerabilities
- WeBWorK 2.1.3 Remote Arbitrary Command Execution Vulnerability
- Apache mod_auth_pgsql 2.0.2 Multiple Format String Vulnerabilities
- Hitachi HITSENSER Data Mart Server Unspecified SQL Injection Vulnerabilities
- BrowserCRM Results.PHP Cross-Site Scripting Vulnerability
- CyberShop Ultimate E-commerce Multiple Cross-Site Scripting Vulnerabilities
- UebiMiau 2.7.9 HTML Email HTML Injection Vulnerability
- WebspotBlogging 3.0 Login.PHP SQL Injection Vulnerability
- MyBB 1.2 Index.PHP Referrer Cookie SQL Injection Vulnerability
- BlogPHP 1.2 Multiple SQL Injection Vulnerabilities
- PHlyMail 3.0.2 Multiple Input Validation Vulnerabilities
- MyBB UserCP2.PHP Referer Header HTML Injection Vulnerability
- ASPThai Forums 8.0 Login.ASP SQL Injection Vulnerability
- PHP 5 User-Supplied Session ID Input Validation Vulnerability
- miniBloggie 1.0 Login.PHP SQL Injection Vulnerability
- Daffodil CRM 8.0 Userlogin.ASP SQL Injection Vulnerability
- Community Server Multiple Cross-Site Scripting Vulnerabilities
- Netrix X-Site Manager product_details.php product_id Variable XSS
- PMachine ExpressionEngine 1.4.1 HTTP Referrer HTML Injection Vulnerability