releases

Acunetix Web Vulnerability Scanner Product Releases

docs & FAQs

Acunetix technical documentation and FAQ

news

Acunetix Company and Web Security news, & Press Releases

events

Acunetix Webinars, Events and Training around the world

web security zone

Everything you need to know about Web Security

Home » Archive by Month

Article Archive for October 2009

CubeCart 4 session management bypass leads to administrator access
October 29, 2009 – 8:13 pm | 11 Comments
CubeCart 4 session management bypass leads to administrator access

Release Date: 2009/10/29
Author: Bogdan Calin (bogdan [at] acunetix [dot] com)
Severity: Critical
Vendor Status: Vendor has released an updated version
Release Date: 2009/10/29
Author: Bogdan Calin (bogdan [at] acunetix [dot] com)
Severity: Critical
Vendor Status: Vendor has released …

Acunetix WVS Version 6.5 build 20091027 released
October 27, 2009 – 9:52 pm | No Comment

An updated build for Acunetix WVS Version 6.5 has been released.  It includes a number of bug fixes.
Bug fixes:

Fixed: Redirect on LoginSequenceStep was not followed correctly
Fix in URL Rewrite module to remove GetVars before matching …

Acunetix WVS Version 6.5 build 20091012 released
October 12, 2009 – 5:11 pm | No Comment

An updated build for Acunetix WVS Version 6.5 has been released with some bug fixes.
Bug fixes:
Fixed: Memory leak when invoking state change handler
Fixed: Item index for an item which has just been inserted fails in …

Statistics from 10,000 leaked Hotmail passwords
October 6, 2009 – 7:54 pm | 198 Comments

An anonymous user posted usernames and passwords for over 10,000 Windows Live Hotmail accounts to web site PasteBin.
PasteBin is currently down for maintenance but I managed to get a copy of the list and quickly …

Acunetix WVS Version 6.5 build 20091005 released
October 5, 2009 – 3:41 pm | One Comment

An updated build for Acunetix WVS Version 6.5 has been released with some improvements, bug fixes and new security checks.
New:
Added a new check for SVN repositories
Improvements:
Improved MultiRequest paramenter manipulation; now using the form matcher to …