<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.3.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Code-Authors</title>
	<link>http://wiki.code-authors.com</link>
	<description>Code Authors Blog</description>
	<pubDate>Wed, 16 Jan 2008 08:11:33 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.2</generator>
	<language>en</language>
			<item>
		<title>[Drupal] Drupal Multiple Vulnerabilitie</title>
		<link>http://wiki.code-authors.com/2008/01/16/drupal-drupal-multiple-vulnerabilitie/</link>
		<comments>http://wiki.code-authors.com/2008/01/16/drupal-drupal-multiple-vulnerabilitie/#comments</comments>
		<pubDate>Wed, 16 Jan 2008 08:11:33 +0000</pubDate>
		<dc:creator>Guardian</dc:creator>
		
		<category><![CDATA[Drupal]]></category>

		<guid isPermaLink="false">http://wiki.code-authors.com/2008/01/16/drupal-drupal-multiple-vulnerabilitie/</guid>
		<description><![CDATA[TITLE:
Drupal Multiple Vulnerabilities
SECUNIA ADVISORY ID:
SA28422
VERIFY ADVISORY:
http://secunia.com/advisories/28422/
CRITICAL:
Moderately critical
IMPACT:
Cross Site Scripting
WHERE:
From remote
SOFTWARE:
Drupal 4.x
http://secunia.com/product/342/
Drupal 5.x
http://secunia.com/product/13378/
DESCRIPTION:
Some vulnerabilities have been reported in Drupal, which can be
exploited by malicious people to conduct cross-site scripting, script
insertion, and cross-site request forgery attacks.
1) Input passed via unspecified parameters to theme .tpl.php files is
not properly sanitised before being returned to the user. This can be
exploited [...]]]></description>
		<wfw:commentRss>http://wiki.code-authors.com/2008/01/16/drupal-drupal-multiple-vulnerabilitie/feed/</wfw:commentRss>
		</item>
		<item>
		<title>[Drupal] Drupal Meta Tags Module Arbitrary Code Executio</title>
		<link>http://wiki.code-authors.com/2008/01/15/drupal-drupal-meta-tags-module-arbitrary-code-executio/</link>
		<comments>http://wiki.code-authors.com/2008/01/15/drupal-drupal-meta-tags-module-arbitrary-code-executio/#comments</comments>
		<pubDate>Tue, 15 Jan 2008 15:58:42 +0000</pubDate>
		<dc:creator>Guardian</dc:creator>
		
		<category><![CDATA[Drupal]]></category>

		<guid isPermaLink="false">http://wiki.code-authors.com/2008/01/15/drupal-drupal-meta-tags-module-arbitrary-code-executio/</guid>
		<description><![CDATA[TITLE:
Drupal Meta Tags Module Arbitrary Code Execution
SECUNIA ADVISORY ID:
SA28478
VERIFY ADVISORY:
http://secunia.com/advisories/28478/
CRITICAL:
Moderately critical
IMPACT:
System access
WHERE:
From remote
SOFTWARE:
Drupal Meta Tags Module 5.x
http://secunia.com/product/17200/
DESCRIPTION:
A vulnerability has been reported in the Meta Tags module for Drupal,
which can be exploited by malicious users to compromise a vulnerable
system.
The vulnerability is caused due to an error within the handling of
nodes. This can be exploited to execute [...]]]></description>
		<wfw:commentRss>http://wiki.code-authors.com/2008/01/15/drupal-drupal-meta-tags-module-arbitrary-code-executio/feed/</wfw:commentRss>
		</item>
		<item>
		<title>[Drupal] Drupal BUEditor Module Cross-Site Request Forger</title>
		<link>http://wiki.code-authors.com/2008/01/12/drupal-drupal-bueditor-module-cross-site-request-forger/</link>
		<comments>http://wiki.code-authors.com/2008/01/12/drupal-drupal-bueditor-module-cross-site-request-forger/#comments</comments>
		<pubDate>Sat, 12 Jan 2008 09:16:34 +0000</pubDate>
		<dc:creator>Guardian</dc:creator>
		
