<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="0.92">
<channel>
	<title>Exabytes Security Portal</title>
	<link>http://security.exabytes.com</link>
	<description>Exabytes Security Portal</description>
	<lastBuildDate>Mon, 05 May 2008 00:11:28 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>eGroupWare File Upload</title>
		<description>Application: eGroupWare
Affected Version: prior to 1.4.004.
Vendor’s URL: eGroupWare
Bug Type: File Inclusion
Risk Level: Critical

Solution:
Update to version 1.4.004. </description>
		<link>http://security.exabytes.com/2008/04/egroupware-file-upload.html</link>
			</item>
	<item>
		<title>Joomla Jom Comment Component Unspecified SQL Injection</title>
		<description>Application: Joomla Jom Comment Component
Affected Version: version 2.0 and other versions.
Vendor’s URL: Joomla Jom Comment Component
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Update to version 2.2. </description>
		<link>http://security.exabytes.com/2008/04/joomla-jom-comment-component-unspecified-sql-injection.html</link>
			</item>
	<item>
		<title>WordPress WP-Download Plugin SQL Injection</title>
		<description>Application: WordPress WP-Download Plugin
Affected Version: 1.2 and other versions.
Vendor’s URL: WordPress WP-Download Plugin
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Update to version 1.2.1. </description>
		<link>http://security.exabytes.com/2008/04/wordpress-wp-download-plugin-sql-injection.html</link>
			</item>
	<item>
		<title>AuraCMS SQL Injection</title>
		<description>Application: AuraCMS
Affected Version: 2.2.1 and other versions.
Vendor’s URL: AuraCMS
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitized.
 </description>
		<link>http://security.exabytes.com/2008/04/auracms-sql-injection.html</link>
			</item>
	<item>
		<title>Simple Gallery XSS</title>
		<description>Application: Simple Gallery
Affected Version: 2.2 and other versions.
Vendor’s URL: Simple Gallery
Bug Type: Cross Site Scripting
Risk Level: Medium

Solution:
Edit the source code to ensure that input is properly sanitized.
 </description>
		<link>http://security.exabytes.com/2008/04/simple-gallery-xss.html</link>
			</item>
	<item>
		<title>Drupal Webform Module Unspecified Script Insertion</title>
		<description>Application: Drupal Webform Module
Affected Version: prior to version 5.x-1.10.
Vendor’s URL: Drupal Webform Module
Bug Type: Script Insertion
Risk Level: Critical

Solution:
Update to version 5.x-1.10.
 </description>
		<link>http://security.exabytes.com/2008/04/drupal-webform-module-unspecified-script-insertion.html</link>
			</item>
	<item>
		<title>PHP Photo Gallery SQL Injection</title>
		<description>Application: PHP Photo Gallery
Affected Version: 
Vendor’s URL: PHP Photo Gallery
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitized. </description>
		<link>http://security.exabytes.com/2008/04/php-photo-gallery-sql-injection.html</link>
			</item>
	<item>
		<title>Wikepage Information Disclosure</title>
		<description>Application: Wikepage
Affected Version: version Opus 13 2007.2 and other versions.
Vendor’s URL: Wikepage
Bug Type: Information Disclosure
Risk Level: Medium

Solution:
Edit the source code to ensure that input is properly sanitized. </description>
		<link>http://security.exabytes.com/2008/04/wikepage-information-disclosure.html</link>
			</item>
	<item>
		<title>Drupal Menu System Security Bypass</title>
		<description>Application: Drupal Menu System
Affected Version: 6.2 and prior versions.
Vendor’s URL: Drupal Menu System
Bug Type: Security Bypass
Risk Level: Critical

