<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>BlogSecurity &#187; Alerts</title>
	<atom:link href="http://blogsecurity.net/category/alerts/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Mon, 22 Feb 2010 21:41:28 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Critical IPhone SMS Vulnerability</title>
		<link>http://blogsecurity.net/alerts/critical-iphone-sms-vulnerability</link>
		<comments>http://blogsecurity.net/alerts/critical-iphone-sms-vulnerability#comments</comments>
		<pubDate>Tue, 11 Aug 2009 14:48:05 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Alerts]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=576</guid>
		<description><![CDATA[Apple is releasing a critical patch on Saturday to address a recent vulnerability that was demonstrated at the infamous Blackhat hacking conference.

Charlie Miller, a consultant with Independent Security Evaluators, and Collin Mulliner, a PhD student at the Technical University of Berlin, presented the details of the vulnerability at the Black Hat Security Conference in Las [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/alerts/critical-iphone-sms-vulnerability/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Old WP-Forum Vulnerability Gets Disclosed</title>
		<link>http://blogsecurity.net/wordpress/wp-forum-178-vulnerability</link>
		<comments>http://blogsecurity.net/wordpress/wp-forum-178-vulnerability#comments</comments>
		<pubDate>Tue, 27 Jan 2009 00:14:06 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[BlogWatch]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[wordpress plugin vulnerability]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=335</guid>
		<description><![CDATA[
An vulnerability for  Fredrik Fahlstad&#8217;s WP-Forum Plugin has been made public on milw0rm. The exploit appears to affect an older version (1.7.8) of the popular WordPress plugin.


The plugins homepage is already on version 2.2. This means this vulnerability was probably discovered shortly after the initial version 1.7.4 vulnerability reported by BlogSecurity in early 2008.


As [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wp-forum-178-vulnerability/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>WordPress 2.6.2 Snoopy Vulnerability</title>
		<link>http://blogsecurity.net/wordpress/wordpress-262-snoopy-vulnerability</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-262-snoopy-vulnerability#comments</comments>
		<pubDate>Sat, 01 Nov 2008 15:56:25 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[BlogWatch]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=290</guid>
		<description><![CDATA[
WordPress announced the following vulnerability in WordPress 2.6.2:


A vulnerability in the Snoopy library was announced today.&#160; WordPress uses Snoopy to fetch the feeds shown in the Dashboard. Although this seems to be a low risk vulnerability for WordPress users, we wanted to get an update out immediately. 2.6.3 is available for download right now. If [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-262-snoopy-vulnerability/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>st_newsletter SQL Injection</title>
		<link>http://blogsecurity.net/wordpress/st_newsletter-sql-injection</link>
		<comments>http://blogsecurity.net/wordpress/st_newsletter-sql-injection#comments</comments>
		<pubDate>Sat, 01 Nov 2008 15:50:33 +0000</pubDate>
		<dc:creator>Philipp</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[BlogWatch]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=278</guid>
		<description><![CDATA[
The st_newsletter Plugin is once again vulnerable to SQL Injection.


The hole is located within the page stnl_iframe.php, the parameter newsletter is missing correct sanitisation and so the plugin is prone to this attack. Currently we&#8217;re not aware about any fixes, users should disable the Plugin in the meantime, or should fix the problem their self. [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/st_newsletter-sql-injection/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wordpress-MU Cross Site Scripting Vulnerability</title>
		<link>http://blogsecurity.net/wordpress/wordpress-mu-cross-site-scripting-vulnerability</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-mu-cross-site-scripting-vulnerability#comments</comments>
		<pubDate>Thu, 02 Oct 2008 20:46:39 +0000</pubDate>
		<dc:creator>Philipp</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[WP-MU]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=267</guid>
		<description><![CDATA[
Product: Wordpress-MU (multi-user)
Version: Versions prior to 2.6 are affected
Credits:  Juan Galiana


Juan Galiana has published the advisory to Bugtraq this week which includes a proof of concept exploit.


