<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Exabytes Security Portal</title>
	<link>http://security.exabytes.com</link>
	<description>Exabytes Security Portal</description>
	<pubDate>Mon, 05 May 2008 00:11:28 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
	<language>en</language>
			<item>
		<title>eGroupWare File Upload</title>
		<link>http://security.exabytes.com/2008/04/egroupware-file-upload.html</link>
		<comments>http://security.exabytes.com/2008/04/egroupware-file-upload.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 10:10:05 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[File Inclusion]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/egroupware-file-upload.html</guid>
		<description><![CDATA[Application: eGroupWare
Affected Version: prior to 1.4.004.
Vendor’s URL: eGroupWare
Bug Type: File Inclusion
Risk Level: Critical
Solution:
Update to version 1.4.004.
]]></description>
			<content:encoded><![CDATA[<p>Application: eGroupWare<br />
Affected Version: prior to 1.4.004.<br />
Vendor’s URL: <a href="http://www.egroupware.org/">eGroupWare</a><br />
Bug Type: File Inclusion<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 1.4.004.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/egroupware-file-upload.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla Jom Comment Component Unspecified SQL Injection</title>
		<link>http://security.exabytes.com/2008/04/joomla-jom-comment-component-unspecified-sql-injection.html</link>
		<comments>http://security.exabytes.com/2008/04/joomla-jom-comment-component-unspecified-sql-injection.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 10:08:26 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/joomla-jom-comment-component-unspecified-sql-injection.html</guid>
		<description><![CDATA[Application: Joomla Jom Comment Component
Affected Version: version 2.0 and other versions.
Vendor’s URL: Joomla Jom Comment Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 2.2.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla Jom Comment Component<br />
Affected Version: version 2.0 and other versions.<br />
Vendor’s URL: <a href="http://www.azrul.com/products/joomla_comment_system.html">Joomla Jom Comment Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 2.2.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/joomla-jom-comment-component-unspecified-sql-injection.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>WordPress WP-Download Plugin SQL Injection</title>
		<link>http://security.exabytes.com/2008/04/wordpress-wp-download-plugin-sql-injection.html</link>
		<comments>http://security.exabytes.com/2008/04/wordpress-wp-download-plugin-sql-injection.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 10:07:06 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/wordpress-wp-download-plugin-sql-injection.html</guid>
		<description><![CDATA[Application: WordPress WP-Download Plugin
Affected Version: 1.2 and other versions.
Vendor’s URL: WordPress WP-Download Plugin
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 1.2.1.
]]></description>
			<content:encoded><![CDATA[<p>Application: WordPress WP-Download Plugin<br />
Affected Version: 1.2 and other versions.<br />
Vendor’s URL: <a href="http://www.arno-box.net/wordpress/12/wordpress-plugin-wp-download/">WordPress WP-Download Plugin</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 1.2.1.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/wordpress-wp-download-plugin-sql-injection.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>AuraCMS SQL Injection</title>
		<link>http://security.exabytes.com/2008/04/auracms-sql-injection.html</link>
		<comments>http://security.exabytes.com/2008/04/auracms-sql-injection.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 10:05:37 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/auracms-sql-injection.html</guid>
		<description><![CDATA[Application: AuraCMS
Affected Version: 2.2.1 and other versions.
Vendor’s URL: AuraCMS
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitized.
]]></description>
			<content:encoded><![CDATA[<p>Application: AuraCMS<br />
Affected Version: 2.2.1 and other versions.<br />
Vendor’s URL: <a href="http://www.auracms.org/">AuraCMS</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitized.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/auracms-sql-injection.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Simple Gallery XSS</title>
		<link>http://security.exabytes.com/2008/04/simple-gallery-xss.html</link>
		<comments>http://security.exabytes.com/2008/04/simple-gallery-xss.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 10:04:24 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Cross Site Scripting]]></category>