Solution:
Update to Drupal 6.2 or apply patch.
 </description>
		<link>http://security.exabytes.com/2008/04/drupal-menu-system-security-bypass.html</link>
			</item>
	<item>
		<title>Gallery Script Lite Information Disclosure</title>
		<description>Application: Gallery Script Lite
Affected Version: 
Vendor’s URL: Gallery Script Lite
Bug Type: Information Disclosure
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitized. </description>
		<link>http://security.exabytes.com/2008/04/gallery-script-lite-information-disclosure.html</link>
			</item>
	<item>
		<title>KnowledgeQuest SQL Injection and Security Bypass</title>
		<description>Application: KnowledgeQuest
Affected Version: 2.6 and other versions.
Vendor’s URL: KnowledgeQuest
Bug Type: Security Bypass
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitized. Restrict access to the admincheck.php </description>
		<link>http://security.exabytes.com/2008/04/knowledgequest-sql-injection-and-security-bypass.html</link>
			</item>
	<item>
		<title>Drupal Simple Access Module Security Bypass</title>
		<description>Application: Drupal Simple Access Module
Affected Version: 5.x-1.2-2 and prior versions.
Vendor’s URL: Drupal Simple Access Module
Bug Type: Access bypass
Risk Level: Critical

Solution:
Update to version 5.x-1.3. </description>
		<link>http://security.exabytes.com/2008/04/drupal-simple-access-module-security-bypass.html</link>
			</item>
	<item>
		<title>LiveCart SQL Injection Vulnerability</title>
		<description>Application: LiveCart
Affected Version: 1.1.1 trial version and other versions.
Vendor’s URL: LiveCart
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitized. </description>
		<link>http://security.exabytes.com/2008/04/livecart-sql-injection-vulnerability.html</link>
			</item>
	<item>
		<title>KwsPHP ConcoursPhoto Module SQL Injection</title>
		<description>Application: KwsPHP ConcoursPhoto Module
Affected Version: 2.0 and prior version.
Vendor’s URL: KwsPHP ConcoursPhoto Module
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Update to version 2.1. </description>
		<link>http://security.exabytes.com/2008/04/kwsphp-concoursphoto-module-sql-injection.html</link>
			</item>
	<item>
		<title>Coppermine Photo Gallery SQL Injection</title>
		<description>Application: Coppermine Photo Gallery
Affected Version: 1.4.16 and other versions.
Vendor’s URL: Coppermine Photo Gallery
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Update to version 1.4.17. </description>
		<link>http://security.exabytes.com/2008/04/coppermine-photo-gallery-sql-injection-2.html</link>
			</item>
	<item>
		<title>NewsOffice File Inclusion Vulnerability</title>
		<description>Application: NewsOffice
Affected Version: 1.1 and prior versions.
Vendor’s URL: NewsOffice
Bug Type: File Inclusion
Risk Level: Critical

Solution:
Update to version 1.1.1. </description>
		<link>http://security.exabytes.com/2008/04/newsoffice-file-inclusion-vulnerability.html</link>
			</item>
	<item>
		<title>phpkb Knowledge Base SQL Injection</title>
		<description>Application: phpkb Knowledge Base
Affected Version: 1.5 and 2.0 and other versions.
Vendor’s URL: phpkb Knowledge Base
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitized. </description>
		<link>http://security.exabytes.com/2008/04/phpkb-knowledge-base-sql-injection.html</link>
			</item>
	<item>
		<title>1024 CMS SQL Injection and File Inclusion</title>
		<description>Application: 1024 CMS
Affected Version: 1.4.1 and other versions.
Vendor’s URL: 1024 CMS
Bug Type: SQL Injection, File Inclusion
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitized and verified. </description>
		<link>http://security.exabytes.com/2008/04/1024-cms-sql-injection-and-file-inclusion.html</link>
			</item>
	<item>
		<title>cpCommerce Multiple Vulnerabilities</title>
		<description>Application: cpCommerce
Affected Version: 1.1.0 and other versions.
Vendor’s URL: cpCommerce
Bug Type: Cross Site Scripting and SQL injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitized and verified.
 </description>
		<link>http://security.exabytes.com/2008/04/cpcommerce-multiple-vulnerabilities.html</link>
			</item>
	<item>
		<title>Coppermine Photo Gallery SQL Injection</title>
		<description>Application: Coppermine Photo Gallery
Affected Version: 1.4.17 and other versions.
Vendor’s URL: Coppermine Photo Gallery
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Update to version 1.4.18. </description>
		<link>http://security.exabytes.com/2008/04/coppermine-photo-gallery-sql-injection.html</link>
			</item>
	<item>
		<title>phpBB Security Bypass Vulnerabilities</title>
		<description>Application: phpBB
Affected Version: 3.0.0.
Vendor’s URL: phpBB
Bug Type: Access Bypass
Risk Level: Critical

