<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>Exabytes Security Portal</title>
	<atom:link href="http://security.exabytes.com/feed" rel="self" type="application/rss+xml" />
	<link>http://security.exabytes.com</link>
	<description>Exabytes Security Portal</description>
	<pubDate>Wed, 25 Aug 2010 06:30:52 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Joomla! Zoom Portfolio Component &#8220;id&#8221; SQL Injection</title>
		<link>http://security.exabytes.com/2010/08/joomla-zoom-portfolio-component-id-sql-injection.html</link>
		<comments>http://security.exabytes.com/2010/08/joomla-zoom-portfolio-component-id-sql-injection.html#comments</comments>
		<pubDate>Wed, 25 Aug 2010 06:20:41 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5491</guid>
		<description><![CDATA[Application:  Joomla!
Affected Version: version 1.5 and other versions.
Vendor’s URL: Zoom Portfolio Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application:  Joomla!<br />
Affected Version: version 1.5 and other versions.<br />
Vendor’s URL: <a href="http://www.egbzoom.com/joomla-portfolio-component.html">Zoom Portfolio Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/08/joomla-zoom-portfolio-component-id-sql-injection.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla JGrid Component File Inclusion and SQL Injection</title>
		<link>http://security.exabytes.com/2010/08/joomla-jgrid-component-file-inclusion-and-sql-injection.html</link>
		<comments>http://security.exabytes.com/2010/08/joomla-jgrid-component-file-inclusion-and-sql-injection.html#comments</comments>
		<pubDate>Wed, 25 Aug 2010 06:19:26 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[File Inclusion]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5489</guid>
		<description><![CDATA[Application:  Joomla
Affected Version: Version 1.0 and other versions.
Vendor’s URL: JGrid Component
Bug Type: File Inclusion and SQL Injection
Risk Level: Critical
Solution:
Update to version 1.1.
]]></description>
			<content:encoded><![CDATA[<p>Application:  Joomla<br />
Affected Version: Version 1.0 and other versions.<br />
Vendor’s URL: <a href="http://www.datagrids.clubsareus.org/">JGrid Component</a><br />
Bug Type: File Inclusion and SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 1.1.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/08/joomla-jgrid-component-file-inclusion-and-sql-injection.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Free Simple CMS Remote File Inclusion</title>
		<link>http://security.exabytes.com/2010/08/free-simple-cms-remote-file-inclusion.html</link>
		<comments>http://security.exabytes.com/2010/08/free-simple-cms-remote-file-inclusion.html#comments</comments>
		<pubDate>Wed, 25 Aug 2010 06:17:28 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[File Inclusion]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5487</guid>
		<description><![CDATA[Application:  Free Simple CMS
Affected Version: version 1.0 and other versions.
Vendor’s URL: Free Simple CMS
Bug Type: File Inclusion
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly verified.
]]></description>
			<content:encoded><![CDATA[<p>Application:  Free Simple CMS<br />
Affected Version: version 1.0 and other versions.<br />
Vendor’s URL: <a href="http://www.freesimplecms.com/">Free Simple CMS</a><br />
Bug Type: File Inclusion<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly verified.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/08/free-simple-cms-remote-file-inclusion.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>CMSQLite Arbitrary File Upload and Security Bypass</title>
		<link>http://security.exabytes.com/2010/08/cmsqlite-arbitrary-file-upload-and-security-bypass.html</link>
		<comments>http://security.exabytes.com/2010/08/cmsqlite-arbitrary-file-upload-and-security-bypass.html#comments</comments>
		<pubDate>Wed, 25 Aug 2010 06:15:42 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Access Bypass]]></category>

		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[File Inclusion]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5485</guid>
		<description><![CDATA[Application:  CMSQLite
Affected Version: version 1.3.1 and other versions.
Vendor’s URL: CMSQLite
Bug Type: File Upload and Security Bypass
Risk Level: Critical
Solution:
Restrict access to the &#8220;admin&#8221; directory (e.g. via a &#8220;.htaccess&#8221; file).
