<?xml version="1.0" encoding="US-ASCII"?>
<rss version="2.0">

<channel>
<title>Acunetix Web Applications Vulnerabilities Listing</title>
<link>http://www.acunetix.com/web-vulnerabilities/</link>
<description>Listing of known Web Application vulnerabilities with links to short descriptions.</description>
<language>en-us</language>
<copyright>Copyright 2007 2007 Acunetix All rights reserved. </copyright>
<managingEditor>info@acunetix.com</managingEditor>
<webMaster>info@acunetix.com</webMaster>





<item>
<title>Zomplog v.3.7.6 Local File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Zomplog-v.3.7.6-Local-Fil.htm</link>
<description>
<![CDATA[
Input passed to the "settings[skin]" in "/themes/default/index.php" parameter isn't properly verified, before it is used to include files. ...continued ...
]]>
</description>
<pubDate>Wed, 23 May 2007 23:07:01 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Zomplog-v.3.7.6-Local-Fil.htm</guid>
</item>



<item>
<title>Zomplog 3.4 SQL Injection and Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Zomplog-3.4-SQL-Injection.htm</link>
<description>
<![CDATA[
Input passed to the "id" parameter in "detail.php", and the "catid" parameter in "get.php" and "index.php" isn't properly sanitised before being used in a SQL query. ...continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 23:05:31 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Zomplog-3.4-SQL-Injection.htm</guid>
</item>



<item>
<title>Zeroboard v.4.1.pl5 Multiple Remoote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Zeroboard-v.4.1.pl5-Multi.htm</link>
<description>
<![CDATA[
Input passed to the "dir" parameter in "error.php", "login.php", "setup.php", "ask_password.php" and "print_category.php" isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 23:03:47 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Zeroboard-v.4.1.pl5-Multi.htm</guid>
</item>



<item>
<title>Zend Cart 1.2.6 admin_email SQL Injection Vulnerability Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Zend-Cart-1.2.6-admin_ema.htm</link>
<description>
<![CDATA[
Input passed to the "admin_email" parameter in "admin/password_forgotten.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 23:02:16 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Zend-Cart-1.2.6-admin_ema.htm</guid>
</item>



<item>
<title>YACS v.6.6.1 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/YACS-v.6.6.1-File-Inclusi.htm</link>
<description>
<![CDATA[
Input passed to the "context[path_to_root]" parameter in "/articles/article.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 23:00:47 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/YACS-v.6.6.1-File-Inclusi.htm</guid>
</item>



<item>
<title>Cross Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Cross-Site-Scripting.htm</link>
<description>
<![CDATA[
This script is possibly vulnerable to Cross Site Scripting (XSS) attacks....continued...<br />
]]>
</description>
<pubDate>Wed, 23 May 2007 22:57:55 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Cross-Site-Scripting.htm</guid>
</item>



<item>
<title>XOOPS v.2.0.11 SQL Injection and Authentification Bypass Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/XOOPS-v.2.0.11-SQL-Inject.htm</link>
<description>
<![CDATA[
The problem with XMLRPC in xoops is lack of sanitation...continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:56:15 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/XOOPS-v.2.0.11-SQL-Inject.htm</guid>
</item>



<item>
<title>XHP CMS v.0.5 File Upload Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/XHP-CMS-v.0.5-File-Upload.htm</link>
<description>
<![CDATA[
Access to the filemanager plugins "inc/htmlarea/plugins/FileManager/manager.php" and "inc/htmlarea/plugins/FileManager/standalonemanager.php" is not properly restricted....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:54:38 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/XHP-CMS-v.0.5-File-Upload.htm</guid>
</item>



<item>
<title>XHP CMS v.0.5.1 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/XHP-CMS-v.0.5.1-Cross-Sit.htm</link>
<description>
<![CDATA[
Input passed to the "errcode" parameter in "ondex.php" is not properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:53:27 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/XHP-CMS-v.0.5.1-Cross-Sit.htm</guid>
</item>



<item>
<title>WWWThreads Forum Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/WWWThreads-Forum-Cross-Si.htm</link>
<description>
<![CDATA[
Input passed to the "week"parameter in "calendar.php" is not properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:52:10 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/WWWThreads-Forum-Cross-Si.htm</guid>
</item>



<item>
<title>XPath Injection vulnerability Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/XPath-Injection-vulnerabi.htm</link>
<description>
<![CDATA[
This web service is possibly vulnerable to XPath Injection attacks....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:50:58 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/XPath-Injection-vulnerabi.htm</guid>
</item>



<item>
<title>WSN Forum 1.21 id SQL Injection Vulnerability Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/WSNForum-1.21-id-SQL-Inje.htm</link>
<description>
<![CDATA[
Input passed to the "id" parameter in "memberlist.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:49:29 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/WSNForum-1.21-id-SQL-Inje.htm</guid>
</item>



<item>
<title>Directories with write permissions enabled Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Directories-with-write-pe.htm</link>
<description>
<![CDATA[
Web Scanner was able to create a test file in this directory....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:48:09 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Directories-with-write-pe.htm</guid>
</item>



<item>
<title>WoWRoster v.1.5.0 Remote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/WoWRoster-v.1.5.0-Remote-.htm</link>
<description>
<![CDATA[
Input passed to the "subdir" parameter in "conf.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:46:53 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/WoWRoster-v.1.5.0-Remote-.htm</guid>
</item>



<item>
<title>WordPress v.2.1.2 (year) Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/WordPress-v.2.1.2--Cross-.htm</link>
<description>
<![CDATA[
Input passed to the "year" parameter in "index.php" is not properly sanitised before being used....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:45:29 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/WordPress-v.2.1.2--Cross-.htm</guid>
</item>



<item>
<title>WordPress v.2.1.1 - Compromised Installation Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/WordPress-v.2.1.1-Comprom.htm</link>
<description>
<![CDATA[
The WordPress source code has been compromised by a third party in order to enable remote command execution on the machines running affected versions....continued...<br />
]]>
</description>
<pubDate>Wed, 23 May 2007 22:43:47 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/WordPress-v.2.1.1-Comprom.htm</guid>
</item>



<item>
<title>WordPress v.2.0.5 Trackback UTF-7 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/WordPress-v.2.0.5-Trackba.htm</link>
<description>
<![CDATA[
WordPress supports decoding trackbacks with different charsets when PHP's mbstring extension is activated....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:40:25 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/WordPress-v.2.0.5-Trackba.htm</guid>
</item>



<item>
<title>WordPress v.2.0.3 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/WordPress-v.2.0.3-SQL-Inj.htm</link>
<description>
<![CDATA[
Input passed to the "paged" parameter in "index.php" is not properly sanitised before being used in SQL queries....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:39:01 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/WordPress-v.2.0.3-SQL-Inj.htm</guid>
</item>



<item>
<title>WordPress_v.2.0.1_Path_Disclosure.xml Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/WordPress_v.2.0.1_Path_Di.htm</link>
<description>
<![CDATA[
Full path disclosure...continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:37:22 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/WordPress_v.2.0.1_Path_Di.htm</guid>
</item>



<item>
<title>Wordcircle v.2.14 SQL Injection, Login Bypass and Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Wordcircle-v.2.14-SQL-Inj.htm</link>
<description>
<![CDATA[
Input passed to the course name field when adding a new course isn't properly sanitised before being used....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:35:59 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Wordcircle-v.2.14-SQL-Inj.htm</guid>
</item>



<item>
<title>WizForum 1.20 Multiple SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/WizForum-1.20-Multiple-SQ.htm</link>
<description>
<![CDATA[
Input passed to the "AuthID" parameter in ForumAuthDetails.php isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:34:25 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/WizForum-1.20-Multiple-SQ.htm</guid>
</item>



<item>
<title>Wili-CMS v.0.11 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Wili-CMS-v.0.11-File-Incl.htm</link>
<description>
<![CDATA[
Input passed to the "globals[content_dir]" parameter in "/templates/dates_list.php", "example-view/templates/root.php" and "example-view/templates/article.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:33:07 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Wili-CMS-v.0.11-File-Incl.htm</guid>
</item>



<item>
<title>WhiteAlbum v.2.5 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/WhiteAlbum-v.2.5-SQL-Inje.htm</link>
<description>
<![CDATA[
Input passed to the "dir" parameter in "pictures.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:31:40 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/WhiteAlbum-v.2.5-SQL-Inje.htm</guid>
</item>



<item>
<title>Web Wiz Forums v.8.05 (MySQL version) SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Web-Wiz-Forums-v.8.05--SQ.htm</link>
<description>
<![CDATA[
Input passed to the "name" parameter in "pop_up_member_search.asp" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:30:16 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Web-Wiz-Forums-v.8.05--SQ.htm</guid>
</item>



<item>
<title>Web server default welcome page Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Web-server-default-welcom.htm</link>
<description>
<![CDATA[
This web server has a default welcome page....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:28:57 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Web-server-default-welcom.htm</guid>
</item>



<item>
<title>Web Quiz Pro v.1.0 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/WebQuiz-Pro-v.1.0-Cross-S.htm</link>
<description>
<![CDATA[
Input passed to the "exam" parameter in "prequiz.asp" and to the "msg" parameter in "student.asp" is not properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:27:32 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/WebQuiz-Pro-v.1.0-Cross-S.htm</guid>
</item>



<item>
<title>Web Content System v.2.7.1 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Web-Content-System-v.2.7..htm</link>
<description>
<![CDATA[
Input passed to the "path[JavascriptEdit]" parameter in "/manage/javascript/formjavascript.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:25:22 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Web-Content-System-v.2.7..htm</guid>
</item>



<item>
<title>WebspotBlogging v.3.0 SQL Injection and Login Bypass Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/WebspotBlogging-v.3.0-SQL.htm</link>
<description>
<![CDATA[
Input passed to the "username" parameter in "login.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:24:03 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/WebspotBlogging-v.3.0-SQL.htm</guid>
</item>



<item>
<title>Webspell v.4.01.02 Local File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Webspell-v.4.01.02-Local-.htm</link>
<description>
<![CDATA[
Input passed to the "id" parameter in "picture.php" isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:22:51 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Webspell-v.4.01.02-Local-.htm</guid>
</item>



<item>
<title>Webspell v.4.01.01 Database Data Disclosure Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Webspell-v.4.01.01-Databa.htm</link>
<description>
<![CDATA[
The database attached to this CMS can be downloaded...continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:21:07 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Webspell-v.4.01.01-Databa.htm</guid>
</item>



<item>
<title>WebDAV Enabled Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/WebDAV-Enabled.htm</link>
<description>
<![CDATA[
WebDAV is an extension to the HTTP protocol....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:20:14 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/WebDAV-Enabled.htm</guid>
</item>