		<category><![CDATA[Image Galleries]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/simple-gallery-xss.html</guid>
		<description><![CDATA[Application: Simple Gallery
Affected Version: 2.2 and other versions.
Vendor’s URL: Simple Gallery
Bug Type: Cross Site Scripting
Risk Level: Medium
Solution:
Edit the source code to ensure that input is properly sanitized.
]]></description>
			<content:encoded><![CDATA[<p>Application: Simple Gallery<br />
Affected Version: 2.2 and other versions.<br />
Vendor’s URL: <a href="http://www.celerondude.com/php-simple-gallery">Simple Gallery</a><br />
Bug Type: Cross Site Scripting<br />
Risk Level: Medium</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitized.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/simple-gallery-xss.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Drupal Webform Module Unspecified Script Insertion</title>
		<link>http://security.exabytes.com/2008/04/drupal-webform-module-unspecified-script-insertion.html</link>
		<comments>http://security.exabytes.com/2008/04/drupal-webform-module-unspecified-script-insertion.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 10:03:00 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/drupal-webform-module-unspecified-script-insertion.html</guid>
		<description><![CDATA[Application: Drupal Webform Module
Affected Version: prior to version 5.x-1.10.
Vendor’s URL: Drupal Webform Module
Bug Type: Script Insertion
Risk Level: Critical
Solution:
Update to version 5.x-1.10.
]]></description>
			<content:encoded><![CDATA[<p>Application: Drupal Webform Module<br />
Affected Version: prior to version 5.x-1.10.<br />
Vendor’s URL: <a href="http://drupal.org/project/webform">Drupal Webform Module</a><br />
Bug Type: Script Insertion<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 5.x-1.10.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/drupal-webform-module-unspecified-script-insertion.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>PHP Photo Gallery SQL Injection</title>
		<link>http://security.exabytes.com/2008/04/php-photo-gallery-sql-injection.html</link>
		<comments>http://security.exabytes.com/2008/04/php-photo-gallery-sql-injection.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 10:01:14 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Image Galleries]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/php-photo-gallery-sql-injection.html</guid>
		<description><![CDATA[Application: PHP Photo Gallery
Affected Version:
Vendor’s URL: PHP Photo Gallery
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitized.
]]></description>
			<content:encoded><![CDATA[<p>Application: PHP Photo Gallery<br />
Affected Version:<br />
Vendor’s URL: <a href="http://www.terong.com/products/advanced-photo-gallery/">PHP Photo Gallery</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitized.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/php-photo-gallery-sql-injection.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Wikepage Information Disclosure</title>
		<link>http://security.exabytes.com/2008/04/wikepage-information-disclosure.html</link>
		<comments>http://security.exabytes.com/2008/04/wikepage-information-disclosure.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:56:31 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[Information Disclosure]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/wikepage-information-disclosure.html</guid>
		<description><![CDATA[Application: Wikepage
Affected Version: version Opus 13 2007.2 and other versions.
Vendor’s URL: Wikepage
Bug Type: Information Disclosure
Risk Level: Medium
Solution:
Edit the source code to ensure that input is properly sanitized.
]]></description>
			<content:encoded><![CDATA[<p>Application: Wikepage<br />
Affected Version: version Opus 13 2007.2 and other versions.<br />
Vendor’s URL: <a href="http://wikepage.org/">Wikepage</a><br />
Bug Type: Information Disclosure<br />
Risk Level: Medium</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitized.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/wikepage-information-disclosure.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Drupal Menu System Security Bypass</title>
		<link>http://security.exabytes.com/2008/04/drupal-menu-system-security-bypass.html</link>
		<comments>http://security.exabytes.com/2008/04/drupal-menu-system-security-bypass.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:54:52 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Access Bypass]]></category>

		<category><![CDATA[Content Management]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/drupal-menu-system-security-bypass.html</guid>
		<description><![CDATA[Application: Drupal Menu System
Affected Version: 6.2 and prior versions.
Vendor’s URL: Drupal Menu System
Bug Type: Security Bypass
Risk Level: Critical
Solution:
Update to Drupal 6.2 or apply patch.
]]></description>
			<content:encoded><![CDATA[<p>Application: Drupal Menu System<br />
Affected Version: 6.2 and prior versions.<br />
Vendor’s URL: <a href="http://drupal.org/">Drupal Menu System</a><br />
Bug Type: Security Bypass<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to Drupal 6.2 or apply patch.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/drupal-menu-system-security-bypass.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Gallery Script Lite Information Disclosure</title>
		<link>http://security.exabytes.com/2008/04/gallery-script-lite-information-disclosure.html</link>
		<comments>http://security.exabytes.com/2008/04/gallery-script-lite-information-disclosure.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:49:42 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Image Galleries]]></category>