]]></description>
			<content:encoded><![CDATA[<p>Application:  CMSQLite<br />
Affected Version: version 1.3.1 and other versions.<br />
Vendor’s URL: <a href="http://www.cmsqlite.net/">CMSQLite</a><br />
Bug Type: File Upload and Security Bypass<br />
Risk Level: Critical</p>
<p>Solution:<br />
Restrict access to the &#8220;admin&#8221; directory (e.g. via a &#8220;.htaccess&#8221; file).</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/08/cmsqlite-arbitrary-file-upload-and-security-bypass.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla onGallery Component &#8220;id&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/08/joomla-ongallery-component-id-sqli.html</link>
		<comments>http://security.exabytes.com/2010/08/joomla-ongallery-component-id-sqli.html#comments</comments>
		<pubDate>Wed, 25 Aug 2010 06:13:51 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5483</guid>
		<description><![CDATA[Application:  Joomla
Affected Version: version 2.0.1 and other versions.
Vendor’s URL: onGallery Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application:  Joomla<br />
Affected Version: version 2.0.1 and other versions.<br />
Vendor’s URL: <a href="http://www.onsom.com/">onGallery Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/08/joomla-ongallery-component-id-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>CMS Source Multiple Vulnerabilities</title>
		<link>http://security.exabytes.com/2010/08/cms-source-multiple-vulnerabilities.html</link>
		<comments>http://security.exabytes.com/2010/08/cms-source-multiple-vulnerabilities.html#comments</comments>
		<pubDate>Wed, 25 Aug 2010 06:09:38 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[Cross Site Scripting]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5481</guid>
		<description><![CDATA[Application:  CMS Source
Affected Version: version 3.0 and other versions.
Vendor’s URL: CMS Source
Bug Type: Cross Site Scripting and SQL Injection
Risk Level: Medium 
Solution:
Edit the source code to ensure that input is properly sanitised and verified.
]]></description>
			<content:encoded><![CDATA[<p>Application:  CMS Source<br />
Affected Version: version 3.0 and other versions.<br />
Vendor’s URL: <a href="http://www.prouddaddy.net/">CMS Source</a><br />
Bug Type: Cross Site Scripting and SQL Injection<br />
Risk Level: Medium </p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised and verified.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/08/cms-source-multiple-vulnerabilities.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Pligg Multiple SQLi</title>
		<link>http://security.exabytes.com/2010/08/pligg-multiple-sqli.html</link>
		<comments>http://security.exabytes.com/2010/08/pligg-multiple-sqli.html#comments</comments>
		<pubDate>Wed, 25 Aug 2010 06:07:56 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5479</guid>
		<description><![CDATA[Application:  Pligg
Affected Version: version 1.1.0 and other versions.
Vendor’s URL: Pligg
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 1.1.1.
]]></description>
			<content:encoded><![CDATA[<p>Application:  Pligg<br />
Affected Version: version 1.1.0 and other versions.<br />
Vendor’s URL: <a href="http://www.pligg.com/">Pligg</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 1.1.1.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/08/pligg-multiple-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla! Teams Component &#8220;PlayerID&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/08/joomla-teams-component-playerid-sqli.html</link>
		<comments>http://security.exabytes.com/2010/08/joomla-teams-component-playerid-sqli.html#comments</comments>
		<pubDate>Wed, 25 Aug 2010 06:05:54 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5477</guid>
		<description><![CDATA[Application:  Joomla!
Affected Version: Version 1 and other versions.
Vendor’s URL: Teams Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application:  Joomla!<br />
Affected Version: Version 1 and other versions.<br />
Vendor’s URL: <a href="http://www.joomlamo.com/joomlamo/downloads/doc_details/22-teams.html">Teams Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/08/joomla-teams-component-playerid-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla! Amblog Component &#8220;catid&#8221; and &#8220;articleid&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/08/joomla-amblog-component-catid-and-articleid-sqli.html</link>
		<comments>http://security.exabytes.com/2010/08/joomla-amblog-component-catid-and-articleid-sqli.html#comments</comments>
		<pubDate>Wed, 25 Aug 2010 05:58:00 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<category><![CDATA[Session Hijacking]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5473</guid>
		<description><![CDATA[Application:  Joomla!
Affected Version: version 1.0 and other versions.