<item>
<title>WebCalendar v.1.00 (send_reminders.php) Remote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/WebCalendar-v.1.00--Remot.htm</link>
<description>
<![CDATA[
Input passed to the "includedir" parameter in "/tools/send_reminders.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:18:56 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/WebCalendar-v.1.00--Remot.htm</guid>
</item>



<item>
<title>Web-News v.1.6.3 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Web-News-v.1.6.3-File-Inc.htm</link>
<description>
<![CDATA[
Input passed to the "content_page" parameter in "/template.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:17:45 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Web-News-v.1.6.3-File-Inc.htm</guid>
</item>



<item>
<title>W2B Online Banking Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/W2B-Online-Banking-Cross-.htm</link>
<description>
<![CDATA[
Input passed to the "SID" parameter is not properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:15:51 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/W2B-Online-Banking-Cross-.htm</guid>
</item>



<item>
<title>W-Agora v.4.2.1 Multiple Security Vulnerabilities</title>
<link>http://www.acunetix.com/vulnerabilities/W-Agora-v.4.2.1-Multiple-.htm</link>
<description>
<![CDATA[
The browse_avatar.php script fails to validate the extension of an uploaded file....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:14:35 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/W-Agora-v.4.2.1-Multiple-.htm</guid>
</item>



<item>
<title>W-Agora 4.2.0 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/W-Agora-4.2.0-Cross-Site-.htm</link>
<description>
<![CDATA[
Some input isn't properly sanitised before being used....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:13:25 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/W-Agora-4.2.0-Cross-Site-.htm</guid>
</item>



<item>
<title>VP-ASP Shopping Cart v.6.09 Multiple Security Vulnerabilities</title>
<link>http://www.acunetix.com/vulnerabilities/VP-ASP-Shopping-Cart-v.6..htm</link>
<description>
<![CDATA[
Input passed to the "LoginLastname" parameter in "shopgiftregsearch.asp" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:11:45 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/VP-ASP-Shopping-Cart-v.6..htm</guid>
</item>



<item>
<title>Vote Pro v.4.0 Remote Command Execution Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Vote-Pro-v.4.0-Remote-Com.htm</link>
<description>
<![CDATA[
Input passed to the "poll_id" parameter in "pool_frame.php" is not properly sanitised, before it is written to the web-accessible chat_log.php file....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:10:09 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Vote-Pro-v.4.0-Remote-Com.htm</guid>
</item>



<item>
<title>Videodb (Mambo component) v.0.3 Remote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Videodb--v.0.3-Remote-Fil.htm</link>
<description>
<![CDATA[
Input passed to the "mosConfig_absolute_path" parameter in "/administrator/components/com_videodb/core/videodb.class.xml.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:07:59 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Videodb--v.0.3-Remote-Fil.htm</guid>
</item>



<item>
<title>Vego Links Builder v.2.00 SQL Injection and Login Bypass Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Vego-Links-Builder-v.2.00.htm</link>
<description>
<![CDATA[
Input passed to the "username" parameter when logging in isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:06:18 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Vego-Links-Builder-v.2.00.htm</guid>
</item>



<item>
<title>URL redirection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/URL-redirection.htm</link>
<description>
<![CDATA[
This script is possibly vulnerable to URL redirection attacks....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:05:20 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/URL-redirection.htm</guid>
</item>



<item>
<title>Unfiltered Header Injection in Apache 1.3.34/2.0.57/2.2.1 Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Unfiltered-Header-Injecti.htm</link>
<description>
<![CDATA[
This version of Apache is vulnerable to HTML injection (includingmalicious Javascript code) through "Expect" header....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:03:03 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Unfiltered-Header-Injecti.htm</guid>
</item>



<item>
<title>Typo3 v.3.8.1 Path Disclosure Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Typo3-v.3.8.1-Path-Disclo.htm</link>
<description>
<![CDATA[
The problem is that it is possible to disclose the full path to "typo3/t3lib/thumbs.php" by accessing it directly....continued...<br />
]]>
</description>
<pubDate>Wed, 23 May 2007 22:01:43 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Typo3-v.3.8.1-Path-Disclo.htm</guid>
</item>



<item>
<title>TWiki rev Parameter Remote Command Execution Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/TWiki-rev-Parameter-Remot.htm</link>
<description>
<![CDATA[
A remote command execution vulnerability affects the application....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 22:00:21 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/TWiki-rev-Parameter-Remot.htm</guid>
</item>



<item>
<title>Trojan shell script Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Trojan-shell-script.htm</link>
<description>
<![CDATA[
A trojan shell script has been found....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:58:25 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Trojan-shell-script.htm</guid>
</item>



<item>
<title>TRACK method is enabled Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/TRACK-method-is-enabled.htm</link>
<description>
<![CDATA[
HTTP TRACK method is enabled on this web server. In the presence of other cross-domain vulnerabilities in web browsers,...continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:56:53 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/TRACK-method-is-enabled.htm</guid>
</item>



<item>
<title>TRACE method is enabled Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/TRACE-method-is-enabled.htm</link>
<description>
<![CDATA[
HTTP TRACE method is enabled on this web server....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:55:06 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/TRACE-method-is-enabled.htm</guid>
</item>



<item>
<title>TOPo v.2.2.178 Remote Code Execution Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/TOPo-v.2.2.178-Remote-Cod.htm</link>
<description>
<![CDATA[
Input passed when adding a new site is not properly sanitised before being used....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:53:54 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/TOPo-v.2.2.178-Remote-Cod.htm</guid>
</item>



<item>
<title>TOPo v.2.2.178 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/TOPo-v.2.2.178-Cross-Site.htm</link>
<description>
<![CDATA[
Input passed to the "gTopNombre" parameter in "code/inc_header.php" is not properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:52:28 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/TOPo-v.2.2.178-Cross-Site.htm</guid>
</item>



<item>
<title>ToendaCMS v.1.0.0 (FckEditor) File Upload Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/ToendaCMS-v.1.0.0--File-U.htm</link>
<description>
<![CDATA[
Access to the FckEditor "/engine/js/FCKeditor/editor/filemanager/browser/default/connectors/php/connector.php" is not properly restricted....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:51:02 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/ToendaCMS-v.1.0.0--File-U.htm</guid>
</item>



<item>
<title>Toast Forums v.1.6 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Toast-Forums-v.1.6-Cross-.htm</link>
<description>
<![CDATA[
Some input isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:49:05 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Toast-Forums-v.1.6-Cross-.htm</guid>
</item>



<item>
<title>Timesheet PHP 1.2.1 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Timesheet-PHP-1.2.1-SQL-I.htm</link>
<description>
<![CDATA[
Input passed to the "username" parameter in "login.php" is not properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:47:26 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Timesheet-PHP-1.2.1-SQL-I.htm</guid>
</item>



<item>
<title>Tim-online PHPBB v1.2.4RC3 (Mambo component) Remote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Tim-online-PHPBB-v1.2.4RC.htm</link>
<description>
<![CDATA[
Input passed to the "phpbb_root_path" parameter in "download.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:45:52 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Tim-online-PHPBB-v1.2.4RC.htm</guid>
</item>



<item>
<title>Tiki Wiki v.1.9.4 JHot.PHP Remote Command Execution Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Tiki-Wiki-v.1.9.4JHot.PHP.htm</link>
<description>
<![CDATA[
TikiWiki is prone to a remote command-execution vulnerability by alowing arbitrary PHP script files upload on the webserver via "jhot.php"....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:44:14 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Tiki-Wiki-v.1.9.4JHot.PHP.htm</guid>
</item>



<item>
<title>Tiki Wiki v.1.9.3.1 Cros-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Tiki-Wiki-v.1.9.3.1-Cros-.htm</link>
<description>
<![CDATA[
Input passed to the "days" and "offset" parameters in tiki-lastchanges.php, "find" parameter in tiki-orphan_pages.php...continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:42:49 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Tiki-Wiki-v.1.9.3.1-Cros-.htm</guid>
</item>



<item>
<title>Thyme v.1.3 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Thyme-v.1.3-Cross-Site-Sc.htm</link>
<description>
<![CDATA[
Input passed to the "searchfor" parameter in the "Search Events" field is not properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:41:42 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Thyme-v.1.3-Cross-Site-Sc.htm</guid>
</item>



<item>
<title>Techno Dreams Products login.asp SQL Injection Vulnerability Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Techno-Dreams-Productslog.htm</link>
<description>
<![CDATA[
Some input passed to "login.asp" when logging in isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:39:11 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Techno-Dreams-Productslog.htm</guid>
</item>



<item>
<title>Teca Diary Personal Edition v.1.0 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Teca-Diary-Personal-Editi.htm</link>
<description>
<![CDATA[
Input passed to the "yy", "mm", and "dd" parameters in "functions.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:37:29 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Teca-Diary-Personal-Editi.htm</guid>
</item>



<item>
<title>TeamCal Pro v.2.8.001 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/TeamCal-Pro-v.2.8.001-Fil.htm</link>
<description>
<![CDATA[
Input passed to the "tc_config[app_root]" parameter in "/includes/footer.html.inc.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:35:58 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/TeamCal-Pro-v.2.8.001-Fil.htm</guid>
</item>



<item>
<title>SZUserMgnt v.1.4. SQL Injection and login Bypass Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/SZUserMgnt-v.1.4.-SQL-Inj.htm</link>
<description>
<![CDATA[
Input passed to the "username" parameter in "login.verify.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:34:01 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/SZUserMgnt-v.1.4.-SQL-Inj.htm</guid>
</item>



<item>
<title>Survey System 1.1 SURVEY_ID parameter SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Survey-System-1.1-SURVEY_.htm</link>
<description>
<![CDATA[
Input passed to the "SURVEY_ID" parameter in "survey.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:32:16 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Survey-System-1.1-SURVEY_.htm</guid>
</item>



<item>
<title>SunShop Shopping Cart v.3.5 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/SunShop-Shopping-Cart-v.3.htm</link>
<description>
<![CDATA[
Input passed to the "action", "id", "prevaction","previd","prevstart", and "itemid" parameters in index.php is not properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:30:51 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/SunShop-Shopping-Cart-v.3.htm</guid>
</item>



<item>
<title>ssCMS v.2.1.0 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/ssCMS-v.2.1.0-Cross-Site-.htm</link>
<description>
<![CDATA[
Input passed to the "keywords" parameter in the search functionality is not properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:29:40 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/ssCMS-v.2.1.0-Cross-Site-.htm</guid>
</item>



<item>
<title>SQuery v.4.5 (phpNuke module) Remote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/SQuery-v.4.5--Remote-File.htm</link>
<description>
<![CDATA[
Input passed to the "libpath" parameter in "gore.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:27:30 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/SQuery-v.4.5--Remote-File.htm</guid>
</item>



