Joomla! Components vulnerabilities and updates for Aug 2010

By N-Stalker Team on August 12, 2010

N-Stalker has made available its latest “N-Stealth Web Attack Database” update for all products, including N-Stalker 2009 and 2006 version.You should be able to automatically download it next time you execute N-Stalker Scanner.

If you need to contact us for additional instructions, go to N-Stalker’s Customer Center.

Important Note: N-Stalker 2006 Version has been discontinued since March 31st, 2009. You must upgrade to N-Stalker 2009 to obtain our technical support.

This release includes patterns for the following vulnerabilities:

  • Joomla! DM Orders Component Index.PHP SQL Injection Vulnerability
  • Joomla! jEmbed Component Index.PHP SQL Injection Vulnerability – [CVE-2010-1073]
  • D-LINK DKVM-IP8 Auth.ASP Cross Site Scripting Vulnerability – [CVE-2010-0936]
  • Com_Kk Joomla! Component Index.PHP SQL Injection Vulnerability – [CVE-2010-0936]
  • Docebo 3.6.0.2 Index.PHP Local File Include Vulnerability – [CVE-2010-0936]
  • Joomla! Com_Perchagallery Component Index.PHP SQL Injection Vulnerability – [CVE-2010-0694]
  • Joomla! Joaktree Component 1.0 Index.PHP SQL Injection Vulnerability – [CVE-2009-4784]
  • Joomla! BF Survey Pro Index.PHP SQL Injection Vulnerability – [CVE-2010-2255]
  • BF Survey Pro Joomla! Component Index.PHP Local File Include Vulnerability – [CVE-2010-2255]
  • LXR Cross Referencer 0.9.6 Multiple Cross Site Scripting Vulnerabilities – [CVE-2009-4497]
  • Dating Agent PRO 4.9.1 Search.PHP HTML Injection Vulnerability – [CVE-2009-4497]
  • Dating Agent PRO 4.9.1 Picture.PHP HTML Injection Vulnerability – [CVE-2009-4497]
  • Dating Agent PRO 4.9.1 Login.PHP SQL Injection Vulnerability – [CVE-2009-4497]
  • Joomla! Module for Alfresco 1.0 Index.PHP SQL Injection Vulnerability – [CVE-2009-4497]
  • Discuz! 1.0 Member.PHP Cross Site Scripting Vulnerability – [CVE-2009-4497]
  • DieselPay 1.6 Cross Site Scripting Vulnerability – [CVE-2009-4497]
  • DieselPay 1.6 Directory Traversal Vulnerability – [CVE-2009-4497]
  • Joomla! J-Projects Component Index.PHP SQL Injection Vulnerability – [CVE-2010-1363]
  • Com_Doqment Joomla! Component Index.PHP SQL Injection Vulnerability – [CVE-2010-1363]
  • MercuryBoard 1.1.5 Index.PHP Cross-Site Scripting Vulnerability – [CVE-2010-1363]
  • Shape5 Bridge of Hope Template for Joomla! Index.PHP SQL Injection Vulnerability – [CVE-2010-2254]
  • WMNews 0.5 Wmnews.PHP Cross-Site Scripting Vulnerability – [CVE-2010-2254]
  • XOOPS 2.4.2 Notification_Update.PHP SQL Injection Vulnerability – [CVE-2010-2254]
  • Dailymeals Joomla! Component Index.PHP Local File Include Vulnerability – [CVE-2010-2254]
  • Joomla! Com_Otzivi Component Index.PHP SQL Injection Vulnerability – [CVE-2010-2254]
  • pL-PHP Index.PHP Cross-Site Scripting Vulnerability – [CVE-2010-2254]
  • Joomla! Com_Tpjobs Component Index.PHP SQL Injection Vulnerability – [CVE-2010-2254]
  • REZERVI Belegungsplan und Gästedatenbank 3.0.2 Mail.Inc.PHP Remote File Include Vulnerability – [CVE-2010-2254]
  • Bible Study Joomla! Component 6.1 Index.PHP Local File Include Vulnerability – [CVE-2010-0157]
  • CARTwebERP Joomla! Component Index.PHP Local File Include Vulnerability – [CVE-2010-0157]
  • Joomla! Com_Aprice Component Index.PHP SQL Injection Vulnerability – [CVE-2010-0157]
  • SLAED CMS 2.0 Index.PHP Cross Site Scripting Vulnerability – [CVE-2010-0157]
  • Discuz! 2.0 Post.PHP Cross Site Scripting Vulnerability – [CVE-2010-0157]
  • Discuz! 2.0 Misc.PHP Cross Site Scripting Vulnerability – [CVE-2010-0157]
  • Com_Bfsurvey Joomla! Component Index.PHP Local File Include Vulnerability – [CVE-2010-0157]
  • Joomla! Com_Countries Component Index.PHP SQL Injection Vulnerability – [CVE-2010-0157]
  • Com_Abbrev Joomla! Component Index.PHP Local File Include Vulnerability – [CVE-2010-0985]
  • VisionGate 1.6 Login.PHP Cross-Site Scripting Vulnerability – [CVE-2010-0985]
  • VirtuaSystems VirtuaNews Pro 1.0.4 Admin.PHP Cross-Site Scripting Vulnerability – [CVE-2010-0985]
  • PHPCart 3.1.2 Search.PHP Cross-Site Scripting Vulnerability – [CVE-2010-0985]
  • Reamday Enterprises Magic News Plus 1.0.2 Index.PHP Cross-Site Scripting Vulnerability – [CVE-2010-0985]
  • ArticleLive 1.7.1.2 Blogs.PHP SQL Injection Vulnerability – [CVE-2010-0985]

This entry was posted in N-Stalker Latest Updates and tagged , , . Bookmark the permalink.