Vendor’s URL: Amblog Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application:  Joomla!<br />
Affected Version: version 1.0 and other versions.<br />
Vendor’s URL: <a href="http://robitbt.hu/jm/index.php?option=com_amdownloader&#038;task=showfiles&#038;pathid=8">Amblog Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/08/joomla-amblog-component-catid-and-articleid-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla! cgTestimonial Component Cross-Site Scripting and Arbitrary File Upload</title>
		<link>http://security.exabytes.com/2010/08/joomla-cgtestimonial-component-cross-site-scripting-and-arbitrary-file-upload.html</link>
		<comments>http://security.exabytes.com/2010/08/joomla-cgtestimonial-component-cross-site-scripting-and-arbitrary-file-upload.html#comments</comments>
		<pubDate>Wed, 25 Aug 2010 05:54:03 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[Cross Site Scripting]]></category>

		<category><![CDATA[File Inclusion]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5471</guid>
		<description><![CDATA[Application:  Joomla!
Affected Version: version 1.0 and other versions.
Vendor’s URL: cgTestimonial Component
Bug Type: Cross Site Scripting and File Upload
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised. Restrict access to the components/com_cgtestimonial/user_images directory (e.g. via .htaccess)
]]></description>
			<content:encoded><![CDATA[<p>Application:  Joomla!<br />
Affected Version: version 1.0 and other versions.<br />
Vendor’s URL: <a href="http://www.cmsgalaxy.com/view.download/4/6.html">cgTestimonial Component</a><br />
Bug Type: Cross Site Scripting and File Upload<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised. Restrict access to the components/com_cgtestimonial/user_images directory (e.g. via .htaccess)</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/08/joomla-cgtestimonial-component-cross-site-scripting-and-arbitrary-file-upload.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>WordPress NextGEN Smooth Gallery Plugin &#8220;galleryID&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/08/wordpress-nextgen-smooth-gallery-plugin-galleryid-sqli.html</link>
		<comments>http://security.exabytes.com/2010/08/wordpress-nextgen-smooth-gallery-plugin-galleryid-sqli.html#comments</comments>
		<pubDate>Wed, 25 Aug 2010 04:12:52 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5469</guid>
		<description><![CDATA[Application:  WordPress
Affected Version: version 1.2 and other versions.
Vendor’s URL: NextGEN Smooth Gallery Plugin
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application:  WordPress<br />
Affected Version: version 1.2 and other versions.<br />
Vendor’s URL: <a href="http://wordpress.org/extend/plugins/nextgen-smooth-gallery/">NextGEN Smooth Gallery Plugin</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/08/wordpress-nextgen-smooth-gallery-plugin-galleryid-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla! Spielothek Component Multiple SQLi</title>
		<link>http://security.exabytes.com/2010/08/joomla-spielothek-component-multiple-sqli.html</link>
		<comments>http://security.exabytes.com/2010/08/joomla-spielothek-component-multiple-sqli.html#comments</comments>
		<pubDate>Wed, 25 Aug 2010 04:08:07 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5465</guid>
		<description><![CDATA[Application:  Joomla!
Affected Version: version 1.6.9 and other versions.
Vendor’s URL: Spielothek Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application:  Joomla!<br />
Affected Version: version 1.6.9 and other versions.<br />
Vendor’s URL: <a href="http://www.spielban.de/">Spielothek Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/08/joomla-spielothek-component-multiple-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>EasyManage CMS &#8220;id&#8221; Two SQL Injections</title>
		<link>http://security.exabytes.com/2010/08/easymanage-cms-id-two-sql-injections.html</link>
		<comments>http://security.exabytes.com/2010/08/easymanage-cms-id-two-sql-injections.html#comments</comments>
		<pubDate>Wed, 25 Aug 2010 04:06:09 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5463</guid>
		<description><![CDATA[Application:  EasyManage CMS
Affected Version:
Vendor’s URL: EasyManage CMS
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Reportedly a patch has been released. Contact the vendor for further information.
