<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>Exabytes Security Portal</title>
	<atom:link href="http://security.exabytes.com/feed" rel="self" type="application/rss+xml" />
	<link>http://security.exabytes.com</link>
	<description>Exabytes Security Portal</description>
	<pubDate>Tue, 23 Feb 2010 08:27:06 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Joomla Community Polls Component &#8220;controller&#8221; File Inclusion</title>
		<link>http://security.exabytes.com/2010/02/joomla-community-polls-component-controller-file-inclusion.html</link>
		<comments>http://security.exabytes.com/2010/02/joomla-community-polls-component-controller-file-inclusion.html#comments</comments>
		<pubDate>Tue, 23 Feb 2010 08:27:06 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[File Inclusion]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5325</guid>
		<description><![CDATA[Application: Joomla
Affected Version: versions prior to 1.5.3.
Vendor’s URL: Community Polls Component
Bug Type: File Inclusion
Risk Level: Critical
Solution:
Update to version 1.5.3 or later.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: versions prior to 1.5.3.<br />
Vendor’s URL: <a href="http://www.corejoomla.com/products/core-joomla-community-polls.html">Community Polls Component</a><br />
Bug Type: File Inclusion<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 1.5.3 or later.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/02/joomla-community-polls-component-controller-file-inclusion.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Drupal Content Distribution Module Multiple Vulnerabilities</title>
		<link>http://security.exabytes.com/2010/02/drupal-content-distribution-module-multiple-vulnerabilities.html</link>
		<comments>http://security.exabytes.com/2010/02/drupal-content-distribution-module-multiple-vulnerabilities.html#comments</comments>
		<pubDate>Tue, 23 Feb 2010 08:25:45 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5323</guid>
		<description><![CDATA[Application: Drupal
Affected Version: versions prior to 6.x-1.3.
Vendor’s URL: Content Distribution Module
Bug Type:
Risk Level: Critical
Solution:
Update to version 6.x-1.3.
]]></description>
			<content:encoded><![CDATA[<p>Application: Drupal<br />
Affected Version: versions prior to 6.x-1.3.<br />
Vendor’s URL: <a href="http://drupal.org/project/content_distribution">Content Distribution Module</a><br />
Bug Type:<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to <a href="http://ftp.drupal.org/files/projects/content_distribution-6.x-1.3.tar.gz">version 6.x-1.3.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/02/drupal-content-distribution-module-multiple-vulnerabilities.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla! Core Design Scriptegrator Plugin Multiple File Inclusion</title>
		<link>http://security.exabytes.com/2010/02/joomla-core-design-scriptegrator-plugin-multiple-file-inclusion.html</link>
		<comments>http://security.exabytes.com/2010/02/joomla-core-design-scriptegrator-plugin-multiple-file-inclusion.html#comments</comments>
		<pubDate>Tue, 23 Feb 2010 08:22:52 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[File Inclusion]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5321</guid>
		<description><![CDATA[Application: Joomla!
Affected Version: version 1.4.1 and other versions.
Vendor’s URL: Core Design Scriptegrator Plugin
Bug Type: File Inclusion
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla!<br />
Affected Version: version 1.4.1 and other versions.<br />
Vendor’s URL: <a href="http://www.greatjoomla.com/extensions/plugins/core-design-scriptegrator-plugin.html">Core Design Scriptegrator Plugin</a><br />
Bug Type: File Inclusion<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/02/joomla-core-design-scriptegrator-plugin-multiple-file-inclusion.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla RWCards Component &#8220;controller&#8221; File Inclusion</title>
		<link>http://security.exabytes.com/2010/02/joomla-rwcards-component-controller-file-inclusion.html</link>
		<comments>http://security.exabytes.com/2010/02/joomla-rwcards-component-controller-file-inclusion.html#comments</comments>
		<pubDate>Tue, 23 Feb 2010 08:21:16 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[File Inclusion]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5319</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 3.0.18 and other versions.
Vendor’s URL: RWCards Component
Bug Type: File Inclusion
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 3.0.18 and other versions.<br />
Vendor’s URL: <a href="http://www.weberr.de/index.php/downloads-mainmenu-27/cat_view/23-joomla-15x.html">RWCards Component</a><br />
Bug Type: File Inclusion<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/02/joomla-rwcards-component-controller-file-inclusion.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla Webee Comments Component &#8220;articleId&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/02/joomla-webee-comments-component-articleid-sqli.html</link>
		<comments>http://security.exabytes.com/2010/02/joomla-webee-comments-component-articleid-sqli.html#comments</comments>
		<pubDate>Tue, 23 Feb 2010 08:19:53 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5317</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 2.0 and other versions.
