<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WP-Forum 1.7.4 SQL Injection</title>
	<atom:link href="http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/wordpress/wp-forum-174-sql-injection</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: BlogSecurity &#187; Blog Archive &#187; Old WP-Forum Vulnerability Gets Disclosed</title>
		<link>http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/comment-page-1#comment-15941</link>
		<dc:creator>BlogSecurity &#187; Blog Archive &#187; Old WP-Forum Vulnerability Gets Disclosed</dc:creator>
		<pubDate>Tue, 27 Jan 2009 00:14:14 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/#comment-15941</guid>
		<description>[...] The plugins homepage is already on version 2.2. This means this vulnerability was probably discovered shortly after the initial version 1.7.4 vulnerability reported by BlogSecurity in early 2008. [...]</description>
		<content:encoded><![CDATA[<p>[...] The plugins homepage is already on version 2.2. This means this vulnerability was probably discovered shortly after the initial version 1.7.4 vulnerability reported by BlogSecurity in early 2008. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Philipp</title>
		<link>http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/comment-page-1#comment-11676</link>
		<dc:creator>Philipp</dc:creator>
		<pubDate>Thu, 26 Jun 2008 07:08:46 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/#comment-11676</guid>
		<description>We&#039;ve no newer version Spotted of this Plugin. Anyway his forum seems to run with a newer version of the Plugin. Anyway you could patch that hole by yourself.</description>
		<content:encoded><![CDATA[<p>We&#8217;ve no newer version Spotted of this Plugin. Anyway his forum seems to run with a newer version of the Plugin. Anyway you could patch that hole by yourself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kai</title>
		<link>http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/comment-page-1#comment-11674</link>
		<dc:creator>Kai</dc:creator>
		<pubDate>Wed, 25 Jun 2008 16:34:04 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/#comment-11674</guid>
		<description>Any fix for this yet....?</description>
		<content:encoded><![CDATA[<p>Any fix for this yet&#8230;.?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/comment-page-1#comment-6802</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Sun, 03 Feb 2008 22:00:22 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/#comment-6802</guid>
		<description>Any news?..</description>
		<content:encoded><![CDATA[<p>Any news?..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MustLive</title>
		<link>http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/comment-page-1#comment-6723</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Thu, 31 Jan 2008 17:26:00 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/#comment-6723</guid>
		<description>Philipp and David, the html tags is not properly sanitized in this post ;-) (look at &quot;with the “” tag&quot; phrase). You need to fix it.

P.S.

ryan, you can fix this hole by yourself, if you don&#039;t want to wait for official fix. Because it&#039;s common for developers to fix holes in their software not very fast.</description>
		<content:encoded><![CDATA[<p>Philipp and David, the html tags is not properly sanitized in this post ;-) (look at &#8220;with the “” tag&#8221; phrase). You need to fix it.</p>
<p>P.S.</p>
<p>ryan, you can fix this hole by yourself, if you don&#8217;t want to wait for official fix. Because it&#8217;s common for developers to fix holes in their software not very fast.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Trevor Carpenter</title>
		<link>http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/comment-page-1#comment-6697</link>
		<dc:creator>Trevor Carpenter</dc:creator>
		<pubDate>Tue, 29 Jan 2008 22:34:34 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/#comment-6697</guid>
		<description>@ryan. I have a fix for this...

I uninstalled WP-forum and installed a real forum, phpbb.</description>
		<content:encoded><![CDATA[<p>@ryan. I have a fix for this&#8230;</p>
<p>I uninstalled WP-forum and installed a real forum, phpbb.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DK</title>
		<link>http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/comment-page-1#comment-6581</link>
		<dc:creator>DK</dc:creator>
		<pubDate>Thu, 24 Jan 2008 11:09:27 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/#comment-6581</guid>
		<description>ryan, I haven&#039;t seen any official fix yet.</description>
		<content:encoded><![CDATA[<p>ryan, I haven&#8217;t seen any official fix yet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ryan</title>
		<link>http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/comment-page-1#comment-6580</link>
		<dc:creator>ryan</dc:creator>
		<pubDate>Thu, 24 Jan 2008 11:00:27 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/#comment-6580</guid>
		<description>does anybody know of a fix for this yet?  I&#039;d like to get my forums back up.</description>
		<content:encoded><![CDATA[<p>does anybody know of a fix for this yet?  I&#8217;d like to get my forums back up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DK</title>
		<link>http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/comment-page-1#comment-6549</link>
		<dc:creator>DK</dc:creator>
		<pubDate>Tue, 22 Jan 2008 20:24:45 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/#comment-6549</guid>
		<description>WordPress really need to step up and provide SQL safe functions!</description>
		<content:encoded><![CDATA[<p>WordPress really need to step up and provide SQL safe functions!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