]]></description>
			<content:encoded><![CDATA[<p>Application:  EasyManage CMS<br />
Affected Version:<br />
Vendor’s URL: <a href="http://www.face.co.nz/cms_display.php?sn=32&#038;st=1">EasyManage CMS</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Reportedly a patch has been released. Contact the vendor for further information.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/08/easymanage-cms-id-two-sql-injections.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla! TTVideo Component &#8220;cid&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/07/joomla-ttvideo-component-cid-sqli.html</link>
		<comments>http://security.exabytes.com/2010/07/joomla-ttvideo-component-cid-sqli.html#comments</comments>
		<pubDate>Thu, 29 Jul 2010 08:23:25 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5461</guid>
		<description><![CDATA[Application: Joomla!
Affected Version: version 1.0 and other versions.
Vendor’s URL: TTVideo Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla!<br />
Affected Version: version 1.0 and other versions.<br />
Vendor’s URL: <a href="http://www.toughtomato.com/resources/downloads/joomla-1.5/components/ttvideo/">TTVideo Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/07/joomla-ttvideo-component-cid-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla! IT Armory Component Multiple SQLi</title>
		<link>http://security.exabytes.com/2010/07/joomla-it-armory-component-multiple-sqli.html</link>
		<comments>http://security.exabytes.com/2010/07/joomla-it-armory-component-multiple-sqli.html#comments</comments>
		<pubDate>Thu, 29 Jul 2010 08:21:03 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5459</guid>
		<description><![CDATA[Application: Joomla!
Affected Version: version 0.1.4 and other versions.
Vendor’s URL: IT Armory Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla!<br />
Affected Version: version 0.1.4 and other versions.<br />
Vendor’s URL: <a href="http://extensions.joomla.org/extensions/sports-a-games/world-of-warcraft-game/13137">IT Armory Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/07/joomla-it-armory-component-multiple-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla Frei-Chat Component One Script Insertion</title>
		<link>http://security.exabytes.com/2010/07/joomla-frei-chat-component-one-script-insertion.html</link>
		<comments>http://security.exabytes.com/2010/07/joomla-frei-chat-component-one-script-insertion.html#comments</comments>
		<pubDate>Thu, 29 Jul 2010 08:07:50 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[Cross Site Scripting]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5457</guid>
		<description><![CDATA[Application: Joomla
Affected Version: versions prior to 2.1.2.
Vendor’s URL: Frei-Chat Component 
Bug Type: Cross Site Scripting
Risk Level: Medium
Solution:
Update to version 2.1.2.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: versions prior to 2.1.2.<br />
Vendor’s URL: <a href="http://code.google.com/p/frei-chat/">Frei-Chat Component </a><br />
Bug Type: Cross Site Scripting<br />
Risk Level: Medium</p>
<p>Solution:<br />
Update to version 2.1.2.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/07/joomla-frei-chat-component-one-script-insertion.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>WordPress myLinksDump Plugin &#8220;url&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/07/wordpress-mylinksdump-plugin-url-sqli.html</link>
		<comments>http://security.exabytes.com/2010/07/wordpress-mylinksdump-plugin-url-sqli.html#comments</comments>
		<pubDate>Thu, 29 Jul 2010 08:05:50 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5455</guid>
		<description><![CDATA[Application: WordPress
Affected Version:
Vendor’s URL: myLinksDump Plugin
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application: WordPress<br />
Affected Version:<br />
Vendor’s URL: <a href="http://wordpress.org/extend/plugins/mylinksdump/">myLinksDump Plugin</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/07/wordpress-mylinksdump-plugin-url-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla InstantPhp Jobs Component &#8220;detailed_results&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/07/joomla-instantphp-jobs-component-detailed_results-sqli.html</link>
		<comments>http://security.exabytes.com/2010/07/joomla-instantphp-jobs-component-detailed_results-sqli.html#comments</comments>
		<pubDate>Thu, 29 Jul 2010 08:03:03 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5453</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 1.3.2 and other versions
Vendor’s URL: InstantPhp Jobs Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 1.3.3.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 1.3.2 and other versions<br />
Vendor’s URL: <a href="http://www.instantphp.com/store/details/6/jobs.html">InstantPhp Jobs Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 1.3.3.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/07/joomla-instantphp-jobs-component-detailed_results-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>CMS Made Simple Download Manager Module Arbitrary File Upload</title>
		<link>http://security.exabytes.com/2010/07/cms-made-simple-download-manager-module-arbitrary-file-upload.html</link>
		<comments>http://security.exabytes.com/2010/07/cms-made-simple-download-manager-module-arbitrary-file-upload.html#comments</comments>
		<pubDate>Thu, 29 Jul 2010 07:53:11 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[File Inclusion]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5451</guid>
		<description><![CDATA[Application: CMS Made Simple
Affected Version: version 1.4.1 and other versions.