<item>
<title>SQL injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/SQL-Injection.htm</link>
<description>
<![CDATA[
This script is possibly vulnerable to SQL Injection attacks....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:25:10 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/SQL-Injection.htm</guid>
</item>



<item>
<title>Source code disclosure Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Source-code-disclosure.htm</link>
<description>
<![CDATA[
Looks like the source code for this script is available....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:24:11 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Source-code-disclosure.htm</guid>
</item>



<item>
<title>SmartSiteCMS v1.0 Remote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/SmartSiteCMS-v1.0-Remote-.htm</link>
<description>
<![CDATA[
Input passed to the "root" parameter in "test.php", comment.php", "index.php" and "inc_adminfoot.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:22:41 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/SmartSiteCMS-v1.0-Remote-.htm</guid>
</item>



<item>
<title>SKForum v.1.5 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/SKForum-v.1.5-Cross-Site-.htm</link>
<description>
<![CDATA[
Input passed to the "areaID", "time", and "userID" parameters is not properly sanitised before being returned to the user.&nbsp;...continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:20:24 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/SKForum-v.1.5-Cross-Site-.htm</guid>
</item>



<item>
<title>SiteEnable v.3.3 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/SiteEnable-v.3.3-Cross-Si.htm</link>
<description>
<![CDATA[
Input passed to the "ret_page" parameter in "login.asp" isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:19:00 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/SiteEnable-v.3.3-Cross-Si.htm</guid>
</item>



<item>
<title>Simplog v.0.9.1 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Simplog-v.0.9.1-File-Incl.htm</link>
<description>
<![CDATA[
Input passed to the "s" parameter in "/doc/index.php" isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:17:46 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Simplog-v.0.9.1-File-Incl.htm</guid>
</item>



<item>
<title>Simplog v.0.9.1 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Simplog-v.0.9.1-Cross-Sit.htm</link>
<description>
<![CDATA[
Input passed to the "btag" parameter in "login.php" is not properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Wed, 23 May 2007 21:16:17 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Simplog-v.0.9.1-Cross-Sit.htm</guid>
</item>



<item>
<title>Simplog SQL Injection Security Vulnerabilities</title>
<link>http://www.acunetix.com/vulnerabilities/Simplog-SQL-Injection-Vul.htm</link>
<description>
<![CDATA[
Vulnerability in Simplog, which can be exploited by malicious people to conduct SQL injection attacks....continued...<br />
]]>
</description>
<pubDate>Wed, 23 May 2007 21:14:57 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Simplog-SQL-Injection-Vul.htm</guid>
</item>



<item>
<title>Simple PHP Blog v.0.4.7.1 Local File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Simple-PHP-Blog-v.0.4.7.1.htm</link>
<description>
<![CDATA[
Input passed to the "blog_language" parameter in "install05.php" isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Tue, 22 May 2007 00:13:57 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Simple-PHP-Blog-v.0.4.7.1.htm</guid>
</item>



<item>
<title>Simpleboard v1.1.0 (Mambo component) Remote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Simpleboard-v1.1.0--Remot.htm</link>
<description>
<![CDATA[
Input passed to the "sbp" parameter in "image_upload.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Tue, 22 May 2007 00:12:26 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Simpleboard-v1.1.0--Remot.htm</guid>
</item>



<item>
<title>SimpleBlog v.3.0 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/SimpleBlog-v.3.0-SQL-Inje.htm</link>
<description>
<![CDATA[
Input passed to the "id" parameter in "/admin/approveComment.asp" is not properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Tue, 22 May 2007 00:11:04 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/SimpleBlog-v.3.0-SQL-Inje.htm</guid>
</item>



<item>
<title>SimpleBlog v.2.1 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/SimpleBlog-v.2.1-SQL-Inje.htm</link>
<description>
<![CDATA[
Input passed to the "month" parameter isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Tue, 22 May 2007 00:09:42 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/SimpleBlog-v.2.1-SQL-Inje.htm</guid>
</item>



<item>
<title>SimpleBBS v.1.1 name PHP Code Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/SimpleBBS-v.1.1-name-PHP-.htm</link>
<description>
<![CDATA[
Input passed to the "name" parameter when adding a new topic isn't properly sanitised before being stored in a PHP script....continued...
]]>
</description>
<pubDate>Tue, 22 May 2007 00:08:26 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/SimpleBBS-v.1.1-name-PHP-.htm</guid>
</item>



<item>
<title>Signkorn Guestbook v.1.1 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Signkorn-Guestbook-v.1.1-.htm</link>
<description>
<![CDATA[
Input passed to the "dir_path" parameter in "/includes/log.inc.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Tue, 22 May 2007 00:07:01 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Signkorn-Guestbook-v.1.1-.htm</guid>
</item>



<item>
<title>Sensitive data not encrypted Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Sensitive-data-not-encryp.htm</link>
<description>
<![CDATA[
Sensitive data such as credit card numbers, social security numbers are sent without using an encrypted connection....continued...
]]>
</description>
<pubDate>Tue, 22 May 2007 00:05:42 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Sensitive-data-not-encryp.htm</guid>
</item>



<item>
<title>SendCard v.3.4.0 Unautorized Administrative Access Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/SendCard-v.3.4.0-Unautori.htm</link>
<description>
<![CDATA[
All administrative script on wrong or no authentication return 302 and try to redirect the user to login panel....continued...
]]>
</description>
<pubDate>Tue, 22 May 2007 00:04:22 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/SendCard-v.3.4.0-Unautori.htm</guid>
</item>



<item>
<title>sCssBoard 1.12 search_term Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/sCssBoard-1.12-search_ter.htm</link>
<description>
<![CDATA[
Input passed to the "search_term" parameter when performing a search isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Tue, 22 May 2007 00:02:59 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/sCssBoard-1.12-search_ter.htm</guid>
</item>



<item>
<title>Script source code disclosure Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Script-source-code-disclo.htm</link>
<description>
<![CDATA[
It is possible to read the source code of this script by using script filename as a parameter....continued...
]]>
</description>
<pubDate>Tue, 22 May 2007 00:01:49 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Script-source-code-disclo.htm</guid>
</item>



<item>
<title>ScriptMagix Recipes v.2.0 Multiple SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/ScriptMagix-Recipes-v.2.0.htm</link>
<description>
<![CDATA[
Input passed to the "recid" and "catid" parameters in "index.php" are not properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Tue, 22 May 2007 00:00:06 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/ScriptMagix-Recipes-v.2.0.htm</guid>
</item>



<item>
<title>ScriptMagix Lyrics v.2.0 (recid) SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/ScriptMagix-Lyrics-v.2.0-.htm</link>
<description>
<![CDATA[
Input passed to the "recid" and "catid" parameters in "index.php" are not properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:58:30 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/ScriptMagix-Lyrics-v.2.0-.htm</guid>
</item>



<item>
<title>ScriptMagix Jokes v.2.0 Multiple SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/ScriptMagix-Jokes-v.2.0-M.htm</link>
<description>
<![CDATA[
Input passed to the "recid" and "catid" parameters in "index.php" are not properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:56:59 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/ScriptMagix-Jokes-v.2.0-M.htm</guid>
</item>



<item>
<title>SazCart v.1.5 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/SazCart-v.1.5-File-Inclus.htm</link>
<description>
<![CDATA[
Input passed to the "_saz[settings][shippingfolder]" in "/admin/controls/cart.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:55:44 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/SazCart-v.1.5-File-Inclus.htm</guid>
</item>



<item>
<title>SaveWebPortal v.3.4 Remote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/SaveWebPortal-v.3.4-Remot.htm</link>
<description>
<![CDATA[
Input passed to the "SITE_Path" parameter in "/menu_dx.php", "/poll/poll.php" and "/poll/view_polls.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:54:26 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/SaveWebPortal-v.3.4-Remot.htm</guid>
</item>



<item>
<title>SAPID CMS v.1.23rc3 Remote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/SAPID-CMS-v.1.23rc3-Remot.htm</link>
<description>
<![CDATA[
Input passed to the "SITE_Path" parameter in "/menu_dx.php", "/poll/poll.php" and "/poll/view_polls.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:53:05 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/SAPID-CMS-v.1.23rc3-Remot.htm</guid>
</item>



<item>
<title>RunCMS v.1.3a5 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/RunCMS-v.1.3a5-Cross-Site.htm</link>
<description>
<![CDATA[
Input passed to the "lid" parameter in "ratefile.php" isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:51:23 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/RunCMS-v.1.3a5-Cross-Site.htm</guid>
</item>



<item>
<title>Qwiki v.1.5.1 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Qwiki-v.1.5.1-Cross-Site-.htm</link>
<description>
<![CDATA[
Some input isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:49:08 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Qwiki-v.1.5.1-Cross-Site-.htm</guid>
</item>



<item>
<title>QuizShock v.1.6.1 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/QuizShock-v.1.6.1-Cross-S.htm</link>
<description>
<![CDATA[
Input passed to the "forward_to" parameter in "auth.php" is not properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:46:06 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/QuizShock-v.1.6.1-Cross-S.htm</guid>
</item>



<item>
<title>QuickEStore v.7.9 SQL Injection and Path Diclosure Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/QuickEStore-v.7.9-SQL-Inj.htm</link>
<description>
<![CDATA[
Input passed to the "CategoryID" parameter in prodpage.cfm, the "SubCatID" parameter in index.cfm, the "OrderID" parameter in shipping.cfm, and to the "ItemID" parameter in proddetail.cfm is not properly sanitised before being used in SQL queries....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:44:16 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/QuickEStore-v.7.9-SQL-Inj.htm</guid>
</item>



<item>
<title>QontentOneCMS v1.0 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/QontentOneCMS-v1.0-Cross-.htm</link>
<description>
<![CDATA[
Input passed to search_phrase parameter search.php is not properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:42:47 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/QontentOneCMS-v1.0-Cross-.htm</guid>
</item>



<item>
<title>PUT Method Enabled Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PUT-Method-Enabled.htm</link>
<description>
<![CDATA[
PUT Method is enabled on the root directory of this web server....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:41:23 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PUT-Method-Enabled.htm</guid>
</item>



<item>
<title>Publicist v.0.95 SQL Injection, Path Disclosure and Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Publicist-v.0.95-SQL-Inje.htm</link>
<description>
<![CDATA[
Input passed to the "return" parameter in info.php, "visa" parameter in hitlist_editorial_public_info.php, "search" in search.php and "account" in left.php is not properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:39:50 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Publicist-v.0.95-SQL-Inje.htm</guid>
</item>



<item>
<title>ProjectApp_v.3.3_Cross-Site_Scripting.xml Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/ProjectApp_v.3.3_Cross-Si.htm</link>
<description>
<![CDATA[
Input passed to the "keywords" parameter in "forums.asp", "search_employees.asp", "cat.asp", and "links.asp", the "projectid" parameter in "pmprojects.asp", the "ret_page" parameter in "login.asp", and the "skin_number" parameter in "default.asp" isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:38:01 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/ProjectApp_v.3.3_Cross-Si.htm</guid>
</item>



