<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: dmsguestbook, st_newsletter,  Wordspew, wp-footnotes vulnerabilities [Update2]</title>
	<atom:link href="http://blogsecurity.net/wordpress/dmsguestbook-st_newsletter-wordspew-wp-footnotes-vulnerabilities/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/wordpress/dmsguestbook-st_newsletter-wordspew-wp-footnotes-vulnerabilities</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: WordPress Security - More On Themes And Plugins (ActiveBlogging)</title>
		<link>http://blogsecurity.net/wordpress/dmsguestbook-st_newsletter-wordspew-wp-footnotes-vulnerabilities/comment-page-1#comment-8694</link>
		<dc:creator>WordPress Security - More On Themes And Plugins (ActiveBlogging)</dc:creator>
		<pubDate>Thu, 27 Mar 2008 05:11:32 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/dmsguestbook-st_newsletter-wordspew-wp-footnotes-vulnerabilities/#comment-8694</guid>
		<description>[...] Blogsecurity.net (an excellent security blog and well worth bookmarking) reported on the security flaws of some packages and poorly formed mySQL input. Note this isn&#8217;t malicious coding of plugins - it&#8217;s just code that hasn&#8217;t been checked thoroughly in its inputs. Still, the end result is someone gets access to something they shouldn&#8217;t. [...]</description>
		<content:encoded><![CDATA[<p>[...] Blogsecurity.net (an excellent security blog and well worth bookmarking) reported on the security flaws of some packages and poorly formed mySQL input. Note this isn&#8217;t malicious coding of plugins &#8211; it&#8217;s just code that hasn&#8217;t been checked thoroughly in its inputs. Still, the end result is someone gets access to something they shouldn&#8217;t. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Podcast: Episode 34: WordPress 2.3.3 released, more security problems and Prologue &#124; Pittsburgh Punch</title>
		<link>http://blogsecurity.net/wordpress/dmsguestbook-st_newsletter-wordspew-wp-footnotes-vulnerabilities/comment-page-1#comment-7788</link>
		<dc:creator>WordPress Podcast: Episode 34: WordPress 2.3.3 released, more security problems and Prologue &#124; Pittsburgh Punch</dc:creator>
		<pubDate>Wed, 27 Feb 2008 04:59:15 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/dmsguestbook-st_newsletter-wordspew-wp-footnotes-vulnerabilities/#comment-7788</guid>
		<description>[...] array elements could execute unsanitized HTML to exploit the plugin. Other plugins with problems: WordsPew v3.x reported an &#8220;id&#8221; based SQL injection vulnerability, dmsguestbook 1.7.0, st_newsletter [...]</description>
		<content:encoded><![CDATA[<p>[...] array elements could execute unsanitized HTML to exploit the plugin. Other plugins with problems: WordsPew v3.x reported an &#8220;id&#8221; based SQL injection vulnerability, dmsguestbook 1.7.0, st_newsletter [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Episode 34: WordPress 2.3.3 released, more security problems and Prologue &#124; PHP Podcasts</title>
		<link>http://blogsecurity.net/wordpress/dmsguestbook-st_newsletter-wordspew-wp-footnotes-vulnerabilities/comment-page-1#comment-7700</link>
		<dc:creator>Episode 34: WordPress 2.3.3 released, more security problems and Prologue &#124; PHP Podcasts</dc:creator>
		<pubDate>Tue, 26 Feb 2008 05:16:36 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/dmsguestbook-st_newsletter-wordspew-wp-footnotes-vulnerabilities/#comment-7700</guid>
		<description>[...] array elements could execute unsanitized HTML to exploit the plugin. Other plugins with problems: WordsPew v3.x reported an &#8220;id&#8221; based SQL injection vulnerability, dmsguestbook 1.7.0, st_newsletter [...]</description>
		<content:encoded><![CDATA[<p>[...] array elements could execute unsanitized HTML to exploit the plugin. Other plugins with problems: WordsPew v3.x reported an &#8220;id&#8221; based SQL injection vulnerability, dmsguestbook 1.7.0, st_newsletter [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BlogSecurity &#187; Blog Archive &#187; WordPress BlogWatch</title>
		<link>http://blogsecurity.net/wordpress/dmsguestbook-st_newsletter-wordspew-wp-footnotes-vulnerabilities/comment-page-1#comment-6940</link>
		<dc:creator>BlogSecurity &#187; Blog Archive &#187; WordPress BlogWatch</dc:creator>
		<pubDate>Sun, 10 Feb 2008 19:01:49 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/dmsguestbook-st_newsletter-wordspew-wp-footnotes-vulnerabilities/#comment-6940</guid>
		<description>[...] SQL Injection Vulnerability (more) [...]</description>
		<content:encoded><![CDATA[<p>[...] SQL Injection Vulnerability (more) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pierre Sudarovich</title>
		<link>http://blogsecurity.net/wordpress/dmsguestbook-st_newsletter-wordspew-wp-footnotes-vulnerabilities/comment-page-1#comment-6911</link>
		<dc:creator>Pierre Sudarovich</dc:creator>
		<pubDate>Fri, 08 Feb 2008 09:24:44 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/dmsguestbook-st_newsletter-wordspew-wp-footnotes-vulnerabilities/#comment-6911</guid>
		<description>Hi all,
ok the bug in wordspew-rss.php is now corrected ;)</description>
		<content:encoded><![CDATA[<p>Hi all,<br />
ok the bug in wordspew-rss.php is now corrected ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DK</title>
		<link>http://blogsecurity.net/wordpress/dmsguestbook-st_newsletter-wordspew-wp-footnotes-vulnerabilities/comment-page-1#comment-6822</link>
		<dc:creator>DK</dc:creator>
		<pubDate>Tue, 05 Feb 2008 09:40:38 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/dmsguestbook-st_newsletter-wordspew-wp-footnotes-vulnerabilities/#comment-6822</guid>
		<description>Again, as I stressed before, secure coding functions, documentation and procedures need to be in place before this gets better!</description>
		<content:encoded><![CDATA[<p>Again, as I stressed before, secure coding functions, documentation and procedures need to be in place before this gets better!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