Vendor’s URL: Webee Comments Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 2.0 and other versions.<br />
Vendor’s URL: <a href="http://www.onnogroen.nl/webee/">Webee Comments Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/02/joomla-webee-comments-component-articleid-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla JQuarks Component &#8220;id&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/02/joomla-jquarks-component-id-sqli.html</link>
		<comments>http://security.exabytes.com/2010/02/joomla-jquarks-component-id-sqli.html#comments</comments>
		<pubDate>Tue, 23 Feb 2010 08:18:18 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5315</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 0.2.3 and other versions.
Vendor’s URL: JQuarks Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 0.2.4 or later.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 0.2.3 and other versions.<br />
Vendor’s URL: <a href="http://www.iptechinside.com/labs/projects/show/jquarks">JQuarks Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 0.2.4 or later.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/02/joomla-jquarks-component-id-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla AllVideos Plugin &#8220;file&#8221; Information Disclosure</title>
		<link>http://security.exabytes.com/2010/02/joomla-allvideos-plugin-file-information-disclosure.html</link>
		<comments>http://security.exabytes.com/2010/02/joomla-allvideos-plugin-file-information-disclosure.html#comments</comments>
		<pubDate>Tue, 23 Feb 2010 08:17:09 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[Information Disclosure]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5313</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 3.1
Vendor’s URL: AllVideos Plugin
Bug Type: Information Disclosure
Risk Level: Critical
Solution:
Update to version 3.3 or later.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 3.1<br />
Vendor’s URL: <a href="http://extensions.joomla.org/extensions/812/details">AllVideos Plugin</a><br />
Bug Type: Information Disclosure<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 3.3 or later.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/02/joomla-allvideos-plugin-file-information-disclosure.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Drupal Graphviz Filter Module Arbitrary Command Execution</title>
		<link>http://security.exabytes.com/2010/02/drupal-graphviz-filter-module-arbitrary-command-execution.html</link>
		<comments>http://security.exabytes.com/2010/02/drupal-graphviz-filter-module-arbitrary-command-execution.html#comments</comments>
		<pubDate>Tue, 23 Feb 2010 08:15:28 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[Remote Command Execution]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5311</guid>
		<description><![CDATA[Application: Drupal
Affected Version: versions prior to 6.x-1.6 and 5.x-1.3.
Vendor’s URL: Graphviz Filter Module
Bug Type: Command Execution
Risk Level: Critical
Solution:
If you use Graphviz Filter 6.x-1.x, upgrade to Graphviz Filter 6.x-1.6.
If you use Graphviz Filter 5.x-1.x, upgrade to Graphviz Filter 5.x-1.3.
]]></description>
			<content:encoded><![CDATA[<p>Application: Drupal<br />
Affected Version: versions prior to 6.x-1.6 and 5.x-1.3.<br />
Vendor’s URL: <a href="http://drupal.org/project/graphviz_filter">Graphviz Filter Module</a><br />
Bug Type: Command Execution<br />
Risk Level: Critical</p>
<p>Solution:<br />
If you use Graphviz Filter 6.x-1.x, upgrade to <a href="http://drupal.org/node/710798">Graphviz Filter 6.x-1.6.</a><br />
If you use Graphviz Filter 5.x-1.x, upgrade to <a href="http://drupal.org/node/710804">Graphviz Filter 5.x-1.3.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/02/drupal-graphviz-filter-module-arbitrary-command-execution.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>odlican.net CMS Arbitrary File Upload</title>
		<link>http://security.exabytes.com/2010/02/odlicannet-cms-arbitrary-file-upload.html</link>
		<comments>http://security.exabytes.com/2010/02/odlicannet-cms-arbitrary-file-upload.html#comments</comments>
		<pubDate>Tue, 23 Feb 2010 08:12:37 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[File Inclusion]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5309</guid>
		<description><![CDATA[Application: odlican.net CMS
Affected Version: version 1.5.
Vendor’s URL: odlican.net CMS
Bug Type: File Inclusion
Risk Level: Critical
Solution:
Reportedly fixed in version 1.6.
