PHPBB vulnerabilities and new updates

By N-Stalker Team on April 15, 2007

N-Stalker has made available the latest database update for its Web Application Security Assessment Products. Following the support life-cycle, we are still distributing updates for previous version.

You will be able to download it automatically in the following versions:

  • N-Stalker Web Application Security Scanner 2006 (Enterprise, QA and Infrastructure Edition)
    • WSI Update (N-Stalker Update Manager)
  • N-Stealth HTTP Security Scanner (not updated)

You should be able to receive it automatically next time you execute the scanner.

If you prefer to download it manually, please, use the following url: https://customer.nstalker.com.

If you need any additional assistance during this process, please, contact us at:
Web: Open new support ticket at https://customer.nstalker.com
E-mail: http://www.nstalker.com/about/contact (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

  • E-Uploader Pro 1.0 Config.PHP Remote File Include Vulnerability
  • Zenphoto 1.0.2 Index.PHP Cross-Site Scripting Vulnerability
  • PHP News Reader 2.6.4 Phpbb.inc.PHP Remote File Include Vulnerability
  • Minichat 6.0 FTag.PHP Remote File Include Vulnerability
  • PHPList 2.10.2 Index.PHP Local File Include Vulnerability
  • ExtCalThai 0.9.1 Mambo Component Extcalendar.PHP Remote File Include Vulnerability
  • ExtCalThai 0.9.1 Mambo Component Mail.Inc.PHP Remote File Include Vulnerability
  • ExtCalThai 0.9.1 Mambo Component Admin_Events.PHP Remote File Include Vulnerability
  • BerliOS Security Suite 1.0 PHPBB_Root_Path Remote File Include Vulnerability
  • PHPBB Admin User Viewed Posts Tracker 1.0 Module Remote File Include Vulnerability
  • PHP TopSites 1.022 Config.PHP Remote File Include Vulnerability
  • Journals System PhpBB 1.0.2 Journals_Delete.PHP Remote File Include Vulnerability
  • Journals System PhpBB 1.0.2 Journals_Post.PHP Remote File Include Vulnerability
  • Journals System PhpBB 1.0.2 Journals_Edit.PHP Remote File Include Vulnerability
  • Alex DownloadEngine 1.4.2 Spaw_Root Remote File Include Vulnerability
  • PHPHT Topsites Common.PHP Remote File Include Vulnerability
  • MiniBB Keyword Replacer 1.0 Plugin Remote File Include Vulnerability
  • Insert User PHPBB 0.1.2 PHPBB_Root_Path Remote File Include Vulnerability
  • Redaction System 1.0 Wap/Conn.PHP Remote File Include Vulnerability
  • Redaction System 1.0 Sesscheck.PHP Remote File Include Vulnerability
  • Redaction System 1.0 Index.PHP Remote File Include Vulnerability
  • Redaction System 1.0 Conn.PHP Remote File Include Vulnerability
  • Redaction System 1.0 Wap/Sesscheck.PHP Remote File Include Vulnerability
  • ExtCalendar 2.0 ExtCalendar.PHP Remote File Include Vulnerability
  • SquirrelMail 1.5.1 Search.PHP Cross-Site Scripting Vulnerability
  • LBlog 1.05 Comments.ASP SQL Injection Vulnerability
  • Maluinfo 206.2.381 PHPBB_Root_Path Parameter Remote File Include Vulnerability
  • Afgb Guestbook 2.2 Look.PHP Remote File Include Vulnerability
  • Afgb Guestbook 2.2 Admin.PHP Remote File Include Vulnerability
  • Afgb Guestbook 2.2 Add.PHP Remote File Include Vulnerability
  • Afgb Guestbook 2.2 Re.PHP Remote File Include Vulnerability
  • Genepi 1.6 Genepi.PHP Remote File Include Vulnerability
  • SpamOborona Admin_Spam.PHP Remote File Include Vulnerability
  • Bloq 0.5.4 Admin.PHP Remote File Include Vulnerability
  • Bloq 0.5.4 Rss.PHP Remote File Include Vulnerability
  • Bloq 0.5.4 Rss2.PHP Remote File Include Vulnerability
  • Bloq 0.5.4 Rdf.PHP Remote File Include Vulnerability
  • Bloq 0.5.4 Mainfile.PHP Remote File Include Vulnerability
  • Bloq 0.5.4 Index.PHP Remote File Include Vulnerability
  • PHPMyConference 8.0.2 Menus.Inc.PHP Remote File Include Vulnerability
  • CDSAgenda 4.2.9 Sendalertemail.PHP Remote File Include Vulnerability
  • Xoops 2.2.3 Search.PHP Cross-Site Scripting Vulnerability
  • PHPBB Add Name Module Not_Mem.PHP Remote File Include Vulnerability
  • PHPBB PlusXL 2.0 PHPBB_Root_Path Parameter Remote File Include Vulnerability
  • Buzlas 2006-1 Archive_Topic.PHP Remote File Include Vulnerability
