WordPress myGallery vulnerabilities and new updates

By N-Stalker Team on September 4, 2007

N-Stalker has made available the latest database update for its Web Application Security Assessment Products. Following the support life-cycle, we are still distributing updates for previous version.

You will be able to download it automatically in the following versions:

  • N-Stalker Web Application Security Scanner 2006 (Enterprise, QA and Infrastructure Edition)
    • WSI Update (N-Stalker Update Manager)
  • N-Stealth HTTP Security Scanner (not updated)

You should be able to receive it automatically next time you execute the scanner.

If you prefer to download it manually, please, use the following url: https://customer.nstalker.com.

If you need any additional assistance during this process, please, contact us at:
Web: Open new support ticket at https://customer.nstalker.com
E-mail: http://www.nstalker.com/about/contact (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

  • Zomplog 3.8 File.PHP Directory Traversal Vulnerability
  • EclipseBB 0.5 Phpbb_Root_Path Remote File Include Vulnerability
  • NuclearBB Alpha 1 Register.PHP SQL Injection Vulnerability
  • NuclearBB Alpha 1 Login.PHP SQL Injection Vulnerability
  • NuclearBB Alpha 1 Groups.PHP SQL Injection Vulnerability
  • Einfacher Passworschutz Index.PHP Cross-Site Scripting Vulnerability
  • MXBB MX Smartor Module 2.0 PHPBB_Root_Path Remote File Include Vulnerability
  • OpenSurveyPilot 1.2.1 Group.Inc.PHP Remote File Include Vulnerability
  • Creascripts CreaDirectory 1.2 Error.ASP SQL Injection Vulnerability
  • Fully Modded PHPBB2 PHPBB_Root_Path Remote File Include Vulnerability
  • Exponent CMS 0.96.6 Magpie_Debug.PHP Cross-Site Scripting Vulnerability
  • Exponent CMS 0.96.6 Magpie_Slashbox.PHP Cross-Site Scripting Vulnerability
  • Horde Framework 3.1.3 Login.PHP Cross-Site Scripting Vulnerability
  • PHP Turbulence 0.0.1 Turbulence.PHP Remote File Include Vulnerability
  • PHP Turbulence 0.0.1 Turbulence.PHP Local File Include Vulnerability
  • Supasite 1.23b Admin_Auth_Cookies.PHP Remote File Include Vulnerability
  • Supasite 1.23b Admin_Mods.PHP Remote File Include Vulnerability
  • Supasite 1.23b Admin_News.PHP Remote File Include Vulnerability
  • Supasite 1.23b Admin_Settings.PHP Remote File Include Vulnerability
  • Supasite 1.23b Admin_Topics.PHP Remote File Include Vulnerability
  • Supasite 1.23b Admin_Users.PHP Remote File Include Vulnerability
  • Supasite 1.23b Admin_Utilities.PHP Remote File Include Vulnerability
  • Supasite 1.23b Backend_Site.PHP Remote File Include Vulnerability
  • Supasite 1.23b Site_Comment.PHP Remote File Include Vulnerability
  • Supasite 1.23b Site_News.PHP Remote File Include Vulnerability
  • Supasite 1.23b Common_Functions.PHP Remote File Include Vulnerability
  • JCHit Counter 1.0 Imgsrv.PHP Directory Traversal Vulnerability
  • UPHP Free Ring 0.9 Index.PHP SQL Injection Vulnerability
  • Big Blue Guestbook Comment HTML Injection Vulnerability
  • WEBinsta FM Manager 0.4.1 Admin Cookies Remote File Include Vulnerability
  • TJSChat 0.95 You.PHP Cross-Site Scripting Vulnerability
  • Ripe Website Manager 0.8.4 SQL Injection Vulnerability
  • Ripe Website Manager 0.8.4 Cross-Site Scripting Vulnerability
  • Allfaclassifieds 6.04 Level2.PHP Remote File Include Vulnerability
  • PHPMyBibli 1.32 Init.Inc.PHP Remote File Include Vulnerability
  • File117 DETAIL Parameter Remote File Include Vulnerability
  • File117 RELPATH Parameter Remote File Include Vulnerability
  • PHPMySpace Gold 8.10 Article.PHP SQL Injection Vulnerability
  • ACVSWS Transport.PHP Remote File Include Vulnerability
  • EsForum 3.0 Forum.PHP SQL Injection Vulnerability
  • Post Revolution 7.0 Preview_Post_Completo.PHP Remote File Include Vulnerability
  • Post Revolution 7.0 Common.PHP Remote File Include Vulnerability
  • LMS 1.5.4 RTMessageAdd.PHP Remote File Include Vulnerability
  • MyBulletinBoard 1.2.5 Calendar.PHP SQL Injection Vulnerability
  • PHPConcept PCLTar 1.3.1 PCLTar.PHP Remote File Include Vulnerability
  • Phorum 5.1.20 Admin.PHP SQL Injection Vulnerability
  • Phorum 5.1.20 Admin.PHP Cross-Site Scripting Vulnerability
  • Phorum 5.1.20 Admin.PHP Cross-Site Scripting Vulnerability
  • Phorum 5.1.20 Admin.PHP SQL Injection Vulnerability
  • Pagode 0.5.8 Navigator_ok.PHP Directory Traversal Vulnerability