]]></description>
			<content:encoded><![CDATA[<p>Application: odlican.net CMS<br />
Affected Version: version 1.5.<br />
Vendor’s URL: <a href="http://www.odlican.net">odlican.net CMS</a><br />
Bug Type: File Inclusion<br />
Risk Level: Critical</p>
<p>Solution:<br />
Reportedly fixed in version 1.6.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/02/odlicannet-cms-arbitrary-file-upload.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla Productbook Component &#8220;id&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/02/joomla-productbook-component-id-sqli.html</link>
		<comments>http://security.exabytes.com/2010/02/joomla-productbook-component-id-sqli.html#comments</comments>
		<pubDate>Tue, 23 Feb 2010 08:11:15 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5307</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 1.0.4
Vendor’s URL: Productbook Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 1.0.4<br />
Vendor’s URL: <a href="http://www.design-cars.com/component/option,com_remository/Itemid,30/func,select/id,1/">Productbook Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/02/joomla-productbook-component-id-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla JEvents Search Plugin SQLi</title>
		<link>http://security.exabytes.com/2010/02/joomla-jevents-search-plugin-sqli.html</link>
		<comments>http://security.exabytes.com/2010/02/joomla-jevents-search-plugin-sqli.html#comments</comments>
		<pubDate>Tue, 23 Feb 2010 08:10:09 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5305</guid>
		<description><![CDATA[Application: Joomla
Affected Version: versions prior to 1.5.3b
Vendor’s URL: JEvents Search Plugin
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 1.5.3b or later.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: versions prior to 1.5.3b<br />
Vendor’s URL: <a href="http://www.jevents.net/">JEvents Search Plugin</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 1.5.3b or later.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/02/joomla-jevents-search-plugin-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla! jVideoDirect Component &#8220;v&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/02/joomla-jvideodirect-component-v-sqli.html</link>
		<comments>http://security.exabytes.com/2010/02/joomla-jvideodirect-component-v-sqli.html#comments</comments>
		<pubDate>Tue, 23 Feb 2010 08:08:51 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5303</guid>
		<description><![CDATA[Application: Joomla!
Affected Version: version 1.1RC3b and other versions.
Vendor’s URL: jVideoDirect Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla!<br />
Affected Version: version 1.1RC3b and other versions.<br />
Vendor’s URL: <a href="http://www.jvideodirect.com/">jVideoDirect Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/02/joomla-jvideodirect-component-v-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla! Documents Seller Component &#8220;category_id&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/02/joomla-documents-seller-component-category_id-sqli.html</link>
		<comments>http://security.exabytes.com/2010/02/joomla-documents-seller-component-category_id-sqli.html#comments</comments>
		<pubDate>Tue, 23 Feb 2010 08:07:30 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5301</guid>
		<description><![CDATA[Application: Joomla!
Affected Version: version 2.5.1 and other versions.
Vendor’s URL: Documents Seller Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Filter malicious characters and character sequences using a proxy.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla!<br />
Affected Version: version 2.5.1 and other versions.<br />
Vendor’s URL: <a href="http://joomdonation.com/index.php?option=com_content&#038;view=article&#038;id=41&#038;Itemid=40">Documents Seller Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Filter malicious characters and character sequences using a proxy.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/02/joomla-documents-seller-component-category_id-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla! JE Event Calendars Component &#8220;event_id&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/02/joomla-je-event-calendars-component-event_id-sqli.html</link>
		<comments>http://security.exabytes.com/2010/02/joomla-je-event-calendars-component-event_id-sqli.html#comments</comments>
		<pubDate>Tue, 23 Feb 2010 08:06:19 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5299</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 1.0
Vendor’s URL: JE Event Calendars Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 1.0<br />
Vendor’s URL: <a href="http://joomlaextensions.co.in/extensions/joomla-component/event-calendar.html">JE Event Calendars Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/02/joomla-je-event-calendars-component-event_id-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla ccNewsletter Component &#8220;controller&#8221; File Inclusion</title>
		<link>http://security.exabytes.com/2010/02/joomla-ccnewsletter-component-controller-file-inclusion.html</link>
		<comments>http://security.exabytes.com/2010/02/joomla-ccnewsletter-component-controller-file-inclusion.html#comments</comments>
		<pubDate>Tue, 23 Feb 2010 08:03:40 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[File Inclusion]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5296</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 1.0.5
Vendor’s URL: ccNewsletter Component
Bug Type: File Inclusion
Risk Level: Critical
Solution:
Update to version 1.0.6.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 1.0.5<br />
Vendor’s URL: <a href="http://www.chillcreations.com/en/extensions/ccnewsletter-joomla-newsletter-extension.html">ccNewsletter Component</a><br />
Bug Type: File Inclusion<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 1.0.6.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/02/joomla-ccnewsletter-component-controller-file-inclusion.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>LightOpenCMS &#8220;cwd&#8221; File Inclusion</title>
		<link>http://security.exabytes.com/2010/01/lightopencms-cwd-file-inclusion.html</link>
		<comments>http://security.exabytes.com/2010/01/lightopencms-cwd-file-inclusion.html#comments</comments>
		<pubDate>Wed, 27 Jan 2010 03:31:12 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[File Inclusion]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5294</guid>
		<description><![CDATA[Application: LightOpenCMS
Affected Version: version 0.1 and other versions
Vendor’s URL: LightOpenCMS
Bug Type: File Inclusion
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly verified.
