Cisco Vulnerabilities and Special Holiday Database Update

By N-Stalker Team on December 28, 2006

N-Stalker has made available the latest database update for its Web Application Security Assessment Products. Following the support life-cycle, we are still distributing updates for previous version.

You will be able to download it automatically in the following versions:

  • N-Stalker Web Application Security Scanner 2006 (Enterprise, QA and Infrastructure Edition)
    • WSI Update (N-Stalker Update Manager)
  • N-Stealth HTTP Security Scanner (database update 187)
    • Automatic DB Update

You should be able to receive it automatically next time you execute the scanner.

If you prefer to download it manually, please, use the following url: https://customer.nstalker.com.

If you need any additional assistance during this process, please, contact us at:
Web: Open new support ticket at https://customer.nstalker.com
E-mail: http://www.nstalker.com/about/contact (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

  • Cisco CallManager 4.1 Cross-Site Scripting Vulnerability
  • Cisco Secure ACS 2.3 LoginProxy.CGI Cross-Site Scripting Vulnerability
  • BandSite 1.1.1 Root_Path Remote File Include Vulnerability
  • Clubpage Multiple Input Validation Vulnerabilities
  • vBulletin 3.0.10 Portal.PHP SQL Injection Vulnerability
  • BtitTracker 1.3.2 Torrents.PHP SQL Injection Vulnerabilities
  • MAXDEV 1.0.73 CMS PNuserapi.PHP SQL Injection Vulnerability
  • NC Linklist 1.2 Index.PHP Cross-Site Scripting Vulnerabilities
  • Open-Realty 3.2.1 Search.inc.PHP SQL Injection Vulnerability
  • AssoCIateD 1.2 Index.PHP Cross-Site Scripting Vulnerability
  • PHPMyDirectory 10.4.5 Multiple Cross-Site Scripting Vulnerabilities
  • PHPMyForum 4.1.3 Topic.php Cross-Site Scripting Vulnerability
  • Micro CMS 0.3.5 MicroCMS-include.PHP Remote File Include Vulnerability
  • Arctic 1.0.2 Index.PHP Cross-Site Scripting Vulnerability
  • Simple File Manager 0.24a FM.php Cross-Site Scripting Vulnerability
  • Sharky E-Shop 3.05 Meny2.ASP Cross-Site Scripting Vulnerability
  • Sharky E-Shop 3.05 Search_Prod_List.ASP Cross-Site Scripting Vulnerability
  • The Edge eCommerce Shop ProductDetail.ASP Cross-Site Scripting Vulnerability
  • DPVision Tradingeye Shop R4 Details.CFM Cross-Site Scripting Vulnerability
  • TPL Design TplShop 2.0 Category.PHP SQL Injection Vulnerability
  • SWSoft Confixx 3.0 Pro Tools_Ftp_Pwaendern.PHP Cross-Site Scripting Vulnerability
  • Xarancms 2.0 Xarancms_haupt.PHP SQL Injection Vulnerability
  • Singapore 0.10 Gallery Index.PHP Cross-Site Scripting Vulnerabilities
  • ASP Stats Generator 2.1.1 Pages.ASP SQL Injection Vulnerability
  • Qto File Manager 1.0 index.php Cross-Site Scripting Vulnerability
  • PHP Live Helper 2.0 Initiate.PHP Remote File Include Vulnerability
  • e107 0.75 Search.PHP Cross-Site Scripting Vulnerability
  • Datecomm 1.1 Multiple Cross-Site Scripting Vulnerabilities
  • AxentForum II viewposts.cfm Cross-Site Scripting Vulnerability
  • DreamAccount 3.1 Multiple Remote File Include Vulnerabilities
  • PHP Labware LabWiki 1.0 Recentchanges.PHP Cross-Site Scripting Vulnerability
  • Unak CMS 1.5 RC1 Multiple Input Validation Vulnerabilities
  • myNewsletter 1.1.2 UserName SQL Injection Vulnerability
  • IShopCart Easy-Scart.CGI Directory Traversal Vulnerability
  • ToendaCMS 0.7 Content_footer.PHP Cross-Site Scripting Vulnerability
  • CMS Faethon 1.3.2 Multiple Remote File Include Vulnerabilities
  • Bible Portal 2.12 Rtf_parser.PHP Remote File Include Vulnerability
  • VBZoom 1.11 Multiple SQL Injection Vulnerabilities
  • SixCMS 6.0 List.PHP Cross-Site Scripting Vulnerability
  • SixCMS 6.0 Detail.PHP Directory Traversal Vulnerability
  • Cline Communications Multiple SQL Injection Vulnerabilities
  • DotWidget For Articles 2.0 Multiple Remote File Include Vulnerabilities
