v11.0.173271618 - 24 Nov 2017 Copy Link Copy Link Version 11 (build 11.0.173271618) – 24th November 2017 New Features Added new OWASP Top Ten 2017 report Fixes Fixed: DeepScan was processing ignored scripts
v11.0.173131028 - 09 Nov 2017 Copy Link Copy Link Version 11 (build 11.0.173131028) – 9th November 2017 New Features and Vulnerability Tests Added support for Selenium scripts as Target Import files Introduced various vulnerability checks for CMS Made Simple including: PHP Remote File Inclusion (RFI) in version 0.10 (CVE-2005-2846) SQL Injection in version 1.0.5 and earlier (CVE-2007-2473) Directory Traversal in version 1.8.1 and earlier (CVE-2010-2797) Web Server Cache Poisoning in versions 2.1.3 and earlier and 1.12.2 and earlier (CVE-2016-2784) Cross Site Request Forgery (CSRF) in version 2.1.6 and earlier (CVE-2016-7904) Cross Site Scripting (XSS) in version 2.1.6 and earlier (CVE-2017-6555) Cross Site Scripting (XSS) in version 2.1.6 (CVE-2017-6556) Local File Inclusion in version 2.1.6 and earlier Improvements Various minor UI updates Improved handling of aborted scans for Targets with Continuous scanning enabled Increased Custom Cookie size limit from 512 bytes to 10Kb (2Kb for Acunetix Online) Added new email templates Email notification now indicates if a scan has failed Multiple minor updates to the reports Updated the Error Message script to show full JAVA error messages Tech Admin role can now create and alter Scan types. Fixes Scan Comparison was incorrectly switching the order of the scans Scan Comparison was incorrectly comparing with Allowed host Fixed bug in the licensed user limit Fixed bug causing scans to fail when the LSR contains Unicode characters Multiple fixes in XML export Multiple fixes in F5 WAF rules export Fixed 2 minor security issues in web interface 2 fixes affecting incorrect vulnerability count in Dashboard Fixed the retesting of vulnerabilities for Targets requiring manual intervention Fixed the Targets page incorrectly showing that the Target is being scanned, when an ongoing scan is deleted.
v11.0.172901635 - 17 Oct 2017 Copy Link Copy Link Version 11 (build 11.0.172901635) – 17th October 2017 New Features and Vulnerability Tests Added detection for XSF vulnerability in WordPress (CVE-2016-9263) Improvements Updated the Joomla and WordPress vulnerability checks Fixes Fixed bug causing scans to fail because of certain characters in the LSR file
v11.0.172641450 - 22 Sep 2017 Copy Link Copy Link Version 11 (build 11.0.172641450) – 22nd September 2017 New Features and Vulnerability Tests Added detection for Apache Struts Remote Code Execution (s2-052) Added detection for Apache Struts Remote Code Execution (s2-053) – CVE-2017-12611 Check for Header Injection via misconfigured nginx redirects Check for nginx Integer Overflow vulnerability (CVE-2017-7529) Improvements Improved the detection of Blind SQL Injection Better support for large JavaScript files JAVA error detection now includes the full JAVA error returned by the server Improved the Remote File Inclusion XSS checks Updated the Joomla and WordPress vulnerability checks Fixes Fixed bug causing the downloading of a Target’s LSR file to fail Fixed bug in HTTP Digest Authentication
v11.0.172371608 - 25 Aug 2017 Copy Link Copy Link Version 11 (build 11.0.172371608) – 25th August 2017 Fixes Fixed issue causing automatic updates to fail. Updates need to be downloaded manually from https://www.acunetix.com/download/fullver11/
v11.0.172351036 - 23 Aug 2017 Copy Link Copy Link Version 11 (build 11.0.172351036) – 23rd August 2017 New Features and Vulnerability Tests Detection of Apache Struts 2 Showcase RCE (CVE-2017-9791) Check for .hgignore (Mercurial SCM configuration file) Check for Atlassian Confluence Stored XSS (CVE-2016-6283) Check for private key files with names based on ScanHost, e.g. “www.example.org.key”, “example.org.key” Check for moment.js Denial of Service (CVE-2016-4055) Various updates to the WordPress and Joomla checks Introduction of Multi-Engine functionality for Enterprise customers Improvements Updated the Database backup file checks Improved Jquery version fingerprinting Updated detection of HttpOnly and Secure cookie flags Updated default Target list sorting Fixes Fixed XSS detection issue Minor fix to the allow_url_fopen enabled check Fixed F5 BIP-AP ASM WAF XML export Fixed issue causing Acunetix not to be able to install on Chinese OS
v11.0.171721334 - 21 Jun 2017 Copy Link Copy Link Version 11 (build 11.0.171721334) – 21st June 2017 New Vulnerability Tests Checks for XSS vulnerabilities jQuery UI version < 1.12.0 Checks for various jQuery vulnerabilities Checks for Atlassian Confluence Access Restriction Bypass Checks for Tiki Wiki CMS Arbitrary File Download Checks for Tiki Wiki CMS Calendar module RCE Checks for Tiki Wiki CMS file upload vulnerability leading to arbitrary code execution. Improvements Improved detection of WordPress version Various updates to the WordPress and Joomla checks Updated description for Broken links alert. Fixes Fixed issue causing a crash in the scanning engine Fix affecting the processing of xml files, resulting in scan performance improvement Fix in the High Risk Scan Type, resulting in scan performance improvement Various updates and fixes in the Acunetix web UI.
v11.0.171381251 - 18 May 2017 Copy Link Copy Link Version 11 (build 11.0.171381251) – 18th May 2017 New Vulnerability Tests New check for Joomla SQL Injection Vulnerability (CVE-2017-8917)
v11.0.171251523 - 05 May 2017 Copy Link Copy Link Version 11 (build 11.0.171251523) – 5th May 2017 New Vulnerability Tests New check for WordPress Potential Unauthorized Password Reset