Set &#8220;register_globals&#8221; to &#8220;Off&#8221;.
]]></description>
			<content:encoded><![CDATA[<p>Application: LightOpenCMS<br />
Affected Version: version 0.1 and other versions<br />
Vendor’s URL: <a href="http://sourceforge.net/projects/lightopencms/">LightOpenCMS</a><br />
Bug Type: File Inclusion<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly verified.<br />
Set &#8220;register_globals&#8221; to &#8220;Off&#8221;.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/01/lightopencms-cwd-file-inclusion.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla! Component Ozio Gallery &#8220;writeToFile.php&#8221; File Manipulation</title>
		<link>http://security.exabytes.com/2010/01/joomla-component-ozio-gallery-writetofilephp-file-manipulation.html</link>
		<comments>http://security.exabytes.com/2010/01/joomla-component-ozio-gallery-writetofilephp-file-manipulation.html#comments</comments>
		<pubDate>Wed, 27 Jan 2010 03:26:07 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5292</guid>
		<description><![CDATA[Application: Joomla!
Affected Version: versions prior to 2.3.
Vendor’s URL: Ozio Gallery
Bug Type: File Manipulation
Risk Level: Critical
Solution:
Update to version 2.3.
http://www.joomla.it/download/oziogallery.html
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla!<br />
Affected Version: versions prior to 2.3.<br />
Vendor’s URL: <a href="http://oziogallery.joomla.it/">Ozio Gallery</a><br />
Bug Type: File Manipulation<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 2.3.<br />
http://www.joomla.it/download/oziogallery.html</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/01/joomla-component-ozio-gallery-writetofilephp-file-manipulation.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla JBDiary Component Multiple SQLi</title>
		<link>http://security.exabytes.com/2010/01/joomla-jbdiary-component-multiple-sqli.html</link>
		<comments>http://security.exabytes.com/2010/01/joomla-jbdiary-component-multiple-sqli.html#comments</comments>
		<pubDate>Wed, 27 Jan 2010 03:09:18 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5290</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 1.6 and other versions.
Vendor’s URL: JBDiary Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 1.6 and other versions.<br />
Vendor’s URL: <a href="http://www.jb-soft.nl/index.php?option=com_content&#038;view=article&#038;catid=18:jb-diary&#038;id=61:jbdiary">JBDiary Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/01/joomla-jbdiary-component-multiple-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla Document Seller for Docman Component &#8220;id&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/01/joomla-document-seller-for-docman-component-id-sqli.html</link>
		<comments>http://security.exabytes.com/2010/01/joomla-document-seller-for-docman-component-id-sqli.html#comments</comments>
		<pubDate>Wed, 27 Jan 2010 03:07:45 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5288</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 2.1
Vendor’s URL: Document Seller for Docman Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 2.1<br />
Vendor’s URL: <a href="http://www.joomservices.com/component/dm_orders/?task=show_item&#038;id=5">Document Seller for Docman Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/01/joomla-document-seller-for-docman-component-id-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla jEmbed-Embed Anything Component &#8220;catid&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/01/joomla-jembed-embed-anything-component-catid-sqli.html</link>
		<comments>http://security.exabytes.com/2010/01/joomla-jembed-embed-anything-component-catid-sqli.html#comments</comments>
		<pubDate>Wed, 27 Jan 2010 03:06:20 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5286</guid>
		<description><![CDATA[Application: Joomla
Affected Version:
Vendor’s URL: jEmbed-Embed Anything Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version:<br />
Vendor’s URL: <a href="http://www.joshprakash.com/index.php?option=com_docman&#038;task=doc_details&#038;gid=70">jEmbed-Embed Anything Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/01/joomla-jembed-embed-anything-component-catid-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla! TPJobs Component &#8220;id_c[]&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/01/joomla-tpjobs-component-id_c-sqli.html</link>
		<comments>http://security.exabytes.com/2010/01/joomla-tpjobs-component-id_c-sqli.html#comments</comments>
		<pubDate>Wed, 27 Jan 2010 03:04:59 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5284</guid>
		<description><![CDATA[Application: Joomla
Affected Version: versions prior to 1.1
Vendor’s URL: TPJobs Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 1.1.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: versions prior to 1.1<br />
Vendor’s URL: <a href="http://www.templateplazza.com/">TPJobs Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 1.1.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/01/joomla-tpjobs-component-id_c-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Xoops XSS and SQLi</title>
		<link>http://security.exabytes.com/2010/01/xoops-xss-and-sqli.html</link>
		<comments>http://security.exabytes.com/2010/01/xoops-xss-and-sqli.html#comments</comments>
		<pubDate>Wed, 27 Jan 2010 03:02:20 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[Cross Site Scripting]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5282</guid>
		<description><![CDATA[Application: Xoops
Affected Version: version 2.4.2 and prior versions.