<item>
<title>PRINTER ISAPI filter mapped Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PRINTER-ISAPI-filter-mapp.htm</link>
<description>
<![CDATA[
.PRINTER ISAPI filter mapped on this web server....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:35:21 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PRINTER-ISAPI-filter-mapp.htm</guid>
</item>



<item>
<title>pppBlog v.0.3.8 Local File Disclosure Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/pppBlog-v.0.3.8-Local-Fil.htm</link>
<description>
<![CDATA[
Input passed to the files parameter in randompic.php isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:33:33 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/pppBlog-v.0.3.8-Local-Fil.htm</guid>
</item>



<item>
<title>Possible sensitive files Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Possible-sensitive-files.htm</link>
<description>
<![CDATA[
A possible sensitive directory has been found....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:32:19 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Possible-sensitive-files.htm</guid>
</item>



<item>
<title>PortalApp v.3.3 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PortalApp-v.3.3-Cross-Sit.htm</link>
<description>
<![CDATA[
Input passed to the "ret_page" parameter in "login.asp" isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:30:55 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PortalApp-v.3.3-Cross-Sit.htm</guid>
</item>



<item>
<title>Popper v.1.41.r2 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Popper-v.1.41.r2-File-Inc.htm</link>
<description>
<![CDATA[
Input passed to the "form" parameter in "childwindow.inc.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:29:05 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Popper-v.1.41.r2-File-Inc.htm</guid>
</item>



<item>
<title>PmWiki v.2.1.19 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PmWiki-v.2.1.19-File-Incl.htm</link>
<description>
<![CDATA[
PmWiki is prone to a remote file inclusion exploit if your version of PHP is vulnerable to the Zend_Hash_Del_Key_Or_Index vulnerability reported by Stefan Esser from Hardened PHP Project....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:27:00 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PmWiki-v.2.1.19-File-Incl.htm</guid>
</item>



<item>
<title>PmWiki 2.0.12 q-Parameter Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PmWiki-2.0.12-q-Parameter.htm</link>
<description>
<![CDATA[
Input passed to the "q" parameter in "Site.Search" isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:25:22 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PmWiki-2.0.12-q-Parameter.htm</guid>
</item>



<item>
<title>PluggedOut Blog v.1.9.9c SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PluggedOut-Blog-v.1.9.9c-.htm</link>
<description>
<![CDATA[
Input passed to the "entryid" parameter in "exec.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:23:55 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PluggedOut-Blog-v.1.9.9c-.htm</guid>
</item>



<item>
<title>Pivot v1.30 RC2 Multiple Input Validation Security Vulnerabilities</title>
<link>http://www.acunetix.com/vulnerabilities/Pivot-v1.30-RC2-Multiple-.htm</link>
<description>
<![CDATA[
Pivot is prone to multiple input-validation vulnerabilities, including remote file-include (on PHP5), local file-include, cross-site scripting, and privilege-escalation issues....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:22:05 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Pivot-v1.30-RC2-Multiple-.htm</guid>
</item>



<item>
<title>PHP version older than 5.2.1 Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-version-older-than-5..htm</link>
<description>
<![CDATA[
This alert was generated using only banner information....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:18:29 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-version-older-than-5..htm</guid>
</item>



<item>
<title>PHP version older than 4.4.1 Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-version-older-than-4.-2.htm</link>
<description>
<![CDATA[
This alert was generated using only banner information....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:16:00 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-version-older-than-4.-2.htm</guid>
</item>



<item>
<title>PHP version older than 4.3.8 Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-version-older-than-4..htm</link>
<description>
<![CDATA[
This alert was generated using only banner information....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:13:28 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-version-older-than-4..htm</guid>
</item>



<item>
<title>PHP upload arbitrary file disclosure vulnerability Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-upload-arbitrary-file.htm</link>
<description>
<![CDATA[
This alert was generated using only banner information....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:11:29 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-upload-arbitrary-file.htm</guid>
</item>



<item>
<title>PHP unspecified remote arbitrary file upload vulnerability Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-unspecified-remote-ar.htm</link>
<description>
<![CDATA[
This alert was generated using only banner information....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:08:21 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-unspecified-remote-ar.htm</guid>
</item>



<item>
<title>PHP undefined Safe_Mode_Include_Dir safemode bypass Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-undefined-Safe_Mode_I.htm</link>
<description>
<![CDATA[
This alert was generated using only banner information....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:05:14 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-undefined-Safe_Mode_I.htm</guid>
</item>



<item>
<title>PHP socket_iovec_alloc() integer overflow Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-socket_iovec_alloc-in.htm</link>
<description>
<![CDATA[
This alert was generated using only banner information....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:03:09 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-socket_iovec_alloc-in.htm</guid>
</item>



<item>
<title>PHP Simple Shop v.2.0 Remote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-Simple-Shop-v.2.0-Rem.htm</link>
<description>
<![CDATA[
Input passed to the "abs_path" parameter in "/admin/index.php", "/admin/adminindex.php", "/admin/login.php", "/admin/menu.php", "/admin/header.php" and "/admin/adminglobal.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 23:00:30 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-Simple-Shop-v.2.0-Rem.htm</guid>
</item>



<item>
<title>PHP Safedir Restriction Bypass Vulnerabilities Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-Safedir-Restriction-B.htm</link>
<description>
<![CDATA[
This alert was generated using only banner information....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 22:58:59 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-Safedir-Restriction-B.htm</guid>
</item>



<item>
<title>PHP POST file upload buffer overflow vulnerabilities Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-POST-file-upload-buff.htm</link>
<description>
<![CDATA[
This alert was generated using only banner information....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 22:57:23 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-POST-file-upload-buff.htm</guid>
</item>



<item>
<title>PHP multiple vulnerabilities Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-multiple-vulnerabilit.htm</link>
<description>
<![CDATA[
This alert was generated using only banner information....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 22:54:56 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-multiple-vulnerabilit.htm</guid>
</item>



<item>
<title>PHP mail function ASCII control character header spoofing Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-mail-function-ASCII-c.htm</link>
<description>
<![CDATA[
This alert was generated using only banner information....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 22:52:29 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-mail-function-ASCII-c.htm</guid>
</item>



<item>
<title>PHP HTTP POST incorrect MIME header parsing Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-HTTP-POST-incorrect-M.htm</link>
<description>
<![CDATA[
This alert was generated using only banner information....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 22:50:19 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-HTTP-POST-incorrect-M.htm</guid>
</item>



<item>
<title>PHP HTML Entity Encoder Heap Overflow Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-HTML-Entity-Encoder-H.htm</link>
<description>
<![CDATA[
This alert was generated using only banner information....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 22:48:40 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-HTML-Entity-Encoder-H.htm</guid>
</item>



<item>
<title>PHP error logging format string Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-error-logging-format-.htm</link>
<description>
<![CDATA[
This alert was generated using only banner information. It may be a false positive....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 22:46:35 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-error-logging-format-.htm</guid>
</item>



<item>
<title>PHP code injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-code-injection.htm</link>
<description>
<![CDATA[
This script is vulnerable to PHP code injection....continued...<br />
]]>
</description>
<pubDate>Mon, 21 May 2007 22:45:12 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-code-injection.htm</guid>
</item>



<item>
<title>PHP Classifieds v.6.20 SQL Injection and Login Bypass Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-Classifieds-v.6.20-SQ.htm</link>
<description>
<![CDATA[
Input passed to the "username" and "password" parameters in member_login.php isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 22:43:12 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-Classifieds-v.6.20-SQ.htm</guid>
</item>



<item>
<title>PHP Classifieds v.6.20 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-Classifieds-v.6.20-Cr.htm</link>
<description>
<![CDATA[
Input passed to the "searchword" parameter in "search.php" isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 22:02:11 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-Classifieds-v.6.20-Cr.htm</guid>
</item>



<item>
<title>PHP Advanced Transfer Manager v.1.21 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-Advanced-Transfer-Man-3.htm</link>
<description>
<![CDATA[
Input passed to the "include_location" parameter in "confirm.php", "login.php" and "index.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:58:15 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-Advanced-Transfer-Man-3.htm</guid>
</item>



<item>
<title>PHP Advanced Transfer Manager System Disclosure and Remote Code Execution (Windows) Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-Advanced-Transfer-Man-2.htm</link>
<description>
<![CDATA[
The software does not properly validate user-supplied input in the 'currentdir' and 'current_dir' parameters....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:54:44 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-Advanced-Transfer-Man-2.htm</guid>
</item>



<item>
<title>PHP Advanced Transfer Manager System Disclosure and Remote Code Execution (Unix) Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-Advanced-Transfer-Man.htm</link>
<description>
<![CDATA[
The software does not properly validate user-supplied input in the 'currentdir' and 'current_dir' parameters....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:51:30 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-Advanced-Transfer-Man.htm</guid>
</item>



<item>
<title>PHP 4.3.0 file disclosure and possible code execution Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-4.3.0-file-disclosure.htm</link>
<description>
<![CDATA[
This alert was generated using only banner information....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:49:29 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-4.3.0-file-disclosure.htm</guid>
</item>



<item>
<title>PHPX v.3.5.15 Multiple SQL Injection and Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHPX-v.3.5.15-Multiple-SQ.htm</link>
<description>
<![CDATA[
Input passed to the "news_id" parameter in print.php; "keywords" in search.php; "cat_id", "topic_id" and "post_id" in forums.php; "cat_id" and "image_id" in gallery.php; "news_id" and "news_cat_id" in news.php; and "user_id" in users.php is not properly sanitised before being used in SQL queries....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:47:45 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHPX-v.3.5.15-Multiple-SQ.htm</guid>
</item>



<item>
<title>PhpWebThings 1.4.4 forum.php SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PhpWebThings-1.4.4-forum..htm</link>
<description>
<![CDATA[
Input passed to the "forum" parameter in "forum.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:46:25 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PhpWebThings-1.4.4-forum..htm</guid>
</item>



<item>
<title>phpWebFTP v.3.2 Local File Inclusion (windows) Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/phpWebFTP-v.3.2-Local-Fil-2.htm</link>
<description>
<![CDATA[
Input passed to to the "language" parameter in index.php isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:45:03 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/phpWebFTP-v.3.2-Local-Fil-2.htm</guid>
</item>



<item>
<title>phpWebFTP v.3.2 Local File Inclusion (unix) Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/phpWebFTP-v.3.2-Local-Fil.htm</link>
<description>
<![CDATA[
Input passed to to the "language" parameter in index.php isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:43:29 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/phpWebFTP-v.3.2-Local-Fil.htm</guid>
</item>