  • RahnemaCo Page.PHP PageID Remote File Include Vulnerability
  • Indexu 5.0.1 Multiple Remote File Include Vulnerabilities
  • MCGuestbook 1.3 Multiple Remote File Include Vulnerabilities
  • Ji-takz Remote File Include Vulnerability
  • Nucleus CMS 3.22 Multiple Remote File Include Vulnerabilities
  • SaPHPLesson 2.0 Show.PHP SQL Injection Vulnerability
  • VBZoom 1.11 Forum.php SQL Injection Vulnerability
  • PictureDis 1.33 Remote File Include Vulnerabilities
  • Chipmailer 1.09 Login Page SQL Injection Vulnerability
  • IntegraMOD 2.0 rc2 Index.PHP Cross-Site Scripting Vulnerability
  • Calendarix 0.7.20060401 Basic ID Parameter Multiple SQL Injection Vulnerabilities
  • Flipper Poll 1.1 Poll.PHP Remote File Include Vulnerability
  • ISPConfig 2.2.3 Session.INC.PHP Remote File Include Vulnerability
  • Vacation Rental Script 1.0 Index.PHP Cross-Site Scripting Vulnerability
  • HotPlug CMS 1.0 Login1.PHP Cross-Site Scripting Vulnerability
  • SSPwiz 1.0.7 Plus Cross-Site Scripting Vulnerability
  • Wikkawiki 1.1.6.1 Wakka.PHP Cross-Site Scripting Vulnerability
  • APBoard 2.2-r3 SQL Injection Vulnerabilities
  • phpBannerExchange 2.0 RC5 Multiple SQL Injection Vulnerabilities
  • ListPics 4.3 Cross-site Scripting Vulnerability
  • PhpBlueDragon CMS 2.9.1 Template.PHP Remote File Include Vulnerability
  • PhpBB BBRSS.PHP Remote File Include Vulnerability
  • RahnemaCo Page.PHP Remote File Include Vulnerability
  • Confixx 3.1.2 FTP_index.PHP Cross-Site Scripting Vulnerability
  • CzarNews 1.14 Headlines.PHP Remote File Include Vulnerability
  • 35mmslidegallery V6 Multiple Cross-Site Scripting Vulnerabilities
  • G-Shout 1.3.1 Shoutbox.PHP Remote File Include Vulnerability
  • Simpnews 2.13 Wap_short_news.PHP Remote File Include Vulnerability
  • iFusion iFlance 1.1 Multiple Input Validation Vulnerabilities
  • BoastMachine 3.1 Vote.PHP Remote File Include Vulnerability
  • aWebNews 1.0 Visview.PHP Remote File Include Vulnerability
  • VBZoom 1.11 Multiple SQL Injection Vulnerabilities
  • Particle Whois 1.0.3 Multiple Input Validation Vulnerabilities
  • DCP-Portal 6.1 Lib.PHP Remote File Include Vulnerability
  • Ottoman 1.1.2 Multiple Remote File Include Vulnerabilities
  • Foing 0.7 Remote File Include Vulnerability
  • iFoto 0.20 Index.PHP Cross-Site Scripting Vulnerability
  • Adaptive Website Framework 1.11 Remote File Include Vulnerability
  • NPDS 5.10 Multiple Input Validation Vulnerabilities
  • WebprojectDB 0.1.3 Multiple Remote File Include Vulnerabilities
  • KAPhotoservice 7.5 Multiple Cross-Site Scripting Vulnerabilities
  • Free QBoard 1.1 Post.PHP Remote File Include Vulnerability
  • Open Business Management 1.0.3 pl1 Multiple Cross-Site Scripting Vulnerabilities
  • Empris 20020923 Remote File Include Vulnerability
  • LoveCompass AEPartner 0.8.3 Remote File Include Vulnerability
  • ViArt Shop 2.5.5 Multiple Cross-Site Scripting Vulnerabilities
  • Enterprise Payroll Systems 1.1 AbsolutePath Remote File Include Vulnerability
  • Open Business Management 1.0.3 pl1 SQL Injection Vulnerabilities
  • Joomla 1.0 IncludePath Remote File Include Vulnerability
  • Ringlink 3.2 Multiple Cross-Site Scripting Vulnerabilities
  • Mafia Moblog 6 Big.PHP SQL Injection Vulnerability
  • Baby Katie Media VSReal and VScal 1.0 Multiple Cross-Site Scripting Vulnerabilities
  • SelectaPix 1.31 Multiple Input Validation Vulnerabilities
  • Particle Links 1.2.2 SQL Injection Vulnerability
  • ScriptsEZ Ez Ringtone Manager Player.PHP Cross-Site Scripting Vulnerability
  • ScriptsEZ Chemical Dictionary Dictionary.PHP Cross-Site Scripting Vulnerability
  • TikiWiki 1.9.3.1 Multiple Cross-Site Scripting Vulnerabilities
  • ScriptsEZ E-Dating System Multiple Input Validation Vulnerabilities
  • KnowledgeTree Open Source 3.0.3 Cross-site Scripting Vulnerability