		<category><![CDATA[Information Disclosure]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/gallery-script-lite-information-disclosure.html</guid>
		<description><![CDATA[Application: Gallery Script Lite
Affected Version:
Vendor’s URL: Gallery Script Lite
Bug Type: Information Disclosure
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitized.
]]></description>
			<content:encoded><![CDATA[<p>Application: Gallery Script Lite<br />
Affected Version:<br />
Vendor’s URL: <a href="http://www.arwscripts.com/gallery-script-lite.html">Gallery Script Lite</a><br />
Bug Type: Information Disclosure<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitized.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/gallery-script-lite-information-disclosure.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>KnowledgeQuest SQL Injection and Security Bypass</title>
		<link>http://security.exabytes.com/2008/04/knowledgequest-sql-injection-and-security-bypass.html</link>
		<comments>http://security.exabytes.com/2008/04/knowledgequest-sql-injection-and-security-bypass.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:47:37 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Access Bypass]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/knowledgequest-sql-injection-and-security-bypass.html</guid>
		<description><![CDATA[Application: KnowledgeQuest
Affected Version: 2.6 and other versions.
Vendor’s URL: KnowledgeQuest
Bug Type: Security Bypass
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitized. Restrict access to the admincheck.php
]]></description>
			<content:encoded><![CDATA[<p>Application: KnowledgeQuest<br />
Affected Version: 2.6 and other versions.<br />
Vendor’s URL: <a href="http://www.myknowledgequest.com/">KnowledgeQuest</a><br />
Bug Type: Security Bypass<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitized. Restrict access to the admincheck.php</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/knowledgequest-sql-injection-and-security-bypass.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Drupal Simple Access Module Security Bypass</title>
		<link>http://security.exabytes.com/2008/04/drupal-simple-access-module-security-bypass.html</link>
		<comments>http://security.exabytes.com/2008/04/drupal-simple-access-module-security-bypass.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:46:05 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Access Bypass]]></category>