<item>
<title>PHPTB 2.0 Code Injection Security Vulnerabilities</title>
<link>http://www.acunetix.com/vulnerabilities/PHPTB-2.0-Code-Injection-.htm</link>
<description>
<![CDATA[
An input validation flaw in PHPTB code allows malicious attackers to cause the server to execute arbitrary code...continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:42:11 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHPTB-2.0-Code-Injection-.htm</guid>
</item>



<item>
<title>phpSysInfo 2.3 Cross-File Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/phpSysInfo-2.3-Cross-File.htm</link>
<description>
<![CDATA[
The vulnerability is caused due to an error in the "register_globals" emulation layer where certain arrays used by the system can be overwritten....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:40:44 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/phpSysInfo-2.3-Cross-File.htm</guid>
</item>



<item>
<title>PHPStatus v.1.0 SQL Injection and Login Bypass Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHPStatus-v.1.0-SQL-Injec.htm</link>
<description>
<![CDATA[
Input passed to the "username" parameter in "check.php" during login isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:39:15 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHPStatus-v.1.0-SQL-Injec.htm</guid>
</item>



<item>
<title>PHPSESSID session fixation Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHPSESSID-session-fixatio.htm</link>
<description>
<![CDATA[
This script is vulnerable to PHPSESSID session fixation attacks....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:37:51 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHPSESSID-session-fixatio.htm</guid>
</item>



<item>
<title>PHPNuke v.7.9 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHPNuke-v.7.9-Cross-Site-.htm</link>
<description>
<![CDATA[
Input passed to the "query" parameter in modules.php' is not properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:36:22 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHPNuke-v.7.9-Cross-Site-.htm</guid>
</item>



<item>
<title>PHPNuke v.7.9 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHPNuke-v.7.9-SQL-Injecti.htm</link>
<description>
<![CDATA[
Input passed to the "cat" parameter in "index.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:34:59 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHPNuke-v.7.9-SQL-Injecti.htm</guid>
</item>



<item>
<title>PHPNuke Remote Directory Traversal Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHPNuke-Remote-Directory--2.htm</link>
<description>
<![CDATA[
Input passed to the file parameter in modules.php isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:33:27 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHPNuke-Remote-Directory--2.htm</guid>
</item>



<item>
<title>PHPNuke Remote Directory Traversal (Unix) Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHPNuke-Remote-Directory-.htm</link>
<description>
<![CDATA[
Input passed to the file parameter in modules.php isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:30:31 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHPNuke-Remote-Directory-.htm</guid>
</item>



<item>
<title>PHPNuke 7.6 Multiple SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHPNuke-7.6-Multiple-SQL-.htm</link>
<description>
<![CDATA[
Input passed to multiple parameters (querylang, email, url, min, orderby, show, etc.) in "modules.php" are not properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:29:11 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHPNuke-7.6-Multiple-SQL-.htm</guid>
</item>



<item>
<title>PHPNuke 7.5 (admin_styles.php) Remote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHPNuke-7.5--Remote-File-.htm</link>
<description>
<![CDATA[
Input passed to the "phpbb_root_path" parameter in "/modules/Forums/admin/admin_styles.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:27:29 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHPNuke-7.5--Remote-File-.htm</guid>
</item>



<item>
<title>phpMyFAQ 1.5.1 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/phpMyFAQ-1.5.1-SQL-Inject.htm</link>
<description>
<![CDATA[
Input passed to the "username" parameter in "password.php" when using the forgotten password functionality isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:25:52 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/phpMyFAQ-1.5.1-SQL-Inject.htm</guid>
</item>



<item>
<title>phpMyAdmin Path Disclosure and Response Splitting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/phpMyAdmin-Path-Disclosur.htm</link>
<description>
<![CDATA[
Multiple security vulnerabilities in phpMyAdmin, these range from full path disclosure to allowing attackers to preform HTTP response splitting....continued...<br />
]]>
</description>
<pubDate>Mon, 21 May 2007 21:24:01 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/phpMyAdmin-Path-Disclosur.htm</guid>
</item>



<item>
<title>phpMyAdmin "grab_globals.lib.php" Directory Traversal Vulnerability Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/phpMyAdmin-grab_globals.l.htm</link>
<description>
<![CDATA[
Vulnerability, which may be exploited by remote attackers to access arbitrary files outside of the webroot directory....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:21:04 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/phpMyAdmin-grab_globals.l.htm</guid>
</item>



<item>
<title>phpMyAdmin Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/phpMyAdmin-Cross-Site-Scr.htm</link>
<description>
<![CDATA[
phpMyAdmin is prone to multiple cross-site scripting vulnerabilities....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 21:19:30 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/phpMyAdmin-Cross-Site-Scr.htm</guid>
</item>



<item>
<title>phpListPro v.2.0.0 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/phpListPro-v.2.0.0-File-I.htm</link>
<description>
<![CDATA[
Input passed to the "returnpath" parameter in config.php is not properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 09:32:28 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/phpListPro-v.2.0.0-File-I.htm</guid>
</item>



<item>
<title>PhpLinkExchange v.1.0 Remote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PhpLinkExchange-v.1.0-Rem.htm</link>
<description>
<![CDATA[
Input passed to the "page" parameter in "index.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 09:31:10 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PhpLinkExchange-v.1.0-Rem.htm</guid>
</item>



<item>
<title>phpLDAPadmin Command Execution Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/phpLDAPadmin-Command-Exec.htm</link>
<description>
<![CDATA[
phpLDAPadmin is a web-based LDAP client....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 09:27:44 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/phpLDAPadmin-Command-Exec.htm</guid>
</item>



<item>
<title>PHPKB v.1.5 Cross Site Scripting Security Vulnerability Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHPKB-v.1.5-Cross-Site-Sc.htm</link>
<description>
<![CDATA[
Input passed to the "searchkeyword" parameter in search.php is not properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 09:25:58 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHPKB-v.1.5-Cross-Site-Sc.htm</guid>
</item>



<item>
<title>PHPjournaler v.1.0 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHPjournaler-v.1.0-SQL-In.htm</link>
<description>
<![CDATA[
Input passed to the "readold" parameter in "index.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 09:19:59 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHPjournaler-v.1.0-SQL-In.htm</guid>
</item>



<item>
<title>PHPinfo page found Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHPinfo-page-found.htm</link>
<description>
<![CDATA[
PHPinfo page has been found on this directory....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 09:14:47 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHPinfo-page-found.htm</guid>
</item>



<item>
<title>PhpHostBot v.1.0 Remote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PhpHostBot-v.1.0-Remote-F.htm</link>
<description>
<![CDATA[
Input passed to the "page" parameter in "index.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 01:07:08 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PhpHostBot-v.1.0-Remote-F.htm</guid>
</item>



<item>
<title>PHPGreetz 0.99 Remote File Include Vulnerability Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHPGreetz-0.99-Remote-Fil.htm</link>
<description>
<![CDATA[
phpGreetz is prone to a remote file include vulnerability....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 01:05:36 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHPGreetz-0.99-Remote-Fil.htm</guid>
</item>



<item>
<title>PhpGedView v.3.3.7 File Inclusion and PHP Code Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PhpGedView-v.3.3.7-File-I.htm</link>
<description>
<![CDATA[
Input passed to the "PGV_BASE_DIRECTORY" parameter in "help_text_vars.php" isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 01:03:42 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PhpGedView-v.3.3.7-File-I.htm</guid>
</item>



<item>
<title>phpFullAnnu v.5.1 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/phpFullAnnu-v.5.1-0File-I.htm</link>
<description>
<![CDATA[
Input passed to the "repmod" parameter in "/modules/home.module.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 01:02:12 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/phpFullAnnu-v.5.1-0File-I.htm</guid>
</item>



<item>
<title>PHPEasyData Pro v.2.2.2 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHPEasyData-Pro-v.2.2.2-S.htm</link>
<description>
<![CDATA[
Input passed to the "cat" parameter in "/index.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 01:00:33 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHPEasyData-Pro-v.2.2.2-S.htm</guid>
</item>



<item>
<title>phpCommunityCalendar login bypass, SQL injection and cross site scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/phpCommunityCalendar-logi.htm</link>
<description>
<![CDATA[
Webadmin contains tools for category administrators....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:58:40 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/phpCommunityCalendar-logi.htm</guid>
</item>



<item>
<title>PHPCollab v.2.4 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHPCollab-v.2.4-SQL-Injec.htm</link>
<description>
<![CDATA[
Input passed to the "User Name" field in "/general/sendpassword.php" isn't properly sanitised before being used in a SQL query...continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:52:25 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHPCollab-v.2.4-SQL-Injec.htm</guid>
</item>



<item>
<title>phpCOIN v.1.2.2 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/phpCOIN-v.1.2.2-Cross-Sit.htm</link>
<description>
<![CDATA[
Input passed to the "fs" parameter in "mod.php" and "mod_print.php" is not properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:50:36 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/phpCOIN-v.1.2.2-Cross-Sit.htm</guid>
</item>



<item>
<title>phpBB XS Build 058 File Inclusion and Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/phpBB-XS-Build-058-File-I.htm</link>
<description>
<![CDATA[
Input passed to the "phpbb_root_path" parameter in "/includes/functions.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:48:24 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/phpBB-XS-Build-058-File-I.htm</guid>
</item>



<item>
<title>phpBB Addon: Hacks List v.1.20 Local File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/phpBB-Addon-Hacks-List-v..htm</link>
<description>
<![CDATA[
Input passed to the "root_path" parameter in master.php isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:46:23 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/phpBB-Addon-Hacks-List-v..htm</guid>
</item>



<item>
<title>phpBB 2.0.15 Viewtopic.php Remote Code Execution Vulnerability Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/phpBB-2.0.15-Viewtopic.ph.htm</link>
<description>
<![CDATA[
The viewtopic.php phpBB script is prone to a remote PHP script injection vulnerability....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:44:51 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/phpBB-2.0.15-Viewtopic.ph.htm</guid>
</item>



<item>
<title>phpArcadeScript v.2.0 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/phpArcadeScript-v.2.0-Cro.htm</link>
<description>
<![CDATA[
Some input isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:43:04 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/phpArcadeScript-v.2.0-Cro.htm</guid>
</item>



<item>
<title>PHP4 multiple vulnerabilities Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP4-multiple-vulnerabili.htm</link>
<description>
<![CDATA[
This alert was generated using only banner information. It may be a false positive....continued...<br />
]]>
</description>
<pubDate>Mon, 21 May 2007 00:40:06 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP4-multiple-vulnerabili.htm</guid>
</item>



<item>
<title>PHP4 IMAP module buffer overflow Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP4-IMAP-module-buffer-o.htm</link>
<description>
<![CDATA[
This alert was generated using only banner information. It may be a false positive....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:38:24 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP4-IMAP-module-buffer-o.htm</guid>
</item>



