Apache ModPython vulnerabilities and new updates

By N-Stalker Team on October 9, 2006

N-Stalker has made available the latest database update for its Web Application Security Assessment Products. Following the support life-cycle, we are still distributing updates for previous version.

You will be able to download it automatically in the following versions:

  • N-Stalker Web Application Security Scanner 2006 (Enterprise, QA and Infrastructure Edition)
    • WSI Update (N-Stalker Update Manager)
  • N-Stealth HTTP Security Scanner (database update 180)
    • Automatic DB Update

You should be able to receive it automatically next time you execute the scanner.

If you prefer to download it manually, please, use the following url: https://customer.nstalker.com.

If you need any additional assistance during this process, please, contact us at:
Web: Open new support ticket at https://customer.nstalker.com
E-mail: http://www.nstalker.com/about/contact (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

  • TextfileBB 1.0 Multiple Cross-Site Scripting Vulnerabilities
  • AZ Bulletin Board 1.1 Post.PHP HTML Injection Vulnerabilities
  • Loudblog 0.41 Multiple Input Validation Vulnerabilities
  • Link Bank Iframe.PHP Cross-Site Scripting Vulnerability
  • Game-Panel 2.6.1 Login.PHP Cross-Site Scripting Vulnerability
  • Acme Labs thttpd 2.24 HTPasswd Multiple Vulnerabilities
  • TotalECommerce 1.0 SQL Injection Vulnerability
  • phpArcadeScript 2.0 Multiple Cross-Site Scripting Vulnerabilities
  • VBZooM 1.11 Forum Multiple Cross-Site Scripting Vulnerabilities
  • MyBBoard 1.0.3 Multiple Input Validation Vulnerabilities
  • NZ Ecommerce Multiple Input Validation Vulnerabilities
  • LogIT 1.4 Remote File Include Vulnerability
  • Apache mod_python 3.2.7 FileSession Code Execution Vulnerability
  • DCI-Designs Dawaween 1.03 Poems.PHP SQL Injection Vulnerability
  • Noah’s Classifieds 1.3 Local File Include Vulnerability
  • Noah’s Classifieds 1.3 Index.PHP Remote File Include Vulnerability
  • MyPHPNuke 1.8.8 Multiple Cross-Site Scripting Vulnerabilities
  • NetworkActiv Web Server 3.5.15 Remote Script Disclosure Vulnerability
  • Lighttpd 1.4.10 Remote Script Disclosure Vulnerability
  • PEHEPE Membership Management System v3 Remote PHP Script Code Injection Vulnerability
  • PEHEPE Membership Management System v3 Sol_menu.PHP Cross-Site Scripting Vulnerability
  • EJ3 TOPo 2.2.178 Inc_header.PHP Cross-Site Scripting Vulnerability
  • QwikiWiki 1.4 Index.PHP Cross-Site Scripting Vulnerability
  • Fantastic Scripts 2.1.1 Fantastic ID Parameter SQL Injection Vulnerability
  • FarsiNews 2.5 Directory Traversal and Local File Include Vulnerabilities
  • N8CMS 1.2 Multiple Input Validation Vulnerabilities
  • D3Jeeb Pro3 Multiple SQL Injection Vulnerabilities
  • Woltlab Burning Board 2.7 Multiple SQL Injection Vulnerabilities
  • Woltlab Burning Board 2.7 Multiple Cross-Site Scripting Vulnerabilities
  • Thomson SpeedTouch 500 Series 5.3.2.6.0 Cross-Site Scripting Vulnerability
  • Fantastic Scripts Fantastic News 2.1.1 SQL Injection Vulnerability
  • Lansuite Board 2.1.0 Module SQL Injection Vulnerability
  • PwsPHP 1.2.3 Index.PHP SQL Injection Vulnerability
  • PHP-Nuke 7.8 Mainfile.PHP SQL Injection Vulnerability
  • iGenus WebMail 2.0.2 Config_Inc.PHP Remote File Include Vulnerability
  • DCI-Taskeen 1.03 Multiple SQL Injection Vulnerabilities
  • PHPWebSite 0.10.2 Topics.PHP SQL Injection Vulnerability
  • SPiD 1.3.1 Scan_Lang_Insert.PHP Local File Include Vulnerability
  • Battleaxe Software BttlxeForum 2.0 Failure.ASP Cross-Site Scripting Vulnerability

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.