Verisign MPKI vulnerabilities and new updates
N-Stalker has made available the latest database update for its Web Application Security Assessment Products. Following the support life-cycle, we are still distributing updates for previous version.
You will be able to download it automatically in the following versions:
- N-Stalker Web Application Security Scanner 2006 (Enterprise, QA and Infrastructure Edition)
- WSI Update (N-Stalker Update Manager)
- N-Stealth HTTP Security Scanner (database update 182)
- Automatic DB Update
You should be able to receive it automatically next time you execute the scanner.
If you prefer to download it manually, please, use the following url: https://customer.nstalker.com.
If you need any additional assistance during this process, please, contact us at:
Web: Open new support ticket at https://customer.nstalker.com
E-mail: http://www.nstalker.com/about/contact (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)
This release has included the following vulnerabilities:
- PHP Live! 3.0 Status_Image.PHP Cross-Site Scripting Vulnerability
- ASP Portal 3.1.1 Multiple SQL Injection Vulnerabilities
- F5 Firepass 4100 SSL VPN 5.4.2 Cross-Site Scripting Vulnerability
- Verisign MPKI 6.0 Haydn.EXE Cross-Site Scripting Vulnerability
- Noah’s Classifieds 1.3 Index.PHP Multiple Cross-Site Scripting Vulnerabilities
- BetaParticle Blog 6.0 Multiple SQL Injection Vulnerabilities
- Woltlab Burning Board 2.3.4 Class_DB_MySQL.PHP Cross-Site Scripting Vulnerability
- ExtCalendar 1.0 Cross-Site Scripting Vulnerabilities
- Invision Power Board 2.0.4 Multiple Cross-Site Scripting Vulnerabilities
- PHPMyAdmin 2.8.1 Set_Theme Cross-Site Scripting Vulnerability
- Oxynews Index.PHP SQL Injection Vulnerability
- CyBoards PHP Lite 1.25 Post.PHP SQL Injection Vulnerability
- MyBB 1.0.4 Multiple Input Validation Vulnerabilities
- Vegas Forum 1.0 Forumlib.PHP SQL Injection Vulnerability
- WMNews Multiple Cross-Site Scripting Vulnerabilities
- DirectContact 0.3b Directory Traversal Vulnerability
- vCard 2.9 Create.PHP Multiple Cross-Site Scripting Vulnerabilities
- GuppY 4.5.11 Dwnld.PHP Remote Directory Traversal Vulnerability
- Nodez 4.6.1 Multiple Input Validation Vulnerabilities
- QwikiWiki 1.5 Multiple Cross-Site Scripting Vulnerabilities
- txtForum 1.0.4 Remote PHP Script Code Injection Vulnerability
- txtForum 1.0.4 Multiple Cross-Site Scripting Vulnerabilities
- DCP Portal 6.1.1 Multiple Cross-Site Scripting Vulnerabilities
- MyBloggie 2.1.3 Multiple Cross-Site Scripting Vulnerabilities
- sBlog 0.7.2 HTML Injection Vulnerabilities
- Daverave HitHost 1.0 Multiple Cross-Site Scripting Vulnerabilities
- Woltlab Burning Board 2.3.4 Misc.PHP Cross-Site Scripting Vulnerability