Solution:
Update to version 3.0.1. </description>
		<link>http://security.exabytes.com/2008/04/phpbb-security-bypass-vulnerabilities.html</link>
			</item>
	<item>
		<title>OSI Affiliate XSS</title>
		<description>Application: OSI Affiliate
Affected Version: 
Vendor’s URL: OSI Affiliate
Bug Type: Cross Site Scripting
Risk Level: Medium

Solution:
Edit the source code to ensure that input is properly sanitized.
 </description>
		<link>http://security.exabytes.com/2008/04/osi-affiliate-xss.html</link>
			</item>
	<item>
		<title>CubeCart Two XSS</title>
		<description>Application: CubeCart
Affected Version: 4.2.1 and other versions.
Vendor’s URL: CubeCart
Bug Type: Cross Site Scripting
Risk Level: Medium

Solution:
Edit the source code to ensure that input is properly sanitized. </description>
		<link>http://security.exabytes.com/2008/04/cubecart-two-xss.html</link>
			</item>
	<item>
		<title>RunCMS Photo Module SQL Injection</title>
		<description>Application: RunCMS Photo Module
Affected Version: 3.02 and other versions.
Vendor’s URL: RunCMS Photo Module
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitized.
 </description>
		<link>http://security.exabytes.com/2008/04/runcms-photo-module-sql-injection.html</link>
			</item>
	<item>
		<title>e107 my_gallery Plugin Information Disclosure</title>
		<description>Application: e107 my_gallery Plugin
Affected Version: 2.3 and other versions.
Vendor’s URL: e107 my_gallery
Bug Type: Information Disclosure
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitized. </description>
		<link>http://security.exabytes.com/2008/04/e107-my_gallery-plugin-information-disclosure.html</link>
			</item>
	<item>
		<title>Photo Cart &#8220;amessage&#8221; XSS</title>
		<description>Application: Photo Cart
Affected Version: 4.1 and other versions.
Vendor’s URL: Photo Cart
Bug Type: Cross Site Scripting
Risk Level: Medium

Solution:
Apply patch. http://www.picturespro.com/sp/ </description>
		<link>http://security.exabytes.com/2008/04/photo-cart-amessage-xss.html</link>
			</item>
	<item>
		<title>Joomla rekry!Joom Component SQL Injection</title>
		<description>Application: Joomla rekry!Joom Component
Affected Version: 1.0.0 and other versions.
Vendor’s URL: Joomla rekry!Joom Component
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitized. </description>
		<link>http://security.exabytes.com/2008/04/joomla-rekryjoom-component-sql-injection.html</link>
			</item>
	<item>
		<title>Joomla Custompages Component File Inclusion</title>
		<description>Application: Joomla
Affected Version: 1.1 and other versions.
Vendor’s URL: Joomla Custompages Component
Bug Type: access bypass, file inclusion
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly verified. </description>
		<link>http://security.exabytes.com/2008/04/joomla-custompages-component-file-inclusion.html</link>
			</item>
	<item>
		<title>DotNetNuke Multiple Vulnerabilities</title>
		<description>Application: DotNetNuke
Affected Version: version prior to 4.8.2.
Vendor’s URL: http://www.dotnetnuke.com/
Bug Type: Privilege escalation, access bypass
Risk Level: Critical

Solution:
Update to version 4.8.2.
http://www.dotnetnuke.com/tabid/125/default.aspx
 </description>
		<link>http://security.exabytes.com/2008/04/dotnetnuke-multiple-vulnerabilities.html</link>
			</item>
	<item>
		<title>phpAddressBook Multiple Vulnerabilities</title>
		<description>Application: phpAddressBook
Affected Version: 2.11 and other versions.
Vendor’s URL: phpAddressBook
Bug Type: Cross Site Scripting and file inclusion
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly verified and sanitized.
 </description>
		<link>http://security.exabytes.com/2008/04/phpaddressbook-multiple-vulnerabilities.html</link>
			</item>
</channel>
</rss>