  • Vice Stats 0.5b VS_Resource.PHP SQL Injection Vulnerability
  • Calendar Express 2.2 Month.PHP SQL Injection Vulnerability
  • AZ Photo Album Script Pro Cross-Site Scripting Vulnerability
  • TinyPHPForum 3.6 Profile.PHP Local File Include Vulnerability
  • MyBulletinBoard 1.1.2 Private.PHP Cross-Site Scripting Vulnerability
  • Tiny Web Gallery 1.4 Index.PHP Cross-Site Scripting Vulnerability
  • GANTTy 1.0.3 Index.PHP Cross-Site Scripting Vulnerability
  • Alex DownloadEngine 1.4.1 Comments.PHP SQL Injection Vulnerability
  • Wikiwig 4.1 WK_lang.PHP Remote File Include Vulnerability
  • Alex NewsEngine 1.5 Newscomments.PHP SQL Injection Vulnerability
  • DreamCost HostAdmin 3.1 Multiple Remote File Include Vulnerabilities
  • Bookmark4U 2.0 Multiple Remote File Include Vulnerabilities
  • Kmita FAQ 1.0 Multiple Input Validation Vulnerabilities
  • Pixelpost 1.5rc1-2 Multiple SQL Injection Vulnerabilities
  • CyBoards PHP Lite 1.25 Common.PHP Remote File Include Vulnerability
  • Particle Gallery 1.0 Viewimage.PHP SQL Injection Vulnerability
  • CoolForum 0.8.3 Editpost.PHP SQL Injection Vulnerabilit
  • CS-Cart 1.3.3 Class.cs_phpmailer.PHP Remote File Include Vulnerability
  • XUEBook 1.0 Index.PHP SQL Injection Vulnerability
  • DotWidget CMS 1.0.6 Multiple Remote File Include Vulnerabilities
  • IBWd Guestbook 1.0 Index.PHP SQL Injection Vulnerability
  • PHPBB 2.0.20 Template.PHP Remote File Include Vulnerability
  • Igloo 0.1.9 Remote File Include Vulnerability
  • Informium 0.12 Remote File Include Vulnerability
  • Ashwebstudio Ashnews 0.83 Multiple Remote File Include Vulnerabilities
  • PHP ManualMaker 1.0 Multiple Input Validation Vulnerabilities
  • PHP Labware LabWiki 1.0 Search.PHP Cross-Site Scripting Vulnerability
  • Dmx Forum 2.1a Edit.PHP SQL Injection Vulnerability
  • DeltaScripts PHP Pro Publish 2.0 Multiple Cross-Site Scripting Vulnerabilities
  • aspWebLinks 2.0 Links.ASP SQL Injection Vulnerability
  • ByteHoard 2.1 Epsilon Server.PHP Remote File Include Vulnerability
  • Ovidentia 5.8 Multiple Remote File Include Vulnerabilities
  • Enigma Haber 4.2 Cross-Site Scripting Vulnerability
  • AssoCIateD 1.1.3 Multiple Remote File Include Vulnerabilities
  • Abarcar Realty Portal 5.1.5 Content.PHP SQL Injection Vulnerability
  • Tekno.Portal Bolum.PHP SQL Injection Vulnerability
  • LocazoList Classifieds 1.04d Viewmsg.ASP SQL Injection Vulnerability
  • Portix-PHP 2-0.3.2 Portal Multiple Cross-Site Scripting Vulnerabilities
  • ASPNuke 0.80 Article.ASP SQL Injection Vulnerability
  • SelectaPix 1.4 View_album.PHP SQL Injection Vulnerability
  • PHPBB 2.0.19 Profile.PHP Cross-Site Scripting Vulnerability
  • QLnews 1.2 Multiple Input Validation Vulnerabilities
  • Mon Album 0.8.7 Multiple SQL Injection Vulnerabilities
  • xFlow 5.46.11 Multiple Input Validation Vulnerabilities
  • Fuju News 1.0 SQL Injection and Authentication Bypass Vulnerabilities
  • Asterisk Recording Interface 0.7.15 Audio.PHP Information Disclosure Vulnerability
  • Manic Web MWGuest 2.1 MWguest.PHP HTML Injection Vulnerability
  • Portal Pack 6.0 Multiple Cross-Site Scripting Vulnerabilities
  • MyBB 1.1 Global Variable Overwrite Vulnerability
  • Manila 9.0.1 Multiple Cross-Site Scripting Vulnerabilities
  • DbbS 2.0-alpha Multiple Input Validation Vulnerabilities
  • Microsoft FrontPage Server Extensions Cross-Site Scripting Vulnerability
  • Indexu 5.0.1 Multiple Remote File Include Vulnerabilities
  • Blursoft Blur6ex 0.3.462 Multiple Input Validation Vulnerabilities
  • PHPMyAdmin 2.7 SQL.PHP Cross-Site Scripting Vulnerability
  • AWebBB 1.2 Multiple Input Validation Vulnerabilities
  • JetPhoto 2.1 Multiple Cross-Site Scripting Vulnerabilities
  • Yukihiro Matsumoto Ruby 1.8.5-P1 CGI Module MIME Denial Of Service Vulnerability

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.