vBulletin vulnerabilities and new updates

By N-Stalker Team on December 1, 2006

N-Stalker has made available the latest database update for its Web Application Security Assessment Products. Following the support life-cycle, we are still distributing updates for previous version.

You will be able to download it automatically in the following versions:

  • N-Stalker Web Application Security Scanner 2006 (Enterprise, QA and Infrastructure Edition)
    • WSI Update (N-Stalker Update Manager)
  • N-Stealth HTTP Security Scanner (database update 186)
    • Automatic DB Update

You should be able to receive it automatically next time you execute the scanner.

If you prefer to download it manually, please, use the following url: https://customer.nstalker.com.

If you need any additional assistance during this process, please, contact us at:
Web: Open new support ticket at https://customer.nstalker.com
E-mail: http://www.nstalker.com/about/contact (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

  • Photoalbum B&W 1.3 Index.PHP Cross-Site Scripting Vulnerability
  • CoolPHP 0 Index.PHP Cross-Site Scripting Vulnerability
  • Epic Designs 3.06 Eggblog Posts.PHP SQL Injection Vulnerability
  • vCard 2.9 Multiple Cross-Site Scripting Vulnerabilities
  • Chipmunk Directory Index.PHP Cross-Site Scripting Vulnerability
  • AR-Blog 5.2 Multiple Cross-Site Scripting Vulnerabilities
  • Jax Guestbook 3.50 Page Parameter Cross-Site Scripting Vulnerability
  • NewsPortal 0.36 Remote PHP Script Code Injection Vulnerability
  • AWeb’s Banner Generator 3.0 Cross-Site Scripting Vulnerability
  • Cherokee 0.5 Webserver Cross-Site Scripting Vulnerability
  • vBulletin 3.5.1 Vbugs.PHP Cross-Site Scripting Vulnerability
  • Jupiter CMS 1.1.5 Index.PHP Cross-Site Scripting Vulnerability
  • Basic Analysis and Security Engine 1.2.4 PrintFreshPage Cross-Site Scripting Vulnerability
  • wpBlog 0.4 Index.PHP SQL Injection Vulnerability
  • Limbo CMS 1.0.4.2 Frontpage Arbitrary PHP Command Execution Vulnerability
  • REMLAB Web Mech Designer 2.0.5 Path Disclosure Vulnerability
  • XN–Gol-kma 2005-Comments-Script 0 Komentare.PHP Multiple Cross-Site Scripting Vulnerabilities
  • Monkey Boards version 0.3.5 Multiple Path Disclosure Vulnerabilities
  • Creative Community Portal 1.1 Multiple SQL Injection Vulnerabilities
  • VP-ASP 6.08 Shopping Cart Shopcurrency.ASP SQL Injection Vulnerability
  • Claroline 1.7.4 Rqmkhtml.PHP Information Disclosure Vulnerability
  • Claroline 1.7.4 RQMKHTML.PHP Cross-Site Scripting Vulnerability
  • Collaborative Portal Server 3.4 POS Parameter Cross-Site Scripting Vulnerability
  • MKPortal 1.1 RC1Multiple Input Validation Vulnerabilities
  • OpenPHPnuke 2.3.3 Remote File Include Vulnerability
  • SK Soft SKForum 1.4.1 Multiple Cross-Site Scripting Vulnerabilities
  • ArabPortal 2.0.1 Multiple Input Validation Vulnerabilities
  • AngelineCMS 0.8.1 Loadkernel.PHP Remote File Include Vulnerability
  • LucidCMS 2.0.0 RC4 Index.PHP Multiple Cross-Site Scripting Vulnerabilities
  • WebAPP 0.9.9.3.2 Multiple Cross-Site Scripting Vulnerabilities

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.