Vendor’s URL: Download Manager Module
Bug Type: File Upload
Risk Level: Critical
Solution:
Restrict access to the &#8220;modules/DownloadManager/lib/simple-upload/example.php&#8221; script (e.g. via .htaccess)
]]></description>
			<content:encoded><![CDATA[<p>Application: CMS Made Simple<br />
Affected Version: version 1.4.1 and other versions.<br />
Vendor’s URL: <a href="http://dev.cmsmadesimple.org/projects/downloadmanager">Download Manager Module</a><br />
Bug Type: File Upload<br />
Risk Level: Critical</p>
<p>Solution:<br />
Restrict access to the &#8220;modules/DownloadManager/lib/simple-upload/example.php&#8221; script (e.g. via .htaccess)</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/07/cms-made-simple-download-manager-module-arbitrary-file-upload.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla AutarTimonial Component &#8220;limit&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/07/joomla-autartimonial-component-limit-sqli.html</link>
		<comments>http://security.exabytes.com/2010/07/joomla-autartimonial-component-limit-sqli.html#comments</comments>
		<pubDate>Thu, 29 Jul 2010 07:47:49 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5448</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 1.0.8 and other versions.
Vendor’s URL: AutarTimonial Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 1.0.8 and other versions.<br />
Vendor’s URL: <a href="http://www.autartica.be/en/autartimonial">AutarTimonial Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/07/joomla-autartimonial-component-limit-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>WordPress Simple:Press Plugin &#8220;value&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/07/wordpress-simplepress-plugin-value-sqli.html</link>
		<comments>http://security.exabytes.com/2010/07/wordpress-simplepress-plugin-value-sqli.html#comments</comments>
		<pubDate>Thu, 29 Jul 2010 07:42:46 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5446</guid>
		<description><![CDATA[Application: WordPress
Affected Version: version 4.3.1 and other versions.
Vendor’s URL: Simple:Press Plugin
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application: WordPress<br />
Affected Version: version 4.3.1 and other versions.<br />
Vendor’s URL: <a href="http://simple-press.com/">Simple:Press Plugin</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/07/wordpress-simplepress-plugin-value-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>WordPress WP-UserOnline Plugin Script Insertion</title>
		<link>http://security.exabytes.com/2010/07/wordpress-wp-useronline-plugin-script-insertion.html</link>
		<comments>http://security.exabytes.com/2010/07/wordpress-wp-useronline-plugin-script-insertion.html#comments</comments>
		<pubDate>Thu, 29 Jul 2010 07:39:11 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[Cross Site Scripting]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5444</guid>
		<description><![CDATA[Application: WordPress
Affected Version: Version 2.62 and other versions
Vendor’s URL: WP-UserOnline Plugin
Bug Type: Cross Site Scripting
Risk Level: Medium
Solution:
Update to version 2.70 or later.
]]></description>
			<content:encoded><![CDATA[<p>Application: WordPress<br />
Affected Version: Version 2.62 and other versions<br />
Vendor’s URL: <a href="http://wordpress.org/extend/plugins/wp-useronline/">WP-UserOnline Plugin</a><br />
Bug Type: Cross Site Scripting<br />
Risk Level: Medium</p>
<p>Solution:<br />
Update to version 2.70 or later.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/07/wordpress-wp-useronline-plugin-script-insertion.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla BookLibrary From Same Author Module &#8220;id&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/07/joomla-booklibrary-from-same-author-module-id-sqli.html</link>
		<comments>http://security.exabytes.com/2010/07/joomla-booklibrary-from-same-author-module-id-sqli.html#comments</comments>
		<pubDate>Thu, 29 Jul 2010 07:36:03 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5442</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 1.5 and other versions.