<item>
<title>PHP.exe Windows CGI for Apache may let remote users view files on the server Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP.exe-Windows-CGI-for-A.htm</link>
<description>
<![CDATA[
PHP.EXE Windows CGI for Apache web server may let remote users view files on the server due to configuration error....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:32:59 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP.exe-Windows-CGI-for-A.htm</guid>
</item>



<item>
<title>Snitz Forums 2000 v.3.4.05 post.asp Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Snitz-Forums-2000-v.3.4.0.htm</link>
<description>
<![CDATA[
Input passed to the "user" parameter in "profile.php" and "mail.php" isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:29:20 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Snitz-Forums-2000-v.3.4.0.htm</guid>
</item>



<item>
<title>PHP-Fusion 6.00.109 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PHP-Fusion-6.00.109-SQL-I.htm</link>
<description>
<![CDATA[
Input passed to the "activate" parameter in "register.php" and the "cat_id" parameter in "faq.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:25:09 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PHP-Fusion-6.00.109-SQL-I.htm</guid>
</item>



<item>
<title>PhotoPost v.4.6 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PhotoPost-v.4.6-File-Incl.htm</link>
<description>
<![CDATA[
Input passed to the "PP_PATH" parameter in "/zipndownload.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:22:44 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PhotoPost-v.4.6-File-Incl.htm</guid>
</item>



<item>
<title>photokorn v.1.542 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/photokorn-v.1.542-SQL-Inj.htm</link>
<description>
<![CDATA[
Some input isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:20:30 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/photokorn-v.1.542-SQL-Inj.htm</guid>
</item>



<item>
<title>Phorum v.5.1.18 (admin.php) Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Phorum-v.5.1.18--Cross-Si.htm</link>
<description>
<![CDATA[
Data passed to the admin.php URL isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:18:31 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Phorum-v.5.1.18--Cross-Si.htm</guid>
</item>



<item>
<title>oaboard 1.0 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/oaboard-1.0-SQL-Injection.htm</link>
<description>
<![CDATA[
Input passed to the "forum_ids[]" parameter in "search.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:16:36 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/oaboard-1.0-SQL-Injection.htm</guid>
</item>



<item>
<title>Pentacle In-Out Board v.6.03.0.0080 SQL Injection and Login Bypass Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Pentacle-In-Out-Board-v.6.htm</link>
<description>
<![CDATA[
Input passed to the "username" and "userpassword" parameters in login.asp and to the "newsid" parameter in newsdetails.asp isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:14:38 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Pentacle-In-Out-Board-v.6.htm</guid>
</item>



<item>
<title>PEAR XML_RPC 1.3.0 Remote Command Execution Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PEAR-XML_RPC-1.3.0-Remote.htm</link>
<description>
<![CDATA[
PEAR XML_RPC is vulnerable to a remote php code execution vulnerability that may allow for an attacker to compromise a vulnerable server....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:11:36 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PEAR-XML_RPC-1.3.0-Remote.htm</guid>
</item>



<item>
<title>Pearl For Mambo v.1.6 Remote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Pearl-For-Mambo-v.1.6-Rem.htm</link>
<description>
<![CDATA[
Input passed to the phpbb_root_path parameter in functions_cms.php and GlobalSettings[templatesDirectory] parameter...continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:09:49 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Pearl-For-Mambo-v.1.6-Rem.htm</guid>
</item>



<item>
<title>Pearl Forums 2.4 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PearlForums-2.4-SQL-Injec.htm</link>
<description>
<![CDATA[
Input passed to the "forumsId" and "topicId" parameters in "index.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:08:19 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PearlForums-2.4-SQL-Injec.htm</guid>
</item>



<item>
<title>PBLang 4.65 System Disclosure and Remote Code Execution Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/PBLang-4.65-System-Disclo.htm</link>
<description>
<![CDATA[
Input passed to the u parameter in setcookie.php isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:03:08 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/PBLang-4.65-System-Disclo.htm</guid>
</item>



<item>
<title>Particle Blogger v.1.2.0 (posid) SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Particle-Blogger-v.1.2.0-.htm</link>
<description>
<![CDATA[
Input passed to the "postid" parameter in "post.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Mon, 21 May 2007 00:01:21 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Particle-Blogger-v.1.2.0-.htm</guid>
</item>



<item>
<title>Pagesetter v.6.2.0 (PostNuke module) Local File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Pagesetter-v.6.2.0--Local.htm</link>
<description>
<![CDATA[
Input passed to the "stepOrder[]" parameter isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:59:32 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Pagesetter-v.6.2.0--Local.htm</guid>
</item>



<item>
<title>paBugs v.2.0b3 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/paBugs-v.2.0b3-File-Inclu.htm</link>
<description>
<![CDATA[
Input passed to the "path_to_bt_dir" parameter in "/class.mysql.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:57:52 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/paBugs-v.2.0b3-File-Inclu.htm</guid>
</item>



<item>
<title>Owl v.0.82 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Owl-v.0.82-File-Inclusion.htm</link>
<description>
<![CDATA[
Input passed to the "xrms_file_root" parameter in "lib/OWL_API.php" isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:56:21 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Owl-v.0.82-File-Inclusion.htm</guid>
</item>



<item>
<title>Ottoman v.1.1.2 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Ottoman-v.1.1.2-File-Incl.htm</link>
<description>
<![CDATA[
Input passed to the "default_path" parameter in "index.php", "error.php", "classes/main_class.php", "format_css.php", "js.php", and "rss.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:53:19 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Ottoman-v.1.1.2-File-Incl.htm</guid>
</item>



<item>
<title>osCommerce v.2.2 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/osCommerce-v.2.2Cross-Sit.htm</link>
<description>
<![CDATA[
Input passed to the "zone" parameter isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:49:55 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/osCommerce-v.2.2Cross-Sit.htm</guid>
</item>



<item>
<title>Orca Forum 4.3.b msg SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Orca-Forum-4.3.b-msg-SQL-.htm</link>
<description>
<![CDATA[
Input passed to the "msg" parameter isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:48:19 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Orca-Forum-4.3.b-msg-SQL-.htm</guid>
</item>



<item>
<title>OrbitHYIP v.2.0 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/OrbitHYIP-v.2.0-Cross-Sit.htm</link>
<description>
<![CDATA[
Input passed to the "referral" parameter in signup.php and to the "id" parameter in members.php is not properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:46:16 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/OrbitHYIP-v.2.0-Cross-Sit.htm</guid>
</item>



<item>
<title>OpenPHPNuke v.2.3.3 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/OpenPHPNuke-v.2.3.3-File-.htm</link>
<description>
<![CDATA[
Input passed to the "root_path" parameter in master.php isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:43:51 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/OpenPHPNuke-v.2.3.3-File-.htm</guid>
</item>



<item>
<title>OpenERM v.2.8.1 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/OpenERM-v.2.8.1-File-Incl.htm</link>
<description>
<![CDATA[
Input passed to the "srcdir" parameter in interface/billing/billing_process.php...continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:41:09 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/OpenERM-v.2.8.1-File-Incl.htm</guid>
</item>



<item>
<title>OpenEdit v.4.0 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/OpenEdit-v.4.0-Cross-Site.htm</link>
<description>
<![CDATA[
Input passed to the "oe-action" and "page" parameters in "results.html" isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:39:50 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/OpenEdit-v.4.0-Cross-Site.htm</guid>
</item>



<item>
<title>oaboard v.1.0 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/oaboard-v.1.0-SQL-Injecti.htm</link>
<description>
<![CDATA[
Input passed to the "channel" and "topic" parameters in "forum.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:38:19 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/oaboard-v.1.0-SQL-Injecti.htm</guid>
</item>



<item>
<title>N/X CMS v.4.1 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/NX-CMS-v.4.1-File-Inclusi.htm</link>
<description>
<![CDATA[
Input passed to the "c[path]" parameter in "/nxheader.inc.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:36:00 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/NX-CMS-v.4.1-File-Inclusi.htm</guid>
</item>



<item>
<title>NZ Ecommerce Cross Site Scripting and SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/NZ-Ecommerce-Cross-Site-S.htm</link>
<description>
<![CDATA[
Input passed to the "action" parameter in "index.php" isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:33:04 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/NZ-Ecommerce-Cross-Site-S.htm</guid>
</item>



<item>
<title>Nodez v.4.6.1.1 Cross-Site Scripting and Local File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Nodez-v.4.6.1.1-Cross-Sit.htm</link>
<description>
<![CDATA[
Input passed to the "op" parameter isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:30:58 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Nodez-v.4.6.1.1-Cross-Sit.htm</guid>
</item>



<item>
<title>NKads v.1.0.a3 Login SQL Injection Vulnerability Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/NKads-v.1.0.a3-Login-SQL-.htm</link>
<description>
<![CDATA[
Input passed to the "usuario_nkads_admin" and "password_nkads_admin" parameters when logging into the administration section isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:28:50 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/NKads-v.1.0.a3-Login-SQL-.htm</guid>
</item>



<item>
<title>Netquery "host" Parameter Arbitrary Command Execution Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Netquery-host-Parameter-A.htm</link>
<description>
<![CDATA[
Input passed to the "host" parameter in nquser.php is not properly sanitised before being used as command line argument to the "dig" command....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:26:07 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Netquery-host-Parameter-A.htm</guid>
</item>



<item>
<title>NetOffice v.2.5.3-pl1 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/NetOffice-v.2.5.3-pl1-SQL.htm</link>
<description>
<![CDATA[
put passed to the "User Name" field in "/general/sendpassword.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:24:15 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/NetOffice-v.2.5.3-pl1-SQL.htm</guid>
</item>



<item>
<title>My Gaming Ladder v.7.0 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/My-Gaming-Ladder-v.7.0-Fi.htm</link>
<description>
<![CDATA[
Input passed to the "dir[base]" parameter in stats.php is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:22:27 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/My-Gaming-Ladder-v.7.0-Fi.htm</guid>
</item>



<item>
<title>Amazon Store Manager v1.0 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Amazon-Store-Manager-v1.0.htm</link>
<description>
<![CDATA[
Input passed to the "q" parameter in "search.php" when performing a search isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:21:00 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Amazon-Store-Manager-v1.0.htm</guid>
</item>



<item>
<title>MyTopix v.1.2.3 SQL Injection And Path Disclosure Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/MyTopix-v.1.2.3-SQL-Injec.htm</link>
<description>
<![CDATA[
The problem is that it is possible to disclose the full path to "modules/logon.mod.php" by accessing it directly....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:18:36 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/MyTopix-v.1.2.3-SQL-Injec.htm</guid>
</item>