Vendor’s URL: Xoops
Bug Type: Cross Site Scripting and SQL Injection
Risk Level: Medium
Solution:
Update to version 2.4.3.
]]></description>
			<content:encoded><![CDATA[<p>Application: Xoops<br />
Affected Version: version 2.4.2 and prior versions.<br />
Vendor’s URL: <a href="http://www.xoops.org/">Xoops</a><br />
Bug Type: Cross Site Scripting and SQL Injection<br />
Risk Level: Medium</p>
<p>Solution:<br />
Update to version 2.4.3.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/01/xoops-xss-and-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla iF Portfolio Nexus Component &#8220;controller&#8221; File Inclusion</title>
		<link>http://security.exabytes.com/2010/01/joomla-if-portfolio-nexus-component-controller-file-inclusion.html</link>
		<comments>http://security.exabytes.com/2010/01/joomla-if-portfolio-nexus-component-controller-file-inclusion.html#comments</comments>
		<pubDate>Wed, 27 Jan 2010 03:00:54 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[File Inclusion]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5280</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 1.5
Vendor’s URL: iF Portfolio Nexus Component
Bug Type: File Inclusion
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly verified.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 1.5<br />
Vendor’s URL: <a href="http://extensions.joomla.org/extensions/directory-a-documentation/portfolio/10360">iF Portfolio Nexus Component</a><br />
Bug Type: File Inclusion<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly verified.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/01/joomla-if-portfolio-nexus-component-controller-file-inclusion.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla! BeeHeard Component &#8220;category_id&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/01/joomla-beeheard-component-category_id-sqli.html</link>
		<comments>http://security.exabytes.com/2010/01/joomla-beeheard-component-category_id-sqli.html#comments</comments>
		<pubDate>Wed, 27 Jan 2010 02:59:28 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5277</guid>
		<description><![CDATA[Application: Joomla!
Affected Version:
Vendor’s URL: BeeHeard Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Filter malicious characters and character sequences using a proxy.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla!<br />
Affected Version:<br />
Vendor’s URL: <a href="http://beeheard.cmstactics.com/">BeeHeard Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Filter malicious characters and character sequences using a proxy.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/01/joomla-beeheard-component-category_id-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>WordPress Woopra Analytics Plugin Arbitrary File Creation</title>
		<link>http://security.exabytes.com/2009/12/wordpress-woopra-analytics-plugin-arbitrary-file-creation.html</link>
		<comments>http://security.exabytes.com/2009/12/wordpress-woopra-analytics-plugin-arbitrary-file-creation.html#comments</comments>
		<pubDate>Thu, 24 Dec 2009 08:15:34 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Access Bypass]]></category>

		<category><![CDATA[Content Management]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5275</guid>
		<description><![CDATA[Application: WordPress
Affected Version:
Vendor’s URL: Woopra Analytics Plugin
Bug Type: System Access
Risk Level: Critical
Solution:
Update to version 1.4.3.2.
Remove ofc_upload_image.php file from the Open Flash Chart directory.
