The Invicti Team today announced an updated build of the Web Vulnerability Scanner Version 8 (WVS 8). The new build, number 20120326, includes new security checks that detect even more vulnerabilities as well as a series of bug fixes.

New Security Checks

Invicti WVS 8 now runs security tests for Joomla 1.6.x/1.7.x/2.5.x Privilege Escalation.
Invicti WVS 8 now provides security tests Joomla 1.7/2.5 Core SQL Injection.

Bug Fixes

  • The crash in the Login Sequence Recorder has been fixed.
  • The Login Sequence Recorder is accurately parsing websites which send back GZIP encoded content, even if it was not specified in the Accept-Encoding header.
  • The Invicti Reporter has improved the handling of missing scans reports.
  • The Invicti Reporter Console supports spaces within the specified parameters.
  • The Invicti Reporter accepts longer input names.

Improvements

  • More advanced security checks for MongoDB and Rails Mass Assignment.

How to Upgrade to Build 20120326:

On starting up Invicti Web Vulnerability Scanner, a pop up window will automatically notify you that a more recent build is available for download.  To download the latest build, navigate to General > Program Updates node in the Tools explorer, click on Download and Install the new build.

Click here for the complete Invicti WVS change log.

To stay up to date with the latest web security news, join the Invicti community by liking the Invicti Facebook Page. Also, follow us on Twitter and read the Invicti Blog.

SHARE THIS POST
THE AUTHOR
Invicti
Invicti

Invicti developers and tech agents regularly contribute to the blog. All the Invicti developers come with years of experience in the web security sphere.