  • PHPBB News Defilante Horizontale 4.1.1 PHPBB_Root_Path Parameter Remote File Include Vulnerability
  • PHPBB Prillian French Lang_Prillian_Faq.PHP Remote File Include Vulnerability
  • RamaCMS ADODB.Inc.PHP Remote File Include Vulnerability
  • PHPBB Security 1.0.1 PHPBB_Security.PHP Remote File Include Vulnerability
  • PHPBB Amazonia Component Zufallscodepart.PHP Remote File Include Vulnerability
  • PHPBB Import Tools 0.1.4 component PHP Remote File Include Vulnerability
  • DanPHPSupport 0.5 Index.PHP Cross-Site Scripting Vulnerability
  • DanPHPSupport 0.5 Admin.PHP Cross-Site Scripting Vulnerability
  • IncCMS Core 1.0 Inc_Dir Remote File Include Vulnerability
  • Zen Cart 1.3.5 Login.PHP Cross-Site Scripting Vulnerability
  • Zen Cart 1.3.5 Password_Forgotten.PHP Cross-Site Scripting Vulnerability
  • 4Images 1.7.3 Details.PHP Cross-Site Scripting Vulnerability
  • PHPMyConferences 8.0.2 Config.Inc.PHP Remote File Include Vulnerability
  • TorrentFlux 2.1 Startpop.PHP Cross-Site Scripting Vulnerability
  • Def-Blog 1.0.1Comadd.PHP SQL Injection Vulnerability
  • H-Sphere 2.5.1 WebShell Login.PHP Cross-Site Scripting Vulnerability
  • PHPBurningPortal 1.0.1 Quest_News.PHP Remote File Include Vulnerability
  • PHPBurningPortal 1.0.1 Quest_Edit.PHP Remote File Include Vulnerability
  • PHPBurningPortal 1.0.1 Quest_Delete.PHP Remote File Include Vulnerability
  • WebYep 1.1.9 WYLogonButtonElement.PHP Remote File Include Vulnerability
  • WebYep 1.1.9 WYGuestbookElement.php.PHP Remote File Include Vulnerability
  • WebYep 1.1.9 WYGalleryElement.PHP Remote File Include Vulnerability
  • WebYep 1.1.9 WYSelectMenu.PHP Remote File Include Vulnerability
  • WebYep 1.1.9 WYPath.PHP Remote File Include Vulnerability
  • WebYep 1.1.9 Webyep.PHP Remote File Include Vulnerability
  • WebYep 1.1.9 WYDocument.PHP Remote File Include Vulnerability
  • WebYep 1.1.9 Webyep.PHP Remote File Include Vulnerability
  • PhpBB SpamBlockerMod 1.0.2 Phpbb_Root_Path Remote File Include Vulnerability
  • Vikingboard 0.1b Topic.PHP SQL Injection Vulnerability
  • Osprey 1.0 GetRecord.PHP Remote File Include Vulnerability
  • Webgenius Goop Gallery 2.0.2 Index.PHP Cross-Site Scripting Vulnerability
  • TorrentFlux 2.1 Admin.PHP Multiple HTML Injection Vulnerabilities
  • CyberBrau 0.9.4 Track.PHP Remote File Include Vulnerability
  • Simplog 0.9.3.1 Comments.PHP SQL Injection Vulnerability
  • Mambo MostlyCE 4.5.4 HTMLTemplate.PHP Remote File Include Vulnerability
  • Maintain 3.0.0 RC2 Example6.PHP Remote File Include Vulnerability
  • Lodel CMS 0.7.3 Calcul-Page.PHP Remote File Include Vulnerability
  • PHPBB ACP User Registration 1.0 PHPBB_Root_Path Parameter Remote File Include Vulnerability
  • PHPBB Archive for Search Engines PHPBB_Root_Path Parameter Remote File Include Vulnerability
  • PowerMovieList 0.14 Edit User HTML Injection Vulnerability
  • SuperMod 3.0 Multiple Remote File Include Vulnerabilities
  • Open Conference Systems 1.1.3 Footer.Inc.PHP Remote File Include Vulnerability
  • Open Conference Systems 1.1.3 Theme.Inc.PHP Remote File Include Vulnerability
  • Back-End CMS 0.4.5 Search.PHP Remote File Include Vulnerability
  • Back-End CMS 0.4.5 Facts.PHP Remote File Include Vulnerability
  • Back-End CMS 0.4.5 Index.PHP Remote File Include Vulnerability
  • Specimen Image Database Remote File Include Vulnerability
  • PHPRecipeBook 2.18 Import_MM.Class.PHP Remote File Include Vulnerability
  • PhpMyManga 0.8.1 ActionsPage Parameter Remote File Include Vulnerability
  • PhpMyManga 0.8.1 FormPage Parameter Remote File Include Vulnerability
  • PHPMybibli 2.1 Circ.PHP Remote File Include Vulnerability
  • PHPMybibli 2.1 Edit.PHP Remote File Include Vulnerability
  • PHPMybibli 2.1 Index.PHP Remote File Include Vulnerability
  • OpenDock FullCore 4.4 Find.PHP Remote File Include Vulnerability
  • OpenDock FullCore 4.4 Comment.PHP Remote File Include Vulnerability
  • OpenDock FullCore 4.4 Lib_Cart.PHP Remote File Include Vulnerability
  • OpenDock FullCore 4.4 Cart.PHP Remote File Include Vulnerability
  • OpenDock FullCore 4.4 Index_Sw.PHP Remote File Include Vulnerability

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.