		<category><![CDATA[Content Management]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/drupal-simple-access-module-security-bypass.html</guid>
		<description><![CDATA[Application: Drupal Simple Access Module
Affected Version: 5.x-1.2-2 and prior versions.
Vendor’s URL: Drupal Simple Access Module
Bug Type: Access bypass
Risk Level: Critical
Solution:
Update to version 5.x-1.3.
]]></description>
			<content:encoded><![CDATA[<p>Application: Drupal Simple Access Module<br />
Affected Version: 5.x-1.2-2 and prior versions.<br />
Vendor’s URL: <a href="http://drupal.org/project/simple_access">Drupal Simple Access Module</a><br />
Bug Type: Access bypass<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 5.x-1.3.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/drupal-simple-access-module-security-bypass.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>LiveCart SQL Injection Vulnerability</title>
		<link>http://security.exabytes.com/2008/04/livecart-sql-injection-vulnerability.html</link>
		<comments>http://security.exabytes.com/2008/04/livecart-sql-injection-vulnerability.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:44:47 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/livecart-sql-injection-vulnerability.html</guid>
		<description><![CDATA[Application: LiveCart
Affected Version: 1.1.1 trial version and other versions.
Vendor’s URL: LiveCart
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitized.
]]></description>
			<content:encoded><![CDATA[<p>Application: LiveCart<br />
Affected Version: 1.1.1 trial version and other versions.<br />
Vendor’s URL: <a href="http://livecart.com/">LiveCart</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitized.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/livecart-sql-injection-vulnerability.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>KwsPHP ConcoursPhoto Module SQL Injection</title>
		<link>http://security.exabytes.com/2008/04/kwsphp-concoursphoto-module-sql-injection.html</link>
		<comments>http://security.exabytes.com/2008/04/kwsphp-concoursphoto-module-sql-injection.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:43:28 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Image Galleries]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/kwsphp-concoursphoto-module-sql-injection.html</guid>
		<description><![CDATA[Application: KwsPHP ConcoursPhoto Module
Affected Version: 2.0 and prior version.
Vendor’s URL: KwsPHP ConcoursPhoto Module
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 2.1.
]]></description>
			<content:encoded><![CDATA[<p>Application: KwsPHP ConcoursPhoto Module<br />
Affected Version: 2.0 and prior version.<br />
Vendor’s URL: <a href="http://nazfree.free.fr/pwsphp/mods/">KwsPHP ConcoursPhoto Module</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 2.1.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/kwsphp-concoursphoto-module-sql-injection.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Coppermine Photo Gallery SQL Injection</title>
		<link>http://security.exabytes.com/2008/04/coppermine-photo-gallery-sql-injection-2.html</link>
		<comments>http://security.exabytes.com/2008/04/coppermine-photo-gallery-sql-injection-2.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:42:19 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Image Galleries]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/coppermine-photo-gallery-sql-injection-2.html</guid>
		<description><![CDATA[Application: Coppermine Photo Gallery
Affected Version: 1.4.16 and other versions.
Vendor’s URL: Coppermine Photo Gallery
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 1.4.17.
]]></description>
			<content:encoded><![CDATA[<p>Application: Coppermine Photo Gallery<br />
Affected Version: 1.4.16 and other versions.<br />
Vendor’s URL: <a href="http://coppermine-gallery.net/">Coppermine Photo Gallery</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 1.4.17.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/coppermine-photo-gallery-sql-injection-2.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>NewsOffice File Inclusion Vulnerability</title>
		<link>http://security.exabytes.com/2008/04/newsoffice-file-inclusion-vulnerability.html</link>
		<comments>http://security.exabytes.com/2008/04/newsoffice-file-inclusion-vulnerability.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:41:09 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[File Inclusion]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/newsoffice-file-inclusion-vulnerability.html</guid>
		<description><![CDATA[Application: NewsOffice
Affected Version: 1.1 and prior versions.
Vendor’s URL: NewsOffice
Bug Type: File Inclusion
Risk Level: Critical
Solution:
Update to version 1.1.1.
]]></description>
			<content:encoded><![CDATA[<p>Application: NewsOffice<br />
Affected Version: 1.1 and prior versions.<br />
Vendor’s URL: <a href="http://www.newanz.com/applications/NewsOffice/">NewsOffice</a><br />
Bug Type: File Inclusion<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 1.1.1.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/newsoffice-file-inclusion-vulnerability.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>phpkb Knowledge Base SQL Injection</title>
		<link>http://security.exabytes.com/2008/04/phpkb-knowledge-base-sql-injection.html</link>
		<comments>http://security.exabytes.com/2008/04/phpkb-knowledge-base-sql-injection.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:39:57 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/phpkb-knowledge-base-sql-injection.html</guid>
		<description><![CDATA[Application: phpkb Knowledge Base
Affected Version: 1.5 and 2.0 and other versions.
Vendor’s URL: phpkb Knowledge Base
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitized.
]]></description>
			<content:encoded><![CDATA[<p>Application: phpkb Knowledge Base<br />
Affected Version: 1.5 and 2.0 and other versions.<br />
Vendor’s URL: <a href="http://www.knowledgebase-script.com/">phpkb Knowledge Base</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitized.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/phpkb-knowledge-base-sql-injection.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>1024 CMS SQL Injection and File Inclusion</title>
		<link>http://security.exabytes.com/2008/04/1024-cms-sql-injection-and-file-inclusion.html</link>
		<comments>http://security.exabytes.com/2008/04/1024-cms-sql-injection-and-file-inclusion.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:38:42 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[File Inclusion]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/1024-cms-sql-injection-and-file-inclusion.html</guid>
		<description><![CDATA[Application: 1024 CMS
Affected Version: 1.4.1 and other versions.
Vendor’s URL: 1024 CMS
Bug Type: SQL Injection, File Inclusion
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitized and verified.
]]></description>
			<content:encoded><![CDATA[<p>Application: 1024 CMS<br />
Affected Version: 1.4.1 and other versions.<br />
Vendor’s URL: <a href="http://1024cms.com/index.php">1024 CMS</a><br />
Bug Type: SQL Injection, File Inclusion<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitized and verified.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/1024-cms-sql-injection-and-file-inclusion.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>cpCommerce Multiple Vulnerabilities</title>
		<link>http://security.exabytes.com/2008/04/cpcommerce-multiple-vulnerabilities.html</link>
		<comments>http://security.exabytes.com/2008/04/cpcommerce-multiple-vulnerabilities.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:37:18 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Cross Site Scripting]]></category>