		<category><![CDATA[Drupal]]></category>

		<guid isPermaLink="false">http://wiki.code-authors.com/2008/01/12/drupal-drupal-bueditor-module-cross-site-request-forger/</guid>
		<description><![CDATA[TITLE:
Drupal BUEditor Module Cross-Site Request Forgery
SECUNIA ADVISORY ID:
SA28418
VERIFY ADVISORY:
http://secunia.com/advisories/28418/
CRITICAL:
Less critical
IMPACT:
Cross Site Scripting
WHERE:
From remote
SOFTWARE:
Drupal BUEditor Module 4.x
http://secunia.com/product/17176/
Drupal BUEditor Module 5.x
http://secunia.com/product/17177/
DESCRIPTION:
A vulnerability has been reported in the BUEditor module for Drupal,
which can be exploited by malicious people to conduct cross-site
request forgery attacks.
The problem is that the module allows users to perform certain
actions via HTTP requests without performing [...]]]></description>
		<wfw:commentRss>http://wiki.code-authors.com/2008/01/12/drupal-drupal-bueditor-module-cross-site-request-forger/feed/</wfw:commentRss>
		</item>
		<item>
		<title>[Mambo] Mambo Search Denial of Servic</title>
		<link>http://wiki.code-authors.com/2008/01/12/mambo-mambo-search-denial-of-servic/</link>
		<comments>http://wiki.code-authors.com/2008/01/12/mambo-mambo-search-denial-of-servic/#comments</comments>
		<pubDate>Sat, 12 Jan 2008 09:16:34 +0000</pubDate>
		<dc:creator>Guardian</dc:creator>
		
		<category><![CDATA[Mambo]]></category>

		<guid isPermaLink="false">http://wiki.code-authors.com/2008/01/12/mambo-mambo-search-denial-of-servic/</guid>
		<description><![CDATA[TITLE:
Mambo Search Denial of Service
SECUNIA ADVISORY ID:
SA28392
VERIFY ADVISORY:
http://secunia.com/advisories/28392/
CRITICAL:
Less critical
IMPACT:
DoS
WHERE:
From remote
SOFTWARE:
Mambo 4.x
http://secunia.com/product/872/
DESCRIPTION:
A vulnerability has been reported in Mambo, which can be exploited by
malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an unspecified error in the search
component and module, which can be exploited to use lots of system
resources. No further information [...]]]></description>
		<wfw:commentRss>http://wiki.code-authors.com/2008/01/12/mambo-mambo-search-denial-of-servic/feed/</wfw:commentRss>
		</item>
		<item>
		<title>[Joomla] Joomla! Cross-Site Request Forgery and Script Insertion Vulnerabilitie</title>
		<link>http://wiki.code-authors.com/2008/01/10/joomla-joomla-cross-site-request-forgery-and-script-insertion-vulnerabilitie/</link>
		<comments>http://wiki.code-authors.com/2008/01/10/joomla-joomla-cross-site-request-forgery-and-script-insertion-vulnerabilitie/#comments</comments>
		<pubDate>Thu, 10 Jan 2008 21:25:41 +0000</pubDate>
		<dc:creator>Guardian</dc:creator>
		
		<category><![CDATA[Joomla]]></category>

		<guid isPermaLink="false">http://wiki.code-authors.com/2008/01/10/joomla-joomla-cross-site-request-forgery-and-script-insertion-vulnerabilitie/</guid>
		<description><![CDATA[TITLE:
Joomla! Cross-Site Request Forgery and Script Insertion
Vulnerabilities
SECUNIA ADVISORY ID:
SA28219
VERIFY ADVISORY:
http://secunia.com/advisories/28219/
CRITICAL:
Less critical
IMPACT:
Cross Site Scripting
WHERE:
From remote
SOFTWARE:
Joomla! 1.x
http://secunia.com/product/5788/
DESCRIPTION:
Some vulnerabilities have been reported in Joomla!, which can be
exploited by malicious users to conduct script insertion attacks and
by malicious people to conduct cross-site request forgery attacks.
1) Some vulnerabilities are caused due to various components and
modules for Joomla! allowing users to [...]]]></description>
		<wfw:commentRss>http://wiki.code-authors.com/2008/01/10/joomla-joomla-cross-site-request-forgery-and-script-insertion-vulnerabilitie/feed/</wfw:commentRss>
		</item>
		<item>
		<title>[RunCms] RunCms newbb_plus &#8220;Client-IP&#8221; SQL Injectio</title>
		<link>http://wiki.code-authors.com/2008/01/10/runcms-runcms-newbb_plus-client-ip-sql-injectio/</link>
		<comments>http://wiki.code-authors.com/2008/01/10/runcms-runcms-newbb_plus-client-ip-sql-injectio/#comments</comments>
		<pubDate>Thu, 10 Jan 2008 21:25:41 +0000</pubDate>
		<dc:creator>Guardian</dc:creator>
		
