RunCMS vulnerabilities and new updates

By N-Stalker Team on February 13, 2007

N-Stalker has made available the latest database update for its Web Application Security Assessment Products. Following the support life-cycle, we are still distributing updates for previous version.

You will be able to download it automatically in the following versions:

  • N-Stalker Web Application Security Scanner 2006 (Enterprise, QA and Infrastructure Edition)
    • WSI Update (N-Stalker Update Manager)
  • N-Stealth HTTP Security Scanner (database update 192)
    • Automatic DB Update

You should be able to receive it automatically next time you execute the scanner.

If you prefer to download it manually, please, use the following url: https://customer.nstalker.com.

If you need any additional assistance during this process, please, contact us at:
Web: Open new support ticket at https://customer.nstalker.com
E-mail: http://www.nstalker.com/about/contact (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

  • Digiappz Freekot 1.01 ASP SQL Injection Vulnerability
  • HLstats 1.34 Hlstats.PHP Cross Site Scripting Vulnerability
  • VisualShapers EzContents 2.0.3 Loginreq2.PHP Cross Site Scripting Vulnerability
  • Evision CMS 1.0 Path Parameter Multiple Remote File Include Vulnerabilities
  • CubeCart 3.0.12 File Include Vulnerability
  • CubeCart 3.0.12 SQL Injection Vulnerability
  • Membrepass 1.5 Recherchemembre.PHP SQL Injection Vulnerability
  • Membrepass 1.5 Multiple Cross-Site Scripting Vulnerabilities
  • VisualShapers EzContents 2.0.3 Headeruserdata.PHP SQL Injection Vulnerability
  • PHP 5.1.3 PHPInfo Large Input Cross-Site Scripting Vulnerability
  • ExBB 1.9.1 Home_Path Parameter Multiple Remote File Include Vulnerabilities
  • DieselScripts DieselPay Index.PHP Cross-Site Scripting Vulnerability
  • YACS 6.6.1 Multiple Remote File Include Vulnerabilities
  • VBZoom 1.11 Index.PHP Cross-Site Scripting Vulnerability
  • ICBlogger 2.0 Devam.ASP SQL Injection Vulnerability
  • Drupal 4.7.1 Cross-Site Scripting Vulnerabilities
  • IntegraMOD 2.0 PHPbb_Root_Path Multiple Remote File Include Vulnerabilities
  • ToendaCMS 1.0.3 Remote File Include Vulnerability
  • AlstraSoft Template Seller 3.25 Config[Template_Path] Multiple Remote File Include Vulnerabilities
  • e107 0.7.5 Multiple SQL Injection Vulnerabilities
  • Autentificator 2.01 Aut_Verifica.Inc.PHP SQL Injection Vulnerability
  • SSLinks 1.33 Multiple SQL Injection Vulnerabilities
  • Revista 1.1.2 File Include Vulnerability
  • Revista 1.1.2 Busqueda.PHP SQL Injection Vulnerability
  • Revista 1.1.2 Autor.PHP SQL InjectionVulnerabilities
  • Revista 1.1.2 Email.PHP SQL Injection Vulnerability
  • Revista 1.1.2 Articulo.PHP SQL Injection Vulnerability
  • Revista 1.1.2 Lista.PHP SQL Injection Vulnerability
  • Revista 1.1.2 Busqueda_Tema.PHP SQL Injection Vulnerabilities
  • Revista 1.1.2 Busqueda.PHP Cross-Site-Scripting Vulnerability
  • Revista 1.1.2 Lista.PHP Cross-Site Scripting Vulnerability
  • Annuaire 1Two 1.1 Index.PHP SQL Injection Vulnerability
  • SoftBB 0.1 Page Parameter Cross-Site Scripting Vulnerability
  • PHP-Nuke MyHeadlines 4.3.1 Module Cross-Site Scripting Vulnerability
  • DynCMS X_Admindir Remote File Include Vulnerability
  • Tiny Web Gallery 1.5 Image Parameter Multiple Remote File Include Vulnerabilities
  • PHP-Proxima 6.0 BB_Smilies.PHP Local File Include Vulnerability
