PHPCMS Vulnerabilities and multiple updates

By N-Stalker Team on April 6, 2009

N-Stalker has made available its latest “N-Stealth Web Attack Database” update for all products, including N-Stalker 2009 and 2006 version.You should be able to automatically download it next time you execute N-Stalker Scanner.

If you need to contact us for additional instructions, go to N-Stalker’s Customer Center.

Important Note:  N-Stalker 2006 Version has been discontinued since March 31st, 2009. You must upgrade to N-Stalker 2009 to obtain our technical support.

This release includes patterns for the following vulnerabilities:

  • MyioSoft Ajax Portal 3.0 Ajaxp_Backend.PHP SQL Injection Vulnerability
  • TinyPHPForum 3.61 Index.PHP Directory Traversal Vulnerability
  • Turnkey eBook Store 1.1 Index.PHP Cross Site Scripting Vulnerability – [CVE-2009-1225]
  • webEdition CMS 6.0.0.4 Index.PHP Local File Include Vulnerability – [CVE-2009-1222]
  • Diskos CMS Manager Side.ASP SQL Injection Vulnerability – [CVE-2009-1222]
  • iWare 5.0.4 Index.PHP CATEGORY Parameter SQL Injection Vulnerability – [CVE-2009-1222]
  • iWare 5.0.4 Index.PHP ID Parameter SQL Injection Vulnerability – [CVE-2009-1222]
  • iWare 5.0.4 Index.PHP D Parameter SQL Injection Vulnerability – [CVE-2009-1222]
  • Community CMS 0.5 View.PHP SQL Injection Vulnerability – [CVE-2009-1222]
  • Community CMS 0.5 Index.PHP SQL Injection Vulnerability – [CVE-2009-1222]
  • Multiple Gravy Media Applications 1.0 Viewmsg.PHP SQL Injection Vulnerability – [CVE-2009-1222]
  • Multiple Gravy Media Applications 1.0 Rate.PHP SQL Injection Vulnerability – [CVE-2009-1222]
  • JobHut Browse.PHP SQL Injection Vulnerability – [CVE-2009-1222]
  • Family Connections 1.8.1 Lostpw.PHP SQL Injection Vulnerability – [CVE-2009-1222]
  • Family Connections 1.8.1 Activate.PHP SQL Injection Vulnerability – [CVE-2009-1222]
  • Family Connections 1.8.1 Recipes.PHP SQL Injection Vulnerability – [CVE-2009-1222]
  • Family Connections 1.8.1 Addressbook.PHP SQL Injection Vulnerability – [CVE-2009-1222]
  • BandSite CMS 1.1.4 Members.PHP SQL Injection Vulnerability – [CVE-2009-1222]
  • My Simple Forum 7.1 Index.Template.PHP Cross-Site Scripting Vulnerability – [CVE-2009-1222]
  • My Simple Forum 7.1 Index.Template.PHP Local File Include Vulnerability – [CVE-2009-1222]
  • My Simple Forum 7.1 Index.PHP Local File Include Vulnerability – [CVE-2009-1222]
  • YAP 1.1.1 Index.PHP SQL Injection Vulnerability – [CVE-2009-1038]
  • YAP 1.1.1 Comments.PHP SQL Injection Vulnerability – [CVE-2009-1038]
  • Free PHP Petition Signing Script Login Page SQL Injection Vulnerability – [CVE-2009-1038]
  • Simply Classified 0.2 Adverts.PHP SQL Injection Vulnerability – [CVE-2009-1038]
  • Aurora FoodPro Nutritive Analysis Module Nutframe.ASP Cross Site Scripting Vulnerabilities – [CVE-2009-1038]
  • Aurora FoodPro Nutritive Analysis Module Menusamp.ASP Cross Site Scripting Vulnerabilities – [CVE-2009-1038]