<item>
<title>MySource 2.14.0 Cross-Site Scripting and File Inclusion Security Vulnerabilities</title>
<link>http://www.acunetix.com/vulnerabilities/MySource-2.14.0-Cross-Sit.htm</link>
<description>
<![CDATA[
Some input isn't properly verified, before it used to include files....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:16:32 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/MySource-2.14.0-Cross-Sit.htm</guid>
</item>



<item>
<title>MyPHP CMS v.0.3 Remote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/MyPHP-CMS-v.0.3-Remote-Fi.htm</link>
<description>
<![CDATA[
Input passed to the "domain" parameter in "global_header.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:14:43 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/MyPHP-CMS-v.0.3-Remote-Fi.htm</guid>
</item>



<item>
<title>myEvent v.1.4 Multiple Security Vulnerabilities</title>
<link>http://www.acunetix.com/vulnerabilities/myEvent-v.1.4-Multiple-Vu.htm</link>
<description>
<![CDATA[
Input passed to the "event_desc" parameter in addevent.php is not properly sanitised before being used....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:12:57 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/myEvent-v.1.4-Multiple-Vu.htm</guid>
</item>



<item>
<title>MyBulletinBoard v.1.1.5 SQL injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/MyBulletinBoard-v.1.1.5-S.htm</link>
<description>
<![CDATA[
Input passed to the CLIENT-IP parameter in "index.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:11:27 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/MyBulletinBoard-v.1.1.5-S.htm</guid>
</item>



<item>
<title>MyBuletinBoard v.1.1.7 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/MyBuletinBoard-v.1.1.7-Cr.htm</link>
<description>
<![CDATA[
1. Input passed via the URL path in "/admin/index.php" is not properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:09:40 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/MyBuletinBoard-v.1.1.7-Cr.htm</guid>
</item>



<item>
<title>MyBuletinBoard v.1.0.2 Table Prefix Weakness Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/MyBuletinBoard-v.1.0.2-Ta.htm</link>
<description>
<![CDATA[
The problem is that SQL error messages are returned to the user....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:07:47 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/MyBuletinBoard-v.1.0.2-Ta.htm</guid>
</item>



<item>
<title>myBloggie SQL Injection and login bypas Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/myBloggie-SQL-Injection-a.htm</link>
<description>
<![CDATA[
Vulnerability in myBloggie, which can be exploited by malicious people to conduct SQL injection attacks....continued...<br />
]]>
</description>
<pubDate>Sun, 20 May 2007 23:05:20 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/myBloggie-SQL-Injection-a.htm</guid>
</item>



<item>
<title>myBloggie v.2.1.4 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/myBloggie-v.2.1.4-SQL-Inj.htm</link>
<description>
<![CDATA[
Input passed to the 'title', 'url', 'excerpt' and 'blog_name' parameters in "/trackback.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:03:58 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/myBloggie-v.2.1.4-SQL-Inj.htm</guid>
</item>



<item>
<title>Musicbox v.2.3 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Musicbox-v.2.3-SQL-Inject.htm</link>
<description>
<![CDATA[
Input passed to the "start" parameter in index.php is not properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 23:02:23 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Musicbox-v.2.3-SQL-Inject.htm</guid>
</item>



<item>
<title>Musicbox v.2.3 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Musicbox-v.2.3-Cross-Site.htm</link>
<description>
<![CDATA[
Input passed to the "term" paramter in index.php is not properly sanitised before being returned to users....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 22:59:57 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Musicbox-v.2.3-Cross-Site.htm</guid>
</item>



<item>
<title>MultiCalendars-v.3.0-SQL-Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/MultiCalendars-v.3.0-SQL-.htm</link>
<description>
<![CDATA[
Input passed to the "calsids" parameter in "all_calendars.asp" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 22:57:00 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/MultiCalendars-v.3.0-SQL-.htm</guid>
</item>



<item>
<title>MODx v.0.9.2.1 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/MODx-v.0.9.2.1-File-Inclu.htm</link>
<description>
<![CDATA[
Input passed to the "base_path" parameter in "/manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 22:53:33 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/MODx-v.0.9.2.1-File-Inclu.htm</guid>
</item>



<item>
<title>miniBloggie v.1.0 SQL Injection and Login Bypass Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/miniBloggie-v.1.0SQL-Inje.htm</link>
<description>
<![CDATA[
Input passed to the "user" parameter in "login.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 22:51:14 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/miniBloggie-v.1.0SQL-Inje.htm</guid>
</item>



<item>
<title>MiniBILL v.1.2.4 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/MiniBILL-v.1.2.4-File-Inc.htm</link>
<description>
<![CDATA[
Input passed to the "config[page_dir]" in "/include/menu_builder.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 22:35:30 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/MiniBILL-v.1.2.4-File-Inc.htm</guid>
</item>



<item>
<title>Minerva v.238a File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Minerva-v.238a-File-Inclu.htm</link>
<description>
<![CDATA[
Input passed to the "phpbb_root_path" parameter in "/admin/admin_topic_action_logging.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 22:34:07 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Minerva-v.238a-File-Inclu.htm</guid>
</item>



<item>
<title>Microsoft IIS Cookie Variable Information Disclosure Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Microsoft-IIS-Cookie-Vari.htm</link>
<description>
<![CDATA[
The Active Server Pages (ASP) engine does not properly handle special cookie values when they are retrieved....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 22:32:32 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Microsoft-IIS-Cookie-Vari.htm</guid>
</item>



<item>
<title>MercuryBoard v.1.1.4 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/MercuryBoard-v.1.1.4-SQL-.htm</link>
<description>
<![CDATA[
Input passed to the User-Agent parameter in "index.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 22:31:12 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/MercuryBoard-v.1.1.4-SQL-.htm</guid>
</item>



<item>
<title>MaxxSchedule v.1.0 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/MaxxSchedule-v.1.0-Cross-.htm</link>
<description>
<![CDATA[
Input passed to the "Error" parameter in Logon.asp isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 22:18:47 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/MaxxSchedule-v.1.0-Cross-.htm</guid>
</item>



<item>
<title>MAXdev MD-Pro v.1.0.76 Path Disclosure Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/MAXdev-MD-Pro-v.1.0.76-Pa.htm</link>
<description>
<![CDATA[
It is possible to disclose the full path to "includes/legacy.php" by accessing it directly....continued...
]]>
</description>
<pubDate>Sun, 20 May 2007 22:17:04 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/MAXdev-MD-Pro-v.1.0.76-Pa.htm</guid>
</item>



<item>
<title>MAXdev MD-Pro v.1.0.76 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/MAXdev-MD-Pro-v.1.0.76-Cr.htm</link>
<description>
<![CDATA[
Input passed to the "op" parameter in "user.php", to the "name", "file", "module", and "func" parameters in "index.php" and to the "file" parameter in "modules.php" isn't properly sanitised before being used....continued...
]]>
</description>
<pubDate>Sat, 19 May 2007 15:42:28 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/MAXdev-MD-Pro-v.1.0.76-Cr.htm</guid>
</item>



<item>
<title>Mantis 1.00 File Inclusion and SQL Injection Vulnerabilities (Windows) Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Mantis-1.00-File-Inclusio-2.htm</link>
<description>
<![CDATA[
1) Input passed to the "t_core_path" parameter in "bug_sponsorship_list_view_inc.php" isn't properly verified, before it used to include files....continued...
]]>
</description>
<pubDate>Sat, 19 May 2007 15:38:44 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Mantis-1.00-File-Inclusio-2.htm</guid>
</item>



<item>
<title>Mantis 1.00 File Inclusion and SQL Injection Vulnerabilities (Unix) Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Mantis-1.00-File-Inclusio.htm</link>
<description>
<![CDATA[
Input passed to the "t_core_path" parameter in "bug_sponsorship_list_view_inc.php" isn't properly verified, before it used to include files....continued...
]]>
</description>
<pubDate>Sat, 19 May 2007 15:36:37 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Mantis-1.00-File-Inclusio.htm</guid>
</item>



<item>
<title>Mambo v.4.5.3h SQL Injection and Login Bypass Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Mambo-v.4.5.3h-SQL-Inject.htm</link>
<description>
<![CDATA[
Input passed to the "usernamel" and "passwd" parameters in "index.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Fri, 18 May 2007 00:17:00 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Mambo-v.4.5.3h-SQL-Inject.htm</guid>
</item>



<item>
<title>Mambo v.4.5.2 (tar.php) Remote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Mambo-v.4.5.2--Remote-Fil.htm</link>
<description>
<![CDATA[
Input passed to the "mosConfig_absolute_path" parameter in "tar.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Fri, 18 May 2007 00:15:26 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Mambo-v.4.5.2--Remote-Fil.htm</guid>
</item>



<item>
<title>Mambo up to v.4.6.1 SQL Injection and Login Bypass Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Mambo-up-to-v.4.6.1-SQL-I.htm</link>
<description>
<![CDATA[
Input passed to the "usercookie[password]" and "usercookie[username]" cookie parameters in "index.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Fri, 18 May 2007 00:13:43 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Mambo-up-to-v.4.6.1-SQL-I.htm</guid>
</item>



<item>
<title>MailGust 1.9 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/MailGust-1.9-SQL-Injectio.htm</link>
<description>
<![CDATA[
Input passed to the "email" field when using the password reminder functionality isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Fri, 18 May 2007 00:12:27 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/MailGust-1.9-SQL-Injectio.htm</guid>
</item>



<item>
<title>Maian Weblog v.2.0 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Maian-Weblog-v.2.0-SQL-In.htm</link>
<description>
<![CDATA[
Input passed to the "entry" parameter in "print.php" and to the "email" parameter in "mail.php" is not properly sanitised before being used in SQL queries....continued...
]]>
</description>
<pubDate>Fri, 18 May 2007 00:11:11 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Maian-Weblog-v.2.0-SQL-In.htm</guid>
</item>



<item>
<title>Maian Events v.1.00 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Maian-Events-v.1.00-SQL-I.htm</link>
<description>
<![CDATA[
Input passed to the "month" and "year" parameter in "menu.php" and to the "date" parameter in "events.php" is not properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Fri, 18 May 2007 00:09:52 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Maian-Events-v.1.00-SQL-I.htm</guid>
</item>



<item>
<title>Magic News Lite v.1.2.3 Code Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Magic-News-Lite-v.1.2.3-C.htm</link>
<description>
<![CDATA[
Input passed to the "php_script_path" parameter in "preview.php" isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Fri, 18 May 2007 00:08:25 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Magic-News-Lite-v.1.2.3-C.htm</guid>
</item>



<item>
<title>Macromedia Dreamweaver Remote Database Scripts Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Macromedia-Dreamweaver-Re.htm</link>
<description>
<![CDATA[
Macromedia Dreamweaver has created a directory (_mmServerScripts or _mmDBScripts) that contains scripts for testing database connectivity....continued...
]]>
</description>
<pubDate>Fri, 18 May 2007 00:07:14 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Macromedia-Dreamweaver-Re.htm</guid>
</item>