		<category><![CDATA[RunCms]]></category>

		<guid isPermaLink="false">http://wiki.code-authors.com/2008/01/10/runcms-runcms-newbb_plus-client-ip-sql-injectio/</guid>
		<description><![CDATA[TITLE:
RunCms newbb_plus &#8220;Client-IP&#8221; SQL Injection
SECUNIA ADVISORY ID:
SA28340
VERIFY ADVISORY:
http://secunia.com/advisories/28340/
CRITICAL:
Moderately critical
IMPACT:
Manipulation of data
WHERE:
From remote
SOFTWARE:
RunCms 1.x
http://secunia.com/product/4808/
DESCRIPTION:
gemaglabin and Elekt have discovered a vulnerability in RunCms, which
can be exploited by malicious people to conduct SQL injection
attacks.
Input passed in the &#8220;Client-IP&#8221; HTTP header to
modules/newbb_plus/index.php is not properly sanitised before being
used in SQL queries. This can be exploited to manipulate SQL queries
by [...]]]></description>
		<wfw:commentRss>http://wiki.code-authors.com/2008/01/10/runcms-runcms-newbb_plus-client-ip-sql-injectio/feed/</wfw:commentRss>
		</item>
		<item>
		<title>[SmallNuke] &#8220;user_email&#8221; SQL Injection Vulnerabilit</title>
		<link>http://wiki.code-authors.com/2008/01/09/smallnuke-user_email-sql-injection-vulnerabilit/</link>
		<comments>http://wiki.code-authors.com/2008/01/09/smallnuke-user_email-sql-injection-vulnerabilit/#comments</comments>
		<pubDate>Wed, 09 Jan 2008 14:03:28 +0000</pubDate>
		<dc:creator>Guardian</dc:creator>
		
		<category><![CDATA[SmallNuke]]></category>

		<guid isPermaLink="false">http://wiki.code-authors.com/2008/01/09/smallnuke-user_email-sql-injection-vulnerabilit/</guid>
		<description><![CDATA[TITLE:
SmallNuke &#8220;user_email&#8221; SQL Injection Vulnerability
SECUNIA ADVISORY ID:
SA28301
VERIFY ADVISORY:
http://secunia.com/advisories/28301/
CRITICAL:
Moderately critical
IMPACT:
Manipulation of data
WHERE:
From remote
SOFTWARE:
SmallNuke 2.x
http://secunia.com/product/17115/
DESCRIPTION:
Eugene Minaev has discovered a vulnerability in SmallNuke, which can
be exploited by malicious people to conduct SQL injection attacks.
Input passed to the &#8220;user_email&#8221; parameter in index.php is not
properly sanitised before being used in SQL queries. This can be
exploited to manipulate SQL queries by [...]]]></description>
		<wfw:commentRss>http://wiki.code-authors.com/2008/01/09/smallnuke-user_email-sql-injection-vulnerabilit/feed/</wfw:commentRss>
		</item>
		<item>
		<title>[XOOPS] &#8220;b_system_comments_show()&#8221; Security Bypas</title>
		<link>http://wiki.code-authors.com/2008/01/04/xoops-b_system_comments_show-security-bypas/</link>
		<comments>http://wiki.code-authors.com/2008/01/04/xoops-b_system_comments_show-security-bypas/#comments</comments>
		<pubDate>Fri, 04 Jan 2008 17:13:18 +0000</pubDate>
		<dc:creator>Guardian</dc:creator>
		