  • GPB Bulletin Board 2001.11.14-1 Login.PHP Remote File Include Vulnerability
  • GPB Bulletin Board 2001.11.14-1 Gpb.Inc.PHP Remote File Include Vulnerability
  • GPB Bulletin Board 2001.11.14-1 Db.Mysql.Inc.PHP Remote File Include Vulnerability
  • phpMyAdmin 2.9.1 GAL Parameter Cross-Site Scripting Vulnerability
  • phpMyAdmin 2.9.1 PIC Parameter Cross-Site Scripting Vulnerability
  • Claroline 1.8 RootSys Remote File Include Vulnerability
  • USP FOSS Distribution 1.01 Download.PHP Directory Traversal Vulnerability
  • Advanced Webhost Billing System 2.4 Cart2.PHP Remote File Include Vulnerability
  • HTMLEditBox 2.2 Config.PHP Remote File Include Vulnerability
  • Wavewoo 0.1.1 Loading.PHP Remote File Include Vulnerability
  • Plesk 8.1.1 Login.PHP3 Directory Traversal Vulnerability
  • JulmaCMS 1.4 File.PHP Directory Traversal Vulnerability
  • Ext 1.0 Feed-Proxy.PHP Directory Traversal Vulnerability
  • MyNewsGroups 0.6 Include.PHP Remote File Include Vulnerability
  • Built2Go PHP Link Portal 1.79 Remote File Include Vulnerability
  • Comus 2.0 Accept.PHP Remote File Include Vulnerability
  • HYIP Manager Pro Smarty_Compiler.Class.PHP Remote File Include Vulnerability
  • HYIP Manager Pro Core.Display_Debug_Console.PHP Remote File Include Vulnerability
  • HYIP Manager Pro Core.Load_Plugins.PHP Remote File Include Vulnerability
  • HYIP Manager Pro Core.Load_Resource_Plugin.PHP Remote File Include Vulnerability
  • HYIP Manager Pro Core.Process_Cached_Inserts.PHP Remote File Include Vulnerability
  • HYIP Manager Pro Core.Process_Compiled_Include.PHP Remote File Include Vulnerability
  • HYIP Manager Pro Core.Read_Cache_File.PHP Remote File Include Vulnerability
  • HYIP Manager Pro Smarty.Class.PHP Remote File Include Vulnerability
  • DynaTracker 1.5.1 Action.PHP Remote File Include Vulnerability
  • DynaTracker 1.5.1 Includes_Handler.PHP Remote File Include Vulnerability
  • Active PHP Bookmarks 1.0 APB_COMMON.PHP Remote File Include Vulnerability
  • Active PHP Bookmarks 1.0 APB.PHP Remote File Include Vulnerability
  • Burak Yilmaz Blog 1.0 BRY.ASP SQL Injection Vulnerability
  • Firefly 1.1.1 Localize.PHP Remote File Include Vulnerability
  • Firefly 1.1.1 Config.PHP Remote File Include Vulnerability
  • Doruk100Net Info.PHP Remote File Include Vulnerability
  • NetArt Media Blog System 1.4 ADMIN/Login.PHP Remote File Include Vulnerability
  • NetArt Media Blog System 1.4 BO/Index.PHP Remote File Include Vulnerability
  • NetArt Media Blog System 1.4 ADMIN/Index.PHP Remote File Include Vulnerability
  • NetArt Media Blog System 1.4 BO/Login.PHP Remote File Include Vulnerability
  • SineCms 2.3.4 Result.PHP Cross Site Scripting Vulnerability
  • PHPOracleView Include_All.Inc.PHP Remote File Include Vulnerability
  • PHPBandManager 0.8 Index.PHP Remote File Include Vulnerability
  • GForge 4.5.11 Advanced_Search.PHP Cross Site Scripting Vulnerability
  • Imageview 5.3 Fileview.PHP Local File Include Vulnerability
  • Gazi Download Portal Down_Indir.ASP SQL Injection Vulnerability
  • BurnCMS 0.2 Authuser.PHP Remote File Include Vulnerability
  • BurnCMS 0.2 Connect.PHP Remote File Include Vulnerability
  • BurnCMS 0.2 Mysql.Class.PHP Remote File Include Vulnerability
  • BurnCMS 0.2 Postgres.Class.PHP Remote File Include Vulnerability
  • BurnCMS 0.2 Misc.PHP Remote File Include Vulnerability
  • PNFlashGames 1.5 PostNuke Module Index.PHP SQL Injection Vulnerability
  • WordPress MyGallery 1.4 Plugin Remote File Include Vulnerability
  • MyBloggie 2.1.6 Index.PHP SQL Injection Vulnerability
  • MyBloggie 2.1.6 Index.PHP SQL Injection Vulnerability
  • PHP JackKnife 2.21 DisplayResults.PHP SQL Injection Vulnerability
  • PHP JackKnife 2.21 G_Display.PHP SQL Injection Vulnerability
  • PHP JackKnife 2.21 G_Display.PHP Cross-Site Scripting Vulnerability
  • PHP JackKnife 2.21 G_Display.PHP Cross-Site Scripting Vulnerability
  • PHP JackKnife 2.21 G_Display.PHP Cross-Site Scripting Vulnerability
  • PHP JackKnife 2.21 G_Display.PHP Cross-Site Scripting Vulnerability
  • PHP JackKnife 2.21 Authenticate.PHP Cross-Site Scripting Vulnerability
  • PHP JackKnife 2.21 Index.PHP Cross-Site Scripting Vulnerability
  • PHP JackKnife 2.21 G_Display.PHP Cross-Site Scripting Vulnerability

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.