<item>
<title>lucidCMS 1.0.11 SQL Injection and Login Bypass Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/lucidCMS-1.0.11-SQL-Injec.htm</link>
<description>
<![CDATA[
Vulnerability in LucidCMS, which can be exploited by malicious people to conduct SQL injection attacks....continued...
]]>
</description>
<pubDate>Fri, 18 May 2007 00:05:24 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/lucidCMS-1.0.11-SQL-Injec.htm</guid>
</item>



<item>
<title>Loudmouth (Mambo component) v.4.0 Remote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Loudmouth--v.4.0-Remote-F.htm</link>
<description>
<![CDATA[
Input passed to the "mosConfig_absolute_path" parameter in "/components/com_loudmouth/includes/abbc/abbc.class.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Fri, 18 May 2007 00:03:41 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Loudmouth--v.4.0-Remote-F.htm</guid>
</item>



<item>
<title>Loudblog v.0.4 File Inclusion and PHP Code Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Loudblog-v.0.4-File-Inclu.htm</link>
<description>
<![CDATA[
Input passed to the "path" parameter in "loudblog/inc/backend_settings.php" isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Fri, 18 May 2007 00:02:05 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Loudblog-v.0.4-File-Inclu.htm</guid>
</item>



<item>
<title>LocazoList Classifieds v.1.03c SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/LocazoList-Classifieds-v..htm</link>
<description>
<![CDATA[
Input passed to the "q" parameter in "searchdb.asp" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:57:37 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/LocazoList-Classifieds-v..htm</guid>
</item>



<item>
<title>Lizard Cart CMS v.1.0.4 id parameter SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Lizard-Cart-CMS-v.1.0.4-i.htm</link>
<description>
<![CDATA[
Input passed to the "id" parameter isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:56:00 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Lizard-Cart-CMS-v.1.0.4-i.htm</guid>
</item>



<item>
<title>LinPHA v.1.0 Local File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/LinPHA-v.1.0-Local-File-I.htm</link>
<description>
<![CDATA[
Input passed to the "lang" parameter in docs/index.php isn't properly verified, before it is used to include files....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:54:37 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/LinPHA-v.1.0-Local-File-I.htm</guid>
</item>



<item>
<title>Leadhound 2006-04-28 Cross Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Leadhound-2006-04-28-Cros.htm</link>
<description>
<![CDATA[
Input passed to the "login", "logged", "camp_id","banner","offset","date","dates", and "page" parameters in various scripts e.g. agent_affil.pl, agent_help.pl, agent_faq.pl...continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:53:04 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Leadhound-2006-04-28-Cros.htm</guid>
</item>



<item>
<title>LDAP Injection vulnerability Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/LDAP-Injection-vulnerabil.htm</link>
<description>
<![CDATA[
This script is possibly vulnerable to LDAP Injection attacks....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:51:53 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/LDAP-Injection-vulnerabil.htm</guid>
</item>



<item>
<title>JiRo's FAQ Manager v.1.x SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/JiRos-FAQ-Manager-v.1.x-S.htm</link>
<description>
<![CDATA[
Input passed to the "fID" parameter in index.asp is not properly sanitised, before being used in a SQL query....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:50:31 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/JiRos-FAQ-Manager-v.1.x-S.htm</guid>
</item>



<item>
<title>JetPhoto Server v.1.x Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/JetPhoto-Server-v.1.x-Cro.htm</link>
<description>
<![CDATA[
Input passed to the "name" and "page" parameters is not properly sanitised before being returned to users....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:48:40 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/JetPhoto-Server-v.1.x-Cro.htm</guid>
</item>



<item>
<title>Jamroom v.3.0.16 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Jamroom-v.3.0.16-Cross-Si.htm</link>
<description>
<![CDATA[
Input passed to the "forgot" parameter in "login.php" is not properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:47:18 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Jamroom-v.3.0.16-Cross-Si.htm</guid>
</item>



<item>
<title>iWare Professional v.5.0.4 Remote Code Execution Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/iWare-Professional-v.5.0..htm</link>
<description>
<![CDATA[
Input passed to the "msg" parameter in "/admin/mods/SimpleChat_1.0.0/chat_panel.php" is not properly sanitised, before it is written to the web-accessible chat_log.php file....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:45:43 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/iWare-Professional-v.5.0..htm</guid>
</item>



<item>
<title>Invision Power Board v2.1.6 SQL injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Invision-Power-Board-v2.1.htm</link>
<description>
<![CDATA[
Input passed to the CLIENT-IP parameter in "index.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:23:11 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Invision-Power-Board-v2.1.htm</guid>
</item>



<item>
<title>Invision Power Board v.2.0.3 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Invision-Power-Board-v.2..htm</link>
<description>
<![CDATA[
This vulnerability exists due to data submitted to the "highlite" parameter not being sanatized properly when displaying search results. The same issue also exists in "sources/topics.php"....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:21:03 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Invision-Power-Board-v.2..htm</guid>
</item>



<item>
<title>IntranetApp v.3.3 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/IntranetApp-v.3.3-Cross-S.htm</link>
<description>
<![CDATA[
Input passed to the "ret_page" parameter in "login.asp" isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:19:21 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/IntranetApp-v.3.3-Cross-S.htm</guid>
</item>



<item>
<title>Interspire FastFind v.2006-10-09 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Interspire-FastFind-v.200.htm</link>
<description>
<![CDATA[
Input passed to the "query" parameter in "index.php" is not properly sanitised before being used....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:17:30 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Interspire-FastFind-v.200.htm</guid>
</item>



<item>
<title>Integramod Portal v.2.0 File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Integramod-Portal-v.2.0-F.htm</link>
<description>
<![CDATA[
Input passed to the "phpbb_root_path" parameter in "/includes/functions_portal.php" is not properly verified before being used to include files....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:15:49 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Integramod-Portal-v.2.0-F.htm</guid>
</item>



<item>
<title>Instant Photo Gallery v.1.0 SQL Injection Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Instant-Photo-Gallery-v.1.htm</link>
<description>
<![CDATA[
Input passed to the "cat_id" parameter in "portfolio.php" and "cid" parameter in "content.php" isn't properly sanitised before being used in a SQL query....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:14:07 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Instant-Photo-Gallery-v.1.htm</guid>
</item>



<item>
<title>IIS server variables backup file Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/IIS-server-variables-back.htm</link>
<description>
<![CDATA[
This file looks like a backup file for global.asa....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:12:52 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/IIS-server-variables-back.htm</guid>
</item>



<item>
<title>Internet Information Server returns IP address in HTTP header (Content-Location) Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Internet-Information-Serv.htm</link>
<description>
<![CDATA[
When you use static HTML pages (for example, Default.htm), a Content-Location header is added to the response....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:11:19 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Internet-Information-Serv.htm</guid>
</item>



<item>
<title>IIS extended unicode directory traversal vulnerability Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/IIS-extended-unicode-dire.htm</link>
<description>
<![CDATA[
The web server is vulnerable to double dot "../" directory traversal...continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:04:36 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/IIS-extended-unicode-dire.htm</guid>
</item>



<item>
<title>IISWorks ASP KnowledgeBase v2.x Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/IISWorks-ASP-KnowledgeBas.htm</link>
<description>
<![CDATA[
Input passed to the "a" parameter in "kb.asp" isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:02:43 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/IISWorks-ASP-KnowledgeBas.htm</guid>
</item>



<item>
<title>IDQ ISAPI filter mapped Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/IDQ-ISAPI-filter-mapped.htm</link>
<description>
<![CDATA[
.IDQ ISAPI filter mapped on this web server....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:01:26 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/IDQ-ISAPI-filter-mapped.htm</guid>
</item>



<item>
<title>IDC ISAPI filter mapped Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/IDC-ISAPI-filter-mapped.htm</link>
<description>
<![CDATA[
IDC ISAPI filter mapped on this web server....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 23:00:15 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/IDC-ISAPI-filter-mapped.htm</guid>
</item>



<item>
<title>IDA ISAPI filter mapped Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/IDA-ISAPI-filter-mapped.htm</link>
<description>
<![CDATA[
.IDA ISAPI filter mapped on this web server....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 22:59:12 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/IDA-ISAPI-filter-mapped.htm</guid>
</item>



<item>
<title>HTW ISAPI filter mapped Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/HTW-ISAPI-filter-mapped.htm</link>
<description>
<![CDATA[
.HTW ISAPI filter mapped on this web server....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 22:57:44 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/HTW-ISAPI-filter-mapped.htm</guid>
</item>



<item>
<title>HTR ISAPI filter mapped Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/HTR-ISAPI-filter-mapped.htm</link>
<description>
<![CDATA[
.HTR ISAPI filter mapped on this web server. If this ISAPI extension is not used on your website, it's recommended to remove it....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 22:56:24 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/HTR-ISAPI-filter-mapped.htm</guid>
</item>



<item>
<title>GreenBeast CMS v.1.3 File Upload Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/GreenBeast-CMS-v.1.3-File.htm</link>
<description>
<![CDATA[
Access to the filemanager plugins "/gbcms_php_files/up_loader.php" is not properly restricted....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 22:55:01 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/GreenBeast-CMS-v.1.3-File.htm</guid>
</item>



<item>
<title>Google Search Appliance UTF-7 Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Google-Search-Appliance-U.htm</link>
<description>
<![CDATA[
Input passed to the "q" or/and "search_string" parameters (when "oe=UTF-7" and the parameter value is UTF7 encoded) is not properly sanitised before being used....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 22:53:15 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Google-Search-Appliance-U.htm</guid>
</item>



<item>
<title>Google API Search Engine v.1.3.1 Script Cross-Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Google-API-Search-Engine-.htm</link>
<description>
<![CDATA[
Input passed to the "REQ" parameter when performing a search isn't properly sanitised before being returned to the user....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 22:51:17 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Google-API-Search-Engine-.htm</guid>
</item>



<item>
<title>Gemini v.2.0 Cross Site Scripting Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/Gemini-v.2.0-Cross-Site-S.htm</link>
<description>
<![CDATA[
Input passed to the "rtcDescription$RadEditor1" field in "issue/createissue.aspx" isn't properly sanitised before being used....continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 22:31:52 +0100</pubDate>
<guid>http://www.acunetix.com/vulnerabilities/Gemini-v.2.0-Cross-Site-S.htm</guid>
</item>



<item>
<title>GeekLog v1.4.0 Remote File Inclusion Security Vulnerability</title>
<link>http://www.acunetix.com/vulnerabilities/GeekLog-v1.4.0-Remote-Fil.htm</link>
<description>
<![CDATA[
Input passed to the "_CONF[path]" parameter in:...continued...
]]>
</description>
<pubDate>Thu, 17 May 2007 22:30:10 +0100</pubDate>
<gu