]]></description>
			<content:encoded><![CDATA[<p>Application: WordPress<br />
Affected Version:<br />
Vendor’s URL: <a href="http://wordpress.org/extend/plugins/woopra/">Woopra Analytics Plugin</a><br />
Bug Type: System Access<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 1.4.3.2.</p>
<p>Remove ofc_upload_image.php file from the Open Flash Chart directory.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2009/12/wordpress-woopra-analytics-plugin-arbitrary-file-creation.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla JEEMA Article Collection Component &#8220;catid&#8221; SQLi</title>
		<link>http://security.exabytes.com/2009/12/joomla-jeema-article-collection-component-catid-sqli.html</link>
		<comments>http://security.exabytes.com/2009/12/joomla-jeema-article-collection-component-catid-sqli.html#comments</comments>
		<pubDate>Thu, 24 Dec 2009 08:13:15 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5272</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 1.0.0.1 and other versions.
Vendor’s URL: JEEMA Article Collection Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 1.0.0.1 and other versions.<br />
Vendor’s URL: <a href="http://www.jeema.net/downloads/free-joomla-extensions/joomla-components/12-jeema-joomla-article-collection.html">JEEMA Article Collection Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2009/12/joomla-jeema-article-collection-component-catid-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla JoomPortfolio Component &#8220;secid&#8221; SQLi</title>
		<link>http://security.exabytes.com/2009/12/joomla-joomportfolio-component-secid-sqli.html</link>
		<comments>http://security.exabytes.com/2009/12/joomla-joomportfolio-component-secid-sqli.html#comments</comments>
		<pubDate>Thu, 24 Dec 2009 08:11:03 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5270</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 1.0.0 and other versions.
Vendor’s URL: JoomPortfolio Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 1.0.0 and other versions.<br />
Vendor’s URL: <a href="http://www.joomplace.com/joomportfolio/joomportfolio.html">JoomPortfolio Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2009/12/joomla-joomportfolio-component-secid-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>WP-Forum Multiple SQLi</title>
		<link>http://security.exabytes.com/2009/12/wp-forum-multiple-sqli.html</link>
		<comments>http://security.exabytes.com/2009/12/wp-forum-multiple-sqli.html#comments</comments>
		<pubDate>Thu, 24 Dec 2009 08:09:13 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Discussion Boards]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5268</guid>
		<description><![CDATA[Application: WP-Forum
Affected Version: versions 2.3 and 2.4 and other versions.
Vendor’s URL: WP-Forum
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application: WP-Forum<br />
Affected Version: versions 2.3 and 2.4 and other versions.<br />
Vendor’s URL: <a href="http://www.fahlstad.se/wp-plugins/wp-forum/">WP-Forum</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2009/12/wp-forum-multiple-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Invision Power Board Script Insertion and SQLi</title>
		<link>http://security.exabytes.com/2009/12/invision-power-board-script-insertion-and-sqli.html</link>
		<comments>http://security.exabytes.com/2009/12/invision-power-board-script-insertion-and-sqli.html#comments</comments>
		<pubDate>Thu, 24 Dec 2009 08:05:37 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Discussion Boards]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5266</guid>
		<description><![CDATA[Application: Invision Power Board
Affected Version: version 2.3.6 and other versions.
Vendor’s URL: Invision Power Board
Bug Type: Script Insertion and SQL Injection
Risk Level: Medium
Solution:
Upgrade to version 3.0.5 or later.
]]></description>
			<content:encoded><![CDATA[<p>Application: Invision Power Board<br />
Affected Version: version 2.3.6 and other versions.<br />
Vendor’s URL: <a href="http://www.invisionboard.com/">Invision Power Board</a><br />
Bug Type: Script Insertion and SQL Injection<br />
Risk Level: Medium</p>
<p>Solution:<br />
Upgrade to version 3.0.5 or later.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2009/12/invision-power-board-script-insertion-and-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla JPhoto Component &#8220;id&#8221; SQLi</title>
		<link>http://security.exabytes.com/2009/12/joomla-jphoto-component-id-sqli.html</link>
		<comments>http://security.exabytes.com/2009/12/joomla-jphoto-component-id-sqli.html#comments</comments>
		<pubDate>Thu, 24 Dec 2009 07:43:46 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5264</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 1.0
Vendor’s URL: JPhoto Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 1.1 or later.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 1.0<br />
Vendor’s URL: <a href="http://www.corephp.com/jphoto/about.html">JPhoto Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 1.1 or later.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2009/12/joomla-jphoto-component-id-sqli.html/feed</wfw:commentRss>
		</item>
	</channel>
</rss>