Wordpress-MU is affected by a Cross Site Scripting vulnerability, an attacker can perform an XSS attack that allows him to access the
targeted user cookies to gain administrator privileges


In [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-mu-cross-site-scripting-vulnerability/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WP Spreadsheet(wpSS) SQL Injection</title>
		<link>http://blogsecurity.net/wordpress/wp-spreadsheetwpss-sql-injection</link>
		<comments>http://blogsecurity.net/wordpress/wp-spreadsheetwpss-sql-injection#comments</comments>
		<pubDate>Thu, 24 Apr 2008 18:32:47 +0000</pubDate>
		<dc:creator>Philipp</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-spreadsheetwpss-sql-injection/</guid>
		<description><![CDATA[
A vulnerability has been found in Spreadsheet(wpSS) WordPress plugin.


The SQL Injection vulnerability may allow an attacker to compromise your backend database and potentially your blog and web server.


A public exploit has been released on milw0rm by 1ten0.0net1.


The &#8217;ss_id&#8217; parameter inside ss_load.php is not correctly escaped before being passed to the database.


It was reported that all [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wp-spreadsheetwpss-sql-injection/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>WP-Download SQL-Injection</title>
		<link>http://blogsecurity.net/wordpress/wp-download-sql-injection</link>
		<comments>http://blogsecurity.net/wordpress/wp-download-sql-injection#comments</comments>
		<pubDate>Fri, 04 Apr 2008 10:02:45 +0000</pubDate>
		<dc:creator>Philipp</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-download-sql-injection/</guid>
		<description><![CDATA[
WP-Download 1.2 is vulnerable to a SQL-Injection Vulnerability. The dl_id parameter in  &#34;wp-download.php&#34; is not correctly sanistised.


An attacker could use this vulnerability to retrieve usernames and passwords and potentially compromise your blog!


This bug has been reported in version 1.2, but it is likely that older versions are affected.


Please upgrade to version 1.2.1 which addresses [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wp-download-sql-injection/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>WordPress.com Blogs Vulnerable</title>
		<link>http://blogsecurity.net/wordpress/wordpresscom-blogs-vulnerable</link>
		<comments>http://blogsecurity.net/wordpress/wordpresscom-blogs-vulnerable#comments</comments>
		<pubDate>Sun, 09 Mar 2008 20:21:04 +0000</pubDate>
		<dc:creator>Philipp</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpresscom-blogs-vulnerable/</guid>
		<description><![CDATA[WordPress.com (2.3.2) is vulnerable to two Cross-Site Scripting vulnerabilities. It is important to note that these only affect WordPress.com blogs.

Proof of concept exploits have been released and there is a danger that an XSS Worm could use this type of vulnerability to compromise thousands of WordPress.com blogs. (See developer verse hosted blogs debate.).


Doz from hackerscenter.com [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpresscom-blogs-vulnerable/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>wp-people, Simple Forum, WP Photo Album, Search Unleashed, Sniplets</title>
		<link>http://blogsecurity.net/wordpress/wp-people-simple-forum-wp-photo-album-search-unleashed-sniplets</link>
		<comments>http://blogsecurity.net/wordpress/wp-people-simple-forum-wp-photo-album-search-unleashed-sniplets#comments</comments>
		<pubDate>Wed, 27 Feb 2008 17:18:46 +0000</pubDate>
		<dc:creator>Philipp</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-people-simple-forum-wp-photo-album-search-unleashed-sniplets/</guid>
		<description><![CDATA[
Once again a number of critical issues have been discovered in a variety of WordPress plugins. If you are using one of these plugins, we suggest disabling the plugin until a fix has been produced by the plugin developer. Info as follows:


WP People &#60;=1.6 is vulnerable to SQL Injection. The person parameter is not correctly [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wp-people-simple-forum-wp-photo-album-search-unleashed-sniplets/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>WP-Filemanager </title>
		<link>http://blogsecurity.net/wordpress/wp-filemanager</link>
		<comments>http://blogsecurity.net/wordpress/wp-filemanager#comments</comments>
		<pubDate>Tue, 08 Jan 2008 21:11:48 +0000</pubDate>
		<dc:creator>Philipp</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-filemanager/</guid>
		<description><![CDATA[The H-T Team have reported a vulnerability in WP-Filemanager.
***No proof of concept available***
The vulnerability is suppose to affect version 1.2. It may also affect earlier versions (in fact, this is likely). It is possible for an Attacker to upload Arbitrary PHP-Code, which can afterwards be executed with Webserver rights.
Currently there&#8217;s no vendor fix available. BlogSecurity [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wp-filemanager/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