  • WEBinsta CMS 0.3.1 Templates_Dir Remote File Include Vulnerability
  • Muratsoft Haber Portal 3.6 Kategori.ASP SQL Injection Vulnerability
  • MyBace Light User_Daten.PHP Remote File Include Vulnerability
  • In-Portal In-Link 2.3.4 ADODB_DIR.PHP Remote File Include Vulnerability
  • Yappa-NG 2.3.1 Admin_Module_Deldir.Inc.PHP Remote File Include Vulnerability
  • Papoo CMS 3.2 IBrowser Remote File Include Vulnerability
  • pHNews alpha 1 Comments.PHP Local File Include Vulnerability
  • TR Forum 2.0 SQL Injection Vulnerability
  • Timesheet 1.2.1 Login.PHP SQL Injection Vulnerability
  • SoftBB 0.1 Addmembre.PHP SQL Injection Vulnerability
  • SoftBB 0.1 Moveto.PHP SQL Injection Vulnerability
  • PortailPHP Mod_PHPAlbum 2.1.5 Sommaire_Admin.PHP Remote File Include Vulnerability
  • Akarru Social BookMarking Engine 4.3.34 Main_Content.PHP Remote File Include Vulnerability
  • SZEWO PhpCommander 3.0 Download.PHP Local File Include Vulnerability
  • Premod Shadow 2.7.1 Functions_Portal.PHP Remote File Include Vulnerability
  • Beautifier 0.1 Core.PHP Remote File Include Vulnerability
  • Uni-vert PhpLeague 0.82 Joueurs.PHP SQL Injection Vulnerability
  • Bingo News 3.01 BP_ncom.PHP Remote File Include Vulnerability
  • Graphiks GrapAgenda 0.1 Index.PHP Remote File Include Vulnerability
  • PHPFullAnnu 5.1 Home.Module.PHP Remote File Include Vulnerability
  • CCHost 2.9 Index.PHP SQL Injection Vulnerability
  • WordPress 2.0.4 Paged Parameter SQL Injection Vulnerability
  • Ixprim 1.2 CMS Theme_Manager.Class.PHP Remote File Include Vulnerability
  • MyBace Light Login_Check.PHP Remote File Include Vulnerability
  • Web-Provence SL_Site 1.0 Spaw_control.class.PHP Remote File Include Vulnerability
  • Blog:CMS 4.1 NP_Referrer.PHP SQL Injection Vulnerabilities
  • Blog:CMS 4.1 NP_Poll.PHP SQL Injection Vulnerabilities
  • Blog:CMS 4.1 NP_Log.PHP SQL Injection Vulnerabilities
  • WMNews 0.5 Delete.PHP Remote File Include Vulnerabilities
  • WMNews 0.5 Modify.PHP Remote File Include Vulnerabilities
  • WMNews 0.5 Admin.PHP Remote File Include Vulnerabilities
  • WMNews 0.5 Modify_Go.PHP Remote File Include Vulnerabilities
  • WMNews 0.5 Article.PHP Remote File Include Vulnerabilities
  • PHP-Fusion 6.1.4 News.PHP SQL Injection Vulnerability
  • PpalCart 2.5 EE Mainpage.PHP File Include Vulnerabilities
  • PpalCart 2.5 EE Index.PHP File Include Vulnerabilities
  • Somery 0.4.6 Include.PHP Remote File Include Vulnerability
  • PHP-Fusion 6.1.4 Maincore.PHP SQL Injection Vulnerability
  • PhpNews 1.0 Variables.PHP Remote File Include Vulnerabilities
  • PhpNews 1.0 Lib.Inc.PHP Remote File Include Vulnerabilities
  • RunCms 1.4.1 Sessions.Class.PHP SQL Injection Vulnerabilities
  • RunCms 1.4.1 Xoopsuser.PHP SQL Injection Vulnerabilities
  • PhpLinkExchange 1.0 File Include Vulnerabilities
  • PhpLinkExchange 1.0 Cross-Site Scripting Vulnerability
  • Fire Soft Board RC3 Demarrage.PHP Remote File Include Vulnerability
  • Jetbox CMS 2.1 Config.PHP Remote File Include Vulnerability
  • Sponge News 2.2 News.PHP Remote File Include Vulnerability
  • KorviBlog 1.3 Livre_or.PHP HTML Injection Vulnerability
  • Limbo CMS 1.0.4 SQL.PHP Remote File Include Vulnerability
  • Photokorn 1.52 Cart.Inc.PHP Remote File Include Vulnerabilities
  • Photokorn 1.52 Ext_Cats.PHP Remote File Include Vulnerabilities
  • Jetbox CMS 2.1 Index.PHP Cross-Site Scripting Vulnerability

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.