		<category><![CDATA[Xoops]]></category>

		<guid isPermaLink="false">http://wiki.code-authors.com/2008/01/04/xoops-b_system_comments_show-security-bypas/</guid>
		<description><![CDATA[TITLE:
XOOPS &#8220;b_system_comments_show()&#8221; Security Bypass
SECUNIA ADVISORY ID:
SA28264
VERIFY ADVISORY:
http://secunia.com/advisories/28264/
CRITICAL:
Not critical
IMPACT:
Security Bypass
WHERE:
From remote
SOFTWARE:
Xoops 2.x
http://secunia.com/product/327/
DESCRIPTION:
A weakness has been reported in XOOPS, which can be exploited by
malicious users to bypass certain security restrictions.
The weakness is caused due to missing permission checks within the
&#8220;b_system_comments_show()&#8221; function in
htdocs/modules/system/blocks/system_blocks.php. This can be exploited
to read the comments of restricted modules.
The weakness is reported in versions [...]]]></description>
		<wfw:commentRss>http://wiki.code-authors.com/2008/01/04/xoops-b_system_comments_show-security-bypas/feed/</wfw:commentRss>
		</item>
		<item>
		<title>[phpWebSite] &#8220;search&#8221; Cross-Site Scripting Vulnerabilit</title>
		<link>http://wiki.code-authors.com/2008/01/04/phpwebsite-search-cross-site-scripting-vulnerabilit/</link>
		<comments>http://wiki.code-authors.com/2008/01/04/phpwebsite-search-cross-site-scripting-vulnerabilit/#comments</comments>
		<pubDate>Fri, 04 Jan 2008 17:13:18 +0000</pubDate>
		<dc:creator>Guardian</dc:creator>
		
		<category><![CDATA[phpWebSite]]></category>

		<guid isPermaLink="false">http://wiki.code-authors.com/2008/01/04/phpwebsite-search-cross-site-scripting-vulnerabilit/</guid>
		<description><![CDATA[TITLE:
phpWebSite &#8220;search&#8221; Cross-Site Scripting Vulnerability
SECUNIA ADVISORY ID:
SA28303
VERIFY ADVISORY:
http://secunia.com/advisories/28303/
CRITICAL:
Less critical
IMPACT:
Cross Site Scripting
WHERE:
From remote
SOFTWARE:
phpWebSite 0.x
http://secunia.com/product/297/
phpWebSite 1.x
http://secunia.com/product/17067/
DESCRIPTION:
Audun Larsen has discovered a vulnerability in phpWebSite, which can
be exploited by malicious people to conduct cross-site scripting
attacks.
Input passed to the &#8220;search&#8221; parameter in the search module is not
properly sanitised before being returned to the user. This can be
exploited to execute arbitrary [...]]]></description>
		<wfw:commentRss>http://wiki.code-authors.com/2008/01/04/phpwebsite-search-cross-site-scripting-vulnerabilit/feed/</wfw:commentRss>
		</item>
		<item>
		<title>[PHP] Multiple Vulnerabilitie</title>
		<link>http://wiki.code-authors.com/2008/01/04/php-multiple-vulnerabilitie/</link>
		<comments>http://wiki.code-authors.com/2008/01/04/php-multiple-vulnerabilitie/#comments</comments>
		<pubDate>Fri, 04 Jan 2008 17:13:18 +0000</pubDate>
		<dc:creator>Guardian</dc:creator>
		
		<category><![CDATA[PHP]]></category>

		<guid isPermaLink="false">http://wiki.code-authors.com/2008/01/04/php-multiple-vulnerabilitie/</guid>
		<description><![CDATA[TITLE:
PHP Multiple Vulnerabilities
SECUNIA ADVISORY ID:
SA28318
VERIFY ADVISORY:
http://secunia.com/advisories/28318/
CRITICAL:
Moderately critical
IMPACT:
Unknown, Security Bypass
WHERE:
From remote
SOFTWARE:
PHP 4.4.x
http://secunia.com/product/5768/
DESCRIPTION:
Some vulnerabilities have been reported in PHP, where some have
unknown impact and others can be exploited by malicious users to
bypass certain security restrictions.
1) An integer overflow error exists in the &#8220;chunk_split()&#8221; function.
This may be related to vulnerability #1 in:
SA25456
2) Integer overflow errors exists in the [...]]]></description>
		<wfw:commentRss>http://wiki.code-authors.com/2008/01/04/php-multiple-vulnerabilitie/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
