<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WP TextLinkAds Plugin SQL Injection Vulnerability</title>
	<atom:link href="http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Brian</title>
		<link>http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/comment-page-1#comment-8581</link>
		<dc:creator>Brian</dc:creator>
		<pubDate>Wed, 26 Mar 2008 08:02:01 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/#comment-8581</guid>
		<description>Does anyone know if this has been fixed yet, or a good version to use?</description>
		<content:encoded><![CDATA[<p>Does anyone know if this has been fixed yet, or a good version to use?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nick</title>
		<link>http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/comment-page-1#comment-6797</link>
		<dc:creator>Nick</dc:creator>
		<pubDate>Sun, 03 Feb 2008 12:15:03 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/#comment-6797</guid>
		<description>I&#039;ve just downloaded a new plugin version   (&lt;i&gt;after being sent an e-mail from TLA&lt;/i&gt;) and the problem still exists.... code from version 1.2.0...
&lt;code&gt;
function tla_send_new_post_alert($postId)
{
	global $text_link_ads_object;

	$text_link_ads_object-&gt;postLevelPing($text_link_ads_object-&gt;tlaPingUrl.&#039;?action=add&amp;inventory_key=&#039;.$text_link_ads_object-&gt;websiteKey.&#039;&amp;post_id=&#039;.$postId);
}
&lt;/code&gt;</description>
		<content:encoded><![CDATA[<p>I&#8217;ve just downloaded a new plugin version   (<i>after being sent an e-mail from TLA</i>) and the problem still exists&#8230;. code from version 1.2.0&#8230;<br />
<code><br />
function tla_send_new_post_alert($postId)<br />
{<br />
	global $text_link_ads_object;</p>
<p>	$text_link_ads_object-&gt;postLevelPing($text_link_ads_object-&gt;tlaPingUrl.'?action=add&amp;inventory_key='.$text_link_ads_object-&gt;websiteKey.'&amp;post_id='.$postId);<br />
}<br />
</code></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: djbaxter</title>
		<link>http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/comment-page-1#comment-6502</link>
		<dc:creator>djbaxter</dc:creator>
		<pubDate>Fri, 18 Jan 2008 16:16:15 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/#comment-6502</guid>
		<description>I couldn&#039;t find the line &quot;$postId = $postId;&quot; at 512 or anywhere else in my TLA plugin. I went to the TLA site and downloaded a brand new plug-in to see if it had changed and it&#039;s nowhere to be found in that file either.</description>
		<content:encoded><![CDATA[<p>I couldn&#8217;t find the line &#8220;$postId = $postId;&#8221; at 512 or anywhere else in my TLA plugin. I went to the TLA site and downloaded a brand new plug-in to see if it had changed and it&#8217;s nowhere to be found in that file either.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SarahG</title>
		<link>http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/comment-page-1#comment-6499</link>
		<dc:creator>SarahG</dc:creator>
		<pubDate>Fri, 18 Jan 2008 14:57:02 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/#comment-6499</guid>
		<description>Ah re-reading your comment and the post an additional S has crept into the link, a simple typing error at a guess. I doubt that was intentional. My apologies, I was checking on www.textlinkads.com, no S after link and the whois gives TLA as owners.

With DK being in Europe (UK judging by his about content) and this domain owner being in the US, I doubt he&#039;d be feeding referrals to someone else on purpose (although he&#039;d have to confirm).</description>
		<content:encoded><![CDATA[<p>Ah re-reading your comment and the post an additional S has crept into the link, a simple typing error at a guess. I doubt that was intentional. My apologies, I was checking on <a href="http://www.textlinkads.com" rel="nofollow">http://www.textlinkads.com</a>, no S after link and the whois gives TLA as owners.</p>
<p>With DK being in Europe (UK judging by his about content) and this domain owner being in the US, I doubt he&#8217;d be feeding referrals to someone else on purpose (although he&#8217;d have to confirm).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathan</title>
		<link>http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/comment-page-1#comment-6496</link>
		<dc:creator>Jonathan</dc:creator>
		<pubDate>Fri, 18 Jan 2008 14:28:13 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/#comment-6496</guid>
		<description>SarahG,

Administrative Contact:
      Wong, Michael  
      Art Dacor USA LLC
      3727 West Magnolia Blvd
      #489
      Burbank, California 91505
      United States
      8186883292

Sure doesn&#039;t look like TextLinkAds.com&#039;s whois.