  • Acute Control Panel 1.0 Container.PHP Remote File Include Vulnerability – [CVE-2009-1038]
  • Acute Control Panel 1.0 Index.PHP SQL Injection Vulnerability – [CVE-2009-1038]
  • Acute Control Panel 1.0 Header.PHP Remote File Include Vulnerability – [CVE-2009-1038]
  • Blogplus 1.0 Block_Center_Down.PHP Local File Include Vulnerability – [CVE-2009-1038]
  • Blogplus 1.0 Window_Top.PHP Local File Include Vulnerability – [CVE-2009-1038]
  • Blogplus 1.0 Window_Down.PHP Local File Include Vulnerability – [CVE-2009-1038]
  • Blogplus 1.0 Block_Right.PHP Local File Include Vulnerability – [CVE-2009-1038]
  • Blogplus 1.0 Block_Left.PHP Local File Include Vulnerability – [CVE-2009-1038]
  • Blogplus 1.0 Block_Center_Top.PHP Local File Include Vulnerability – [CVE-2009-1038]
  • PHPCMS2008 2008.2.11 Search_Ajax.PHP SQL Injection Vulnerability – [CVE-2009-1038]
  • BlogEngine.NET 1.4 Search.ASPX Cross Site Scripting Vulnerability – [CVE-2008-6476]
  • Mega File Hosting Script Cross.PHP Remote File Include Vulnerability – [CVE-2009-0966]
  • SurfMyTv Script 1.0 View.PHP SQL Injection Vulnerability – [CVE-2009-0966]
  • Syzygy CMS 0.3 Index.PHP Local File Include Vulnerability – [CVE-2009-0966]
  • Syzygy CMS 0.3 Index.PHP SQL Injection Vulnerability – [CVE-2009-0966]
  • Comparison Engine Power 1.0 Product.Comparision.PHP SQL Injection Vulnerability – [CVE-2009-0966]
  • Codice CMS 2.0 Index.PHP SQL Injection Vulnerability – [CVE-2009-0966]
  • Pluck 4.6.1 Module_Pages_Site.PHP Local File Include Vulnerability – [CVE-2009-0966]
  • Rittal CMC-TC Processing Unit II 7320.100 Cmclogin.CGI Cross-Site Scripting Vulnerability – [CVE-2009-0966]
  • PHPizabi 0.848b.C1 NOTEPAD_BODY Parameter SQL Injection Vulnerability – [CVE-2009-0966]
  • PHPizabi 0.848b Dac.PHP Local File Include Vulnerability – [CVE-2009-0966]
  • Jinzora 2.8 Index.PHP Local File Include Vulnerability – [CVE-2009-0966]
  • X-BLC 0.2 Get_Read.PHP SQL Injection Vulnerability – [CVE-2009-0966]
  • SuperNews 1.5 Valor.PHP SQL Injection Vulnerability – [CVE-2009-0966]
  • WBB3 rGallery 1.2.3 Index.PHP SQL Injection Vulnerability – [CVE-2009-0966]
  • Pixie CMS Index.PHP Cross Site Scripting Vulnerability – [CVE-2009-1067]
  • Pixie CMS Index.PHP SQL Injection Vulnerability – [CVE-2009-1065]
  • FacilCMS 0.1 Phpinfo.PHP Information Disclosure Vulnerability – [CVE-2009-1065]
  • FacilCMS 0.1 Modules.PHP SQL Injection Vulnerability – [CVE-2009-1065]
  • FacilCMS 0.1 Index.PHP SQL Injection Vulnerability – [CVE-2009-1065]
  • YABSoft Advanced Image Hosting Script 2.3 Gallery_List.PHP SQL Injection Vulnerability – [CVE-2009-1032]
  • DeluxeBB 1.0.5 Misc.PHP SQL Injection Vulnerability – [CVE-2009-1033]
  • Joomla! and Mambo myContent Component 1.1.13 Index.PHP SQL Injection Vulnerability – [CVE-2008-6430]
  • GDL 4.2 Gdl.PHP SQL Injection Vulnerability – [CVE-2009-0965]

This entry was posted in N-Stalker Latest Updates and tagged , . Bookmark the permalink.