		<category><![CDATA[E-Commerce]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/cpcommerce-multiple-vulnerabilities.html</guid>
		<description><![CDATA[Application: cpCommerce
Affected Version: 1.1.0 and other versions.
Vendor’s URL: cpCommerce
Bug Type: Cross Site Scripting and SQL injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitized and verified.
]]></description>
			<content:encoded><![CDATA[<p>Application: cpCommerce<br />
Affected Version: 1.1.0 and other versions.<br />
Vendor’s URL: <a href="http://cpcommerce.cpradio.org/">cpCommerce</a><br />
Bug Type: Cross Site Scripting and SQL injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitized and verified.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/cpcommerce-multiple-vulnerabilities.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Coppermine Photo Gallery SQL Injection</title>
		<link>http://security.exabytes.com/2008/04/coppermine-photo-gallery-sql-injection.html</link>
		<comments>http://security.exabytes.com/2008/04/coppermine-photo-gallery-sql-injection.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:35:29 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Image Galleries]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/coppermine-photo-gallery-sql-injection.html</guid>
		<description><![CDATA[Application: Coppermine Photo Gallery
Affected Version: 1.4.17 and other versions.
Vendor’s URL: Coppermine Photo Gallery
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 1.4.18.
]]></description>
			<content:encoded><![CDATA[<p>Application: Coppermine Photo Gallery<br />
Affected Version: 1.4.17 and other versions.<br />
Vendor’s URL: <a href="http://coppermine-gallery.net/">Coppermine Photo Gallery</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 1.4.18.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/coppermine-photo-gallery-sql-injection.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>phpBB Security Bypass Vulnerabilities</title>
		<link>http://security.exabytes.com/2008/04/phpbb-security-bypass-vulnerabilities.html</link>
		<comments>http://security.exabytes.com/2008/04/phpbb-security-bypass-vulnerabilities.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:34:06 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Access Bypass]]></category>

		<category><![CDATA[Discussion Boards]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/phpbb-security-bypass-vulnerabilities.html</guid>
		<description><![CDATA[Application: phpBB
Affected Version: 3.0.0.
Vendor’s URL: phpBB
Bug Type: Access Bypass
Risk Level: Critical
Solution:
Update to version 3.0.1.
]]></description>
			<content:encoded><![CDATA[<p>Application: phpBB<br />
Affected Version: 3.0.0.<br />
Vendor’s URL: <a href="http://www.phpbb.com/">phpBB</a><br />
Bug Type: Access Bypass<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 3.0.1.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/phpbb-security-bypass-vulnerabilities.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>OSI Affiliate XSS</title>
		<link>http://security.exabytes.com/2008/04/osi-affiliate-xss.html</link>
		<comments>http://security.exabytes.com/2008/04/osi-affiliate-xss.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:32:28 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Cross Site Scripting]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/osi-affiliate-xss.html</guid>
		<description><![CDATA[Application: OSI Affiliate
Affected Version:
Vendor’s URL: OSI Affiliate
Bug Type: Cross Site Scripting
Risk Level: Medium
Solution:
Edit the source code to ensure that input is properly sanitized.
]]></description>
			<content:encoded><![CDATA[<p>Application: OSI Affiliate<br />
Affected Version:<br />
Vendor’s URL: <a href="http://www.osiaffiliate.com/">OSI Affiliate</a><br />
Bug Type: Cross Site Scripting<br />
Risk Level: Medium</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitized.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/osi-affiliate-xss.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>CubeCart Two XSS</title>
		<link>http://security.exabytes.com/2008/04/cubecart-two-xss.html</link>
		<comments>http://security.exabytes.com/2008/04/cubecart-two-xss.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:31:03 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Cross Site Scripting]]></category>

