<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Nextgen gallery &#8211; XSS flaw</title>
	<atom:link href="http://blogsecurity.net/wordpress/nextgen-gallery-xss-flaw/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/wordpress/nextgen-gallery-xss-flaw</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: digitalpbk</title>
		<link>http://blogsecurity.net/wordpress/nextgen-gallery-xss-flaw/comment-page-1#comment-16642</link>
		<dc:creator>digitalpbk</dc:creator>
		<pubDate>Fri, 17 Jul 2009 16:07:46 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/nextgen-gallery-xss-flaw/#comment-16642</guid>
		<description>There is even more flaw in this plugin check out &lt;a href=&quot;http://digitalpbk.blogspot.com/2009/07/wordpress-nextgen-gallery-xss.html&quot; rel=&quot;nofollow&quot;&gt;xss on wordpress nextgen library&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>There is even more flaw in this plugin check out <a href="http://digitalpbk.blogspot.com/2009/07/wordpress-nextgen-gallery-xss.html" rel="nofollow">xss on wordpress nextgen library</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Philipp</title>
		<link>http://blogsecurity.net/wordpress/nextgen-gallery-xss-flaw/comment-page-1#comment-11638</link>
		<dc:creator>Philipp</dc:creator>
		<pubDate>Sun, 22 Jun 2008 15:59:01 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/nextgen-gallery-xss-flaw/#comment-11638</guid>
		<description>As it&#039;s possible to edit Galleries, although with quite lower User Roles than the Administrator one, depending on the Settings, it&#039;s quite some risk. For sure it&#039;s not too high, as everyone should be encourage to give Permissions to trusted Users only, but it&#039;s anyway possible through blindfold grants, that bad guys can gain Administrator rights with it. 
Anyway we should mostly change the advisory a bit, mostly to a recommendation only</description>
		<content:encoded><![CDATA[<p>As it&#8217;s possible to edit Galleries, although with quite lower User Roles than the Administrator one, depending on the Settings, it&#8217;s quite some risk. For sure it&#8217;s not too high, as everyone should be encourage to give Permissions to trusted Users only, but it&#8217;s anyway possible through blindfold grants, that bad guys can gain Administrator rights with it.<br />
Anyway we should mostly change the advisory a bit, mostly to a recommendation only</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#160; Vulnerabilidad XSS en Nextgen Gallery&#160;en&#160;Agamum.net</title>
		<link>http://blogsecurity.net/wordpress/nextgen-gallery-xss-flaw/comment-page-1#comment-11619</link>
		<dc:creator>&#160; Vulnerabilidad XSS en Nextgen Gallery&#160;en&#160;Agamum.net</dc:creator>
		<pubDate>Wed, 18 Jun 2008 14:13:41 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/nextgen-gallery-xss-flaw/#comment-11619</guid>
		<description>[...] en: Blogsecurity.net   Etiquetas: actualización, seguridad, vulnerabilidad, [...]</description>
		<content:encoded><![CDATA[<p>[...] en: Blogsecurity.net   Etiquetas: actualización, seguridad, vulnerabilidad, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Next Gen Galley XSS Security Flaw &#187; Mercury Thread Internet Marketing Blog</title>
		<link>http://blogsecurity.net/wordpress/nextgen-gallery-xss-flaw/comment-page-1#comment-11616</link>
		<dc:creator>Next Gen Galley XSS Security Flaw &#187; Mercury Thread Internet Marketing Blog</dc:creator>
		<pubDate>Wed, 18 Jun 2008 10:59:18 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/nextgen-gallery-xss-flaw/#comment-11616</guid>
		<description>[...] that I could use easily within wordpress is a great help. I just found out that there is an XSS flaw in the Next Gen Gallery script. Does anyone know how to fix this so I can get it back up and [...]</description>
		<content:encoded><![CDATA[<p>[...] that I could use easily within wordpress is a great help. I just found out that there is an XSS flaw in the Next Gen Gallery script. Does anyone know how to fix this so I can get it back up and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://blogsecurity.net/wordpress/nextgen-gallery-xss-flaw/comment-page-1#comment-11615</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Wed, 18 Jun 2008 10:52:32 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/nextgen-gallery-xss-flaw/#comment-11615</guid>
		<description>Cheers for the heads up. Have removed said plugin as a result. Hope they have a fix soon as I was enjoying playing with this.</description>
		<content:encoded><![CDATA[<p>Cheers for the heads up. Have removed said plugin as a result. Hope they have a fix soon as I was enjoying playing with this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert</title>
		<link>http://blogsecurity.net/wordpress/nextgen-gallery-xss-flaw/comment-page-1#comment-11614</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Wed, 18 Jun 2008 10:37:31 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/nextgen-gallery-xss-flaw/#comment-11614</guid>
		<description>So, this &quot;advisory&quot; is basically telling us that a blog owner can introduce any HTML, including scripts, into his/her own blog? OMG! BBQ! WTF?</description>
		<content:encoded><![CDATA[<p>So, this &#8220;advisory&#8221; is basically telling us that a blog owner can introduce any HTML, including scripts, into his/her own blog? OMG! BBQ! WTF?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