Vendor’s URL: BookLibrary From Same Author Module 
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 1.5_2010_06_25.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 1.5 and other versions.<br />
Vendor’s URL: <a href="http://ordasoft.com/Download/View-document-details/50-BookLibrary-Books-from-same-author-module-version-1.5.html">BookLibrary From Same Author Module </a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 1.5_2010_06_25.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/07/joomla-booklibrary-from-same-author-module-id-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>phpaaCMS &#8220;id&#8221; SQLi</title>
		<link>http://security.exabytes.com/2010/07/phpaacms-id-sqli.html</link>
		<comments>http://security.exabytes.com/2010/07/phpaacms-id-sqli.html#comments</comments>
		<pubDate>Thu, 29 Jul 2010 07:21:09 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5440</guid>
		<description><![CDATA[Application: phpaaCMS
Affected Version: version 0.3.1 UTF-8 and other versions
Vendor’s URL: phpaaCMS
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
]]></description>
			<content:encoded><![CDATA[<p>Application: phpaaCMS<br />
Affected Version: version 0.3.1 UTF-8 and other versions<br />
Vendor’s URL: <a href="http://www.phpaa.cn/">phpaaCMS</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/07/phpaacms-id-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla JoomDOC Component File Disclosure</title>
		<link>http://security.exabytes.com/2010/07/joomla-joomdoc-component-file-disclosure.html</link>
		<comments>http://security.exabytes.com/2010/07/joomla-joomdoc-component-file-disclosure.html#comments</comments>
		<pubDate>Thu, 29 Jul 2010 07:19:53 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[Information Disclosure]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5438</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 2.0.2 and other versions
Vendor’s URL: JoomDOC Component
Bug Type: File Disclosure
Risk Level: Medium
Solution:
Restrict access for accounts with &#8220;upload&#8221; and &#8220;edit&#8221; permissions to trusted users only.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 2.0.2 and other versions<br />
Vendor’s URL: <a href="http://www.artio.net/downloads/joomla-related/joomdoc/joomdoc-2-0-2/details">JoomDOC Component</a><br />
Bug Type: File Disclosure<br />
Risk Level: Medium</p>
<p>Solution:<br />
Restrict access for accounts with &#8220;upload&#8221; and &#8220;edit&#8221; permissions to trusted users only.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/07/joomla-joomdoc-component-file-disclosure.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla CKForms Component Multiple Vulnerabilities</title>
		<link>http://security.exabytes.com/2010/07/joomla-ckforms-component-multiple-vulnerabilities.html</link>
		<comments>http://security.exabytes.com/2010/07/joomla-ckforms-component-multiple-vulnerabilities.html#comments</comments>
		<pubDate>Thu, 29 Jul 2010 07:17:28 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5436</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 1.3.4 and other versions
Vendor’s URL: CKForms Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised. Change the &#8220;Uploaded files path&#8221; setting to a directory outside of the web root.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 1.3.4 and other versions<br />
Vendor’s URL: <a href="http://www.cookex.eu/">CKForms Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised. Change the &#8220;Uploaded files path&#8221; setting to a directory outside of the web root.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/07/joomla-ckforms-component-multiple-vulnerabilities.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla BookLibrary Component Multiple SQLi</title>
		<link>http://security.exabytes.com/2010/07/joomla-booklibrary-component-multiple-sqli.html</link>
		<comments>http://security.exabytes.com/2010/07/joomla-booklibrary-component-multiple-sqli.html#comments</comments>
		<pubDate>Thu, 29 Jul 2010 07:15:52 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5434</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 1.5.3 Basic and other versions.
Vendor’s URL: BookLibrary Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 1.5.3_2010_06_20.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 1.5.3 Basic and other versions.<br />
Vendor’s URL: <a href="http://ordasoft.com/Download/View-document-details/3-BookLibrary-1.5.3-Basic-for-Joomla-1.5.html">BookLibrary Component</a><br />
Bug Type: SQL Injection<br />
Risk Level: Critical</p>
<p>Solution:<br />
Update to version 1.5.3_2010_06_20.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/07/joomla-booklibrary-component-multiple-sqli.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Bigforum SQL Injection and Arbitrary File Upload</title>
		<link>http://security.exabytes.com/2010/07/bigforum-sql-injection-and-arbitrary-file-upload.html</link>
		<comments>http://security.exabytes.com/2010/07/bigforum-sql-injection-and-arbitrary-file-upload.html#comments</comments>
		<pubDate>Thu, 29 Jul 2010 07:14:34 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Discussion Boards]]></category>

		<category><![CDATA[File Inclusion]]></category>

		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5432</guid>
		<description><![CDATA[Application: Bigforum
Affected Version: version 5.2 and other versions.