TLA does not own that domain.

I personally don&#039;t care, but a little disclosure would be nice.</description>
		<content:encoded><![CDATA[<p>SarahG,</p>
<p>Administrative Contact:<br />
      Wong, Michael<br />
      Art Dacor USA LLC<br />
      3727 West Magnolia Blvd<br />
      #489<br />
      Burbank, California 91505<br />
      United States<br />
      8186883292</p>
<p>Sure doesn&#8217;t look like TextLinkAds.com&#8217;s whois.</p>
<p>TLA does not own that domain.</p>
<p>I personally don&#8217;t care, but a little disclosure would be nice.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BlogSecurity &#187; Blog Archive &#187; WP TextLinkAds Plugin SQL Injection Vulnerability follow up</title>
		<link>http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/comment-page-1#comment-6492</link>
		<dc:creator>BlogSecurity &#187; Blog Archive &#187; WP TextLinkAds Plugin SQL Injection Vulnerability follow up</dc:creator>
		<pubDate>Fri, 18 Jan 2008 10:28:14 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/#comment-6492</guid>
		<description>[...] advisory has been updated accordingly.    &#160;&#160;&#160;  Enjoy the article? Please take a second to: [...]</description>
		<content:encoded><![CDATA[<p>[...] advisory has been updated accordingly.    &nbsp;&nbsp;&nbsp;  Enjoy the article? Please take a second to: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DK</title>
		<link>http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/comment-page-1#comment-6491</link>
		<dc:creator>DK</dc:creator>
		<pubDate>Fri, 18 Jan 2008 10:23:43 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/#comment-6491</guid>
		<description>Please note, SarahG kindly sent me this plugin (v3.0.8). There is some wierd stuff going on with the version but v3.0.8 is affected in the same way. I will the advisory accordingly.</description>
		<content:encoded><![CDATA[<p>Please note, SarahG kindly sent me this plugin (v3.0.8). There is some wierd stuff going on with the version but v3.0.8 is affected in the same way. I will the advisory accordingly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SarahG</title>
		<link>http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/comment-page-1#comment-6490</link>
		<dc:creator>SarahG</dc:creator>
		<pubDate>Fri, 18 Jan 2008 09:39:03 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/#comment-6490</guid>
		<description>Johnathan, like all good businesses, TLA own both the hypenated and unhyphenated versions. There&#039;s no referral link in DK&#039;s post. Try a whois on the domain to be sure.</description>
		<content:encoded><![CDATA[<p>Johnathan, like all good businesses, TLA own both the hypenated and unhyphenated versions. There&#8217;s no referral link in DK&#8217;s post. Try a whois on the domain to be sure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BloggingTom</title>
		<link>http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/comment-page-1#comment-6486</link>
		<dc:creator>BloggingTom</dc:creator>
		<pubDate>Fri, 18 Jan 2008 06:42:57 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/#comment-6486</guid>
		<description>Well, i just checked it too with the same options SarahG has choosed. Now it is version 3.0.9. I&#039;ll send you an email with the plugin...

And about Jonathan: He&#039;s just complaining about the link in the text above which links to textlinksads.com instead of text-link-ads.com...</description>
		<content:encoded><![CDATA[<p>Well, i just checked it too with the same options SarahG has choosed. Now it is version 3.0.9. I&#8217;ll send you an email with the plugin&#8230;</p>
<p>And about Jonathan: He&#8217;s just complaining about the link in the text above which links to textlinksads.com instead of text-link-ads.com&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathan</title>
		<link>http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/comment-page-1#comment-6482</link>
		<dc:creator>Jonathan</dc:creator>
		<pubDate>Thu, 17 Jan 2008 22:16:15 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/#comment-6482</guid>
		<description>DK,

I&#039;m just wondering, what is textlinkSads.com? isn&#039;t the domain text-link-ads.com?</description>
		<content:encoded><![CDATA[<p>DK,</p>
<p>I&#8217;m just wondering, what is textlinkSads.com? isn&#8217;t the domain text-link-ads.com?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
