Verisign MPKI vulnerabilities and new updates

By N-Stalker Team on October 16, 2006

N-Stalker has made available the latest database update for its Web Application Security Assessment Products. Following the support life-cycle, we are still distributing updates for previous version.

You will be able to download it automatically in the following versions:

  • N-Stalker Web Application Security Scanner 2006 (Enterprise, QA and Infrastructure Edition)
    • WSI Update (N-Stalker Update Manager)
  • N-Stealth HTTP Security Scanner (database update 182)
    • Automatic DB Update

You should be able to receive it automatically next time you execute the scanner.

If you prefer to download it manually, please, use the following url: https://customer.nstalker.com.

If you need any additional assistance during this process, please, contact us at:
Web: Open new support ticket at https://customer.nstalker.com
E-mail: http://www.nstalker.com/about/contact (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

  • PHP Live! 3.0 Status_Image.PHP Cross-Site Scripting Vulnerability
  • ASP Portal 3.1.1 Multiple SQL Injection Vulnerabilities
  • F5 Firepass 4100 SSL VPN 5.4.2 Cross-Site Scripting Vulnerability
  • Verisign MPKI 6.0 Haydn.EXE Cross-Site Scripting Vulnerability
  • Noah’s Classifieds 1.3 Index.PHP Multiple Cross-Site Scripting Vulnerabilities
  • BetaParticle Blog 6.0 Multiple SQL Injection Vulnerabilities
  • Woltlab Burning Board 2.3.4 Class_DB_MySQL.PHP Cross-Site Scripting Vulnerability
  • ExtCalendar 1.0 Cross-Site Scripting Vulnerabilities
  • Invision Power Board 2.0.4 Multiple Cross-Site Scripting Vulnerabilities
  • PHPMyAdmin 2.8.1 Set_Theme Cross-Site Scripting Vulnerability
  • Oxynews Index.PHP SQL Injection Vulnerability
  • CyBoards PHP Lite 1.25 Post.PHP SQL Injection Vulnerability
  • MyBB 1.0.4 Multiple Input Validation Vulnerabilities
  • Vegas Forum 1.0 Forumlib.PHP SQL Injection Vulnerability
  • WMNews Multiple Cross-Site Scripting Vulnerabilities
  • DirectContact 0.3b Directory Traversal Vulnerability
  • vCard 2.9 Create.PHP Multiple Cross-Site Scripting Vulnerabilities
  • GuppY 4.5.11 Dwnld.PHP Remote Directory Traversal Vulnerability
  • Nodez 4.6.1 Multiple Input Validation Vulnerabilities
  • QwikiWiki 1.5 Multiple Cross-Site Scripting Vulnerabilities
  • txtForum 1.0.4 Remote PHP Script Code Injection Vulnerability
  • txtForum 1.0.4 Multiple Cross-Site Scripting Vulnerabilities
  • DCP Portal 6.1.1 Multiple Cross-Site Scripting Vulnerabilities
  • MyBloggie 2.1.3 Multiple Cross-Site Scripting Vulnerabilities
  • sBlog 0.7.2 HTML Injection Vulnerabilities
  • Daverave HitHost 1.0 Multiple Cross-Site Scripting Vulnerabilities
  • Woltlab Burning Board 2.3.4 Misc.PHP Cross-Site Scripting Vulnerability

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.