Vendor’s URL: Bigforum
Bug Type: SQL Injection and Arbitrary File Upload
Risk Level: 
Solution:
Edit the source code to ensure that input is properly sanitised. Restrict access to the &#8220;images/avatar/&#8221; directory (e.g. via .htaccess).
]]></description>
			<content:encoded><![CDATA[<p>Application: Bigforum<br />
Affected Version: version 5.2 and other versions.<br />
Vendor’s URL: <a href="http://www.bfs.kilu.de/">Bigforum</a><br />
Bug Type: SQL Injection and Arbitrary File Upload<br />
Risk Level: </p>
<p>Solution:<br />
Edit the source code to ensure that input is properly sanitised. Restrict access to the &#8220;images/avatar/&#8221; directory (e.g. via .htaccess).</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/07/bigforum-sql-injection-and-arbitrary-file-upload.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla E-portfolio Component Arbitrary File Upload</title>
		<link>http://security.exabytes.com/2010/07/joomla-e-portfolio-component-arbitrary-file-upload.html</link>
		<comments>http://security.exabytes.com/2010/07/joomla-e-portfolio-component-arbitrary-file-upload.html#comments</comments>
		<pubDate>Thu, 29 Jul 2010 07:13:15 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Content Management]]></category>

		<category><![CDATA[File Inclusion]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5430</guid>
		<description><![CDATA[Application: Joomla
Affected Version: version 1.5.0 and other versions.
Vendor’s URL: E-portfolio Component
Bug Type: File Inclusion
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly verified.
]]></description>
			<content:encoded><![CDATA[<p>Application: Joomla<br />
Affected Version: version 1.5.0 and other versions.<br />
Vendor’s URL: <a href="http://www.joomplace.com/e-portfolio/e-portfolio-description.html">E-portfolio Component</a><br />
Bug Type: File Inclusion<br />
Risk Level: Critical</p>
<p>Solution:<br />
Edit the source code to ensure that input is properly verified.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/07/joomla-e-portfolio-component-arbitrary-file-upload.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Ultimate PHP Board Security Bypass and File Disclosure</title>
		<link>http://security.exabytes.com/2010/07/ultimate-php-board-security-bypass-and-file-disclosure.html</link>
		<comments>http://security.exabytes.com/2010/07/ultimate-php-board-security-bypass-and-file-disclosure.html#comments</comments>
		<pubDate>Thu, 29 Jul 2010 07:11:57 +0000</pubDate>
		<dc:creator>TL Guan</dc:creator>
		
		<category><![CDATA[Access Bypass]]></category>

		<category><![CDATA[Discussion Boards]]></category>

		<category><![CDATA[Information Disclosure]]></category>

		<guid isPermaLink="false">http://security.exabytes.com/?p=5428</guid>
		<description><![CDATA[Application: Ultimate PHP Board
Affected Version: version 2.2.6 and other versions.
Vendor’s URL: Ultimate PHP Board
Bug Type: Security Bypass and File Disclosure
Risk Level: Medium
Solution:
Restrict access to the admin_restore.php script (e.g. via .htaccess). Edit the source code to ensure that input is properly verified.
]]></description>
			<content:encoded><![CDATA[<p>Application: Ultimate PHP Board<br />
Affected Version: version 2.2.6 and other versions.<br />
Vendor’s URL: <a href="http://www.myupb.com/">Ultimate PHP Board</a><br />
Bug Type: Security Bypass and File Disclosure<br />
Risk Level: Medium</p>
<p>Solution:<br />
Restrict access to the admin_restore.php script (e.g. via .htaccess). Edit the source code to ensure that input is properly verified.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.exabytes.com/2010/07/ultimate-php-board-security-bypass-and-file-disclosure.html/feed</wfw:commentRss>
		</item>
	</channel>
</rss>