		<category><![CDATA[E-Commerce]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/cubecart-two-xss.html</guid>
		<description><![CDATA[Application: CubeCart
Affected Version: 4.2.1 and other versions.
Vendor’s URL: CubeCart
Bug Type: Cross Site Scripting
Risk Level: Medium
Solution:
Edit the source code to ensure that input is properly sanitized.
]]></description>
			<content:encoded><![CDATA[<p>Application: CubeCart<br />
Affected Version: 4.2.1 and other versions.<br />
Vendor’s URL: <a href="http://www.cubecart.com/">CubeCart</a><br />
Bug Type: Cross Site Scripting<br />
Risk Level: Medium</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitized.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/cubecart-two-xss.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>RunCMS Photo Module SQL Injection</title>
		<link>http://security.exabytes.com/2008/04/runcms-photo-module-sql-injection.html</link>
		<comments>http://security.exabytes.com/2008/04/runcms-photo-module-sql-injection.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:29:34 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/runcms-photo-module-sql-injection.html</guid>
		<description><![CDATA[Application: RunCMS Photo Module
Affected Version: 3.02 and other versions.
Vendor’s URL: RunCMS Photo Module
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitized.
]]></description>
			<content:encoded><![CDATA[<p>Application: RunCMS Photo Module<br />
Affected Version: 3.02 and other versions.<br />
Vendor’s URL: <a href="http://runcms.org/modules/mydownloads/singlefile_lid_65.html">RunCMS Photo Module</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitized.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/runcms-photo-module-sql-injection.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>e107 my_gallery Plugin Information Disclosure</title>
		<link>http://security.exabytes.com/2008/04/e107-my_gallery-plugin-information-disclosure.html</link>
		<comments>http://security.exabytes.com/2008/04/e107-my_gallery-plugin-information-disclosure.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:27:24 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Image Galleries]]></category>

		<category><![CDATA[Information Disclosure]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/e107-my_gallery-plugin-information-disclosure.html</guid>
		<description><![CDATA[Application: e107 my_gallery Plugin
Affected Version: 2.3 and other versions.
Vendor’s URL: e107 my_gallery
Bug Type: Information Disclosure
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitized.
]]></description>
			<content:encoded><![CDATA[<p>Application: e107 my_gallery Plugin<br />
Affected Version: 2.3 and other versions.<br />
Vendor’s URL: <a href="http://plugins.e107.org/e107_plugins/psilo/psilo.php?artifact.208">e107 my_gallery</a><br />
Bug Type: Information Disclosure<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitized.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/e107-my_gallery-plugin-information-disclosure.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Photo Cart &#8220;amessage&#8221; XSS</title>
		<link>http://security.exabytes.com/2008/04/photo-cart-amessage-xss.html</link>
		<comments>http://security.exabytes.com/2008/04/photo-cart-amessage-xss.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:25:27 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Cross Site Scripting]]></category>

		<category><![CDATA[E-Commerce]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/photo-cart-amessage-xss.html</guid>
		<description><![CDATA[Application: Photo Cart
Affected Version: 4.1 and other versions.
Vendor’s URL: Photo Cart
Bug Type: Cross Site Scripting
Risk Level: Medium
Solution:
Apply patch. http://www.picturespro.com/sp/
]]></description>
			<content:encoded><![CDATA[<p>Application: Photo Cart<br />
Affected Version: 4.1 and other versions.<br />
Vendor’s URL: <a href="http://www.picturespro.com/pages/photography_shopping_cart/index.html">Photo Cart</a><br />
Bug Type: Cross Site Scripting<br />
Risk Level: Medium</p>
<p>Solution:<br />
Apply patch. <a href="http://www.picturespro.com/sp/">http://www.picturespro.com/sp/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/photo-cart-amessage-xss.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla rekry!Joom Component SQL Injection</title>
		<link>http://security.exabytes.com/2008/04/joomla-rekryjoom-component-sql-injection.html</link>
		<comments>http://security.exabytes.com/2008/04/joomla-rekryjoom-component-sql-injection.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:23:36 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/joomla-rekryjoom-component-sql-injection.html</guid>
		<description><![CDATA[Application: Joomla rekry!Joom Component
Affected Version: 1.0.0 and other versions.
Vendor’s URL: Joomla rekry!Joom Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitized.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla rekry!Joom Component<br />
Affected Version: 1.0.0 and other versions.<br />
Vendor’s URL: <a href="http://dev.teknologiaplaneetta.com/confluence/display/JOOMLA/rekry%21Joom">Joomla rekry!Joom Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitized.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/joomla-rekryjoom-component-sql-injection.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla Custompages Component File Inclusion</title>
		<link>http://security.exabytes.com/2008/04/joomla-custompages-component-file-inclusion.html</link>
		<comments>http://security.exabytes.com/2008/04/joomla-custompages-component-file-inclusion.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:21:58 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Access Bypass]]></category>

