Xerox Workcentre vulnerability and new updates
N-Stalker has made available the latest database update for its Web Application Security Assessment Products. Following the support life-cycle, we are still distributing updates for previous version.
You will be able to download it automatically in the following versions:
- N-Stalker Web Application Security Scanner 2006 (Enterprise, QA and Infrastructure Edition)
- WSI Update (N-Stalker Update Manager)
- N-Stealth HTTP Security Scanner (database update 180)
- Automatic DB Update
You should be able to receive it automatically next time you execute the scanner.
If you prefer to download it manually, please, use the following url: https://customer.nstalker.com.
If you need any additional assistance during this process, please, contact us at:
Web: Open new support ticket at https://customer.nstalker.com
E-mail: http://www.nstalker.com/about/contact (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)
This release has included the following vulnerabilities:
- freeForum 1.2 Remote PHP Script Code Injection Vulnerability
- Mambo Open Source 4.5.3 Multiple SQL Injection Vulnerabilities
- Webpagecity WPC easy SQL Injection Vulnerability
- Gastebuch 1.3.2 Cross-Site Scripting Vulnerability
- RCBlog 1.0.3 Index.PHP Directory Traversal Vulnerability
- Coppermine 1.4.3 Multiple File Include Vulnerabilities
- Xerox WorkCentre Products Pro 275 HTML Injection Vulnerability
- MiniNuke CMS 1.8.2 Pages.ASP SQL Injection Vulnerability
- Admbook 1.2.2 Remote PHP Script Code Execution Vulnerability
- Magic Calendar Lite 1.02 Index.PHP SQL Injection Vulnerability
- Oi! Email Marketing System 3.0 Index.PHP SQL Injection Vulnerability
- IlchClan 1.0.5 Multiple SQL Injection Vulnerabilities
- BirthSys 3.1 Multiple SQL Injection Vulnerabilities
- RunCMS 1.2 Ratefile.PHP Cross-Site Scripting Vulnerability
- Web Calendar Pro Dropbase.PHP SQL Injection Vulnerability
- CubeCart 3.0.7 Arbitrary File Upload Vulnerability
- JGS-Gallery 4.0 Module Multiple Cross-Site Scripting Vulnerabilities
- Pentacle In-Out Board 6.03 Multiple SQL Injection Vulnerabilities