		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[File Inclusion]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/joomla-custompages-component-file-inclusion.html</guid>
		<description><![CDATA[Application: Joomla
Affected Version: 1.1 and other versions.
Vendor’s URL: Joomla Custompages Component
Bug Type: access bypass, file inclusion
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly verified.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: 1.1 and other versions.<br />
Vendor’s URL: <a href="http://sstreamtv.com/index.php?option=com_docman&#038;task=cat_view&#038;gid=31&#038;Itemid=2">Joomla Custompages Component</a><br />
Bug Type: access bypass, file inclusion<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly verified.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/joomla-custompages-component-file-inclusion.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>DotNetNuke Multiple Vulnerabilities</title>
		<link>http://security.exabytes.com/2008/04/dotnetnuke-multiple-vulnerabilities.html</link>
		<comments>http://security.exabytes.com/2008/04/dotnetnuke-multiple-vulnerabilities.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:19:13 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Access Bypass]]></category>

		<category><![CDATA[Discussion Boards]]></category>

		<category><![CDATA[Privilege Escalation]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/dotnetnuke-multiple-vulnerabilities.html</guid>
		<description><![CDATA[Application: DotNetNuke
Affected Version: version prior to 4.8.2.
Vendor’s URL: http://www.dotnetnuke.com/
Bug Type: Privilege escalation, access bypass
Risk Level: Critical
Solution:
Update to version 4.8.2.
http://www.dotnetnuke.com/tabid/125/default.aspx
]]></description>
			<content:encoded><![CDATA[<p>Application: DotNetNuke<br />
Affected Version: version prior to 4.8.2.<br />
Vendor’s URL: <a href="http://www.dotnetnuke.com/">http://www.dotnetnuke.com/</a><br />
Bug Type: Privilege escalation, access bypass<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 4.8.2.<br />
<a href="http://www.dotnetnuke.com/tabid/125/default.aspx">http://www.dotnetnuke.com/tabid/125/default.aspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/dotnetnuke-multiple-vulnerabilities.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>phpAddressBook Multiple Vulnerabilities</title>
		<link>http://security.exabytes.com/2008/04/phpaddressbook-multiple-vulnerabilities.html</link>
		<comments>http://security.exabytes.com/2008/04/phpaddressbook-multiple-vulnerabilities.html#comments</comments>
		<pubDate>Fri, 18 Apr 2008 09:16:21 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Cross Site Scripting]]></category>

		<category><![CDATA[File Inclusion]]></category>

		<category><![CDATA[Information Disclosure]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/2008/04/phpaddressbook-multiple-vulnerabilities.html</guid>
		<description><![CDATA[Application: phpAddressBook
Affected Version: 2.11 and other versions.
Vendor’s URL: phpAddressBook
Bug Type: Cross Site Scripting and file inclusion
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly verified and sanitized.
]]></description>
			<content:encoded><![CDATA[<p>Application: phpAddressBook<br />
Affected Version: 2.11 and other versions.<br />
Vendor’s URL: <a href="http://www.coronamatrix.org/Projects/1-phpAddressBook">phpAddressBook</a><br />
Bug Type: Cross Site Scripting and file inclusion<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly verified and sanitized.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2008/04/phpaddressbook-multiple-vulnerabilities.html/feed</wfw:commentRss>
		</item>
	</channel>
</rss>
