<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0"
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
  xmlns:admin="http://webns.net/mvcb/"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
  xmlns:wfw="http://wellformedweb.org/CommentAPI/"
  xmlns:content="http://purl.org/rss/1.0/modules/content/"
>
    <channel>
    <title>Hardened-PHP Project Advisories</title>
    <link>http://www.hardened-php.net/</link>
    <description></description>
    <dc:language>en</dc:language>
    <generator>papaya-CMS 4.0.3</generator>
   <pubDate>Mon, 05 Jun 2006 11:50:27 GMT</pubDate>
    <image>
        <url>
        http://www.hardened-php.net/hardened.gif
        </url>
        <title>
        RSS: Hardened-PHP-Project
        </title>
        <link>http://www.hardened-php.net/</link>
        <width>80</width>
        <height>15</height>
    </image>
<item>
<title>Advisory 03&#47;2007&#58; Multiple Browsers Cross Domain Charset Inheritance Vulnerability</title>
<link>http://www.hardened-php.net/advisory_032007.142.html</link>
<description>It was discovered that several web browser will render web-pages without a defined charset with the charset of the parent page when put into an                (i)frame. This might allow bypassing XSS filters with for example UTF-7 payload.
</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Fri, 23 Feb 2007 20:32:27 +0000</pubDate>
</item>
<item>
<title>Advisory 02&#47;2007&#58; WordPress Trackback Charset Decoding SQL Injection Vulnerability</title>
<link>http://www.hardened-php.net/advisory_022007.141.html</link>
<description>It was discovered that WordPress's support of trackbacks in different charsets can be used to bypass WordPress's SQL injection protection.                This might result in a compromise of the admin account and the execution of arbitrary PHP code on the server</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Fri, 05 Jan 2007 15:07:12 +0000</pubDate>
</item>
<item>
<title>Advisory 01&#47;2007&#58; WordPress CSRF Protection XSS Vulnerability</title>
<link>http://www.hardened-php.net/advisory_012007.140.html</link>
<description>It was discovered that the CSRF protection of WordPress's administration                interface is vulnerable to an XSS vulnerability which might result in a compromise of the admin account and the execution of arbitrary PHP code on the server</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Fri, 05 Jan 2007 15:02:29 +0000</pubDate>
</item>
<item>
<title>Advisory 14&#47;2006&#58; Dotdeb PHP Email Header Injection Vulnerability</title>
<link>http://www.hardened-php.net/advisory_142006.139.html</link>
<description>A vulnerability in Dotdebs PHP packages was discovered that allows abusing any PHP script that uses mail() as spamrobot. Furthermore this vulnerability might lead to disclosure of sensitive information sent out by email.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Tue, 14 Nov 2006 16:27:48 +0000</pubDate>
</item>
<item>
<title>Advisory 13&#47;2006&#58; PHP HTML Entity Encoder Heap Overflow Vulnerability</title>
<link>http://www.hardened-php.net/advisory_132006.138.html</link>
<description>A heap overflow in PHP's HTML entity encoder was discovered that can be triggered through the htmlentities() and htmlspecialchars() functions. Successfull exploitation results in arbitrary remote code execution.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Thu, 02 Nov 2006 22:07:12 +0000</pubDate>
</item>
<item>
<title>Advisory 12&#47;2006&#58; phpMyAdmin - error&#46;php XSS Vulnerability</title>
<link>http://www.hardened-php.net/advisory_122006.137.html</link>
<description>An user supplied charset in the error displaying script of phpMyAdmin allows XSS.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Thu, 02 Nov 2006 07:49:45 +0000</pubDate>
</item>
<item>
<title>Advisory 11&#47;2006&#58; Serendipity Weblog XSS Vulnerabilities</title>
<link>http://www.hardened-php.net/advisory_112006.136.html</link>
<description>Multiple XSS vulnerabilities within the administration interface of Serendipity were found that allow Cross Site Scripting attacks against the blog admin.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Thu, 19 Oct 2006 15:26:27 +0000</pubDate>
</item>
<item>
<title>Advisory 10&#47;2006&#58; ViewVC Undefined Charset UTF-7 XSS Vulnerability</title>
<link>http://www.hardened-php.net/advisory_102006.134.html</link>
<description>A missing default charset definition in ViewVC allows XSS attacks against browsers interpreting UTF-7.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Sun, 15 Oct 2006 14:13:27 +0000</pubDate>
</item>
<item>
<title>Advisory 09&#47;2006&#58; PHP unserialize&#40;&#41; Array Creation Integer Overflow</title>
<link>http://www.hardened-php.net/advisory_092006.133.html</link>
<description>It was discovered that userinput passed to the unserialize() function might trigger an integer overflow in array creation that might result in remote code execution.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Mon, 09 Oct 2006 06:41:24 +0000</pubDate>
</item>
<item>
<title>Advisory 08&#47;2006&#58; PHP open_basedir Race Condition Vulnerability</title>
<link>http://www.hardened-php.net/advisory_082006.132.html</link>
<description>A design flaw of PHP's open_basedir feature allows bypassing it's restrictions with the symlink() function.
</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Tue, 03 Oct 2006 15:29:35 +0000</pubDate>
</item>
<item>
<title>Advisory 07&#47;2006&#58; phpMyAdmin Multiple CSRF Vulnerabilities</title>
<link>http://www.hardened-php.net/advisory_072006.130.html</link>
<description>Multiple vulnerabilities within phpMyAdmin were discovered that allow bypassing it's protection against CSRF which might lead to the execution of arbitrary SQL queries.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Sun, 01 Oct 2006 17:53:49 +0000</pubDate>
</item>
<item>
<title>Advisory 06&#47;2006&#58; PHProjekt &#40;Remote&#41; Include Vulnerabilities</title>
<link>http://www.hardened-php.net/advisory_062006.129.html</link>
<description>An unverified path variable might allow an attacker to inject and execute arbitrary PHP code within PHProjekt.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Fri, 29 Sep 2006 10:57:53 +0000</pubDate>
</item>
<item>
<title>Advisory 05&#47;2006 - Zend Platform Multiple Remote Vulnerabilities</title>
<link>http://www.hardened-php.net/advisory_052006.128.html</link>
<description>Multiple remote vulnerabilities in the Zend Platform Session Handler have been discovered that can even lead to remote (PHP) code execution.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Thu, 24 Aug 2006 11:23:22 +0000</pubDate>
</item>
<item>
<title>Advisory 04&#47;2006&#58; DokuWiki PHP code execution vulnerability in spellchecker</title>
<link>http://www.hardened-php.net/advisory_042006.119.html</link>
<description>A vulnerability in DokuWiki's spellchecker allows normal wiki visitors to execute arbritrary PHP code through injection into a preg_replace() call, that uses the /e modifier.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Mon, 05 Jun 2006 08:01:13 +0000</pubDate>
</item>
<item>
<title>Advisory 03&#47;2006&#58; KisMAC Cisco Vendor Tag Encapsulated SSID Overflow</title>
<link>http://www.hardened-php.net/advisory_032006.115.html</link>
<description>A vulnerability in the passive wifi scanner KisMAC was discovered that allows execution of arbitrary code through a single manipulated 80211 management frame.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Thu, 23 Mar 2006 07:11:19 +0000</pubDate>
</item>
<item>
<title>Advisory 02&#47;2006&#58; PHP ext&#47;mysqli Format String Vulnerability</title>
<link>http://www.hardened-php.net/advisory_022006.113.html</link>
<description>A format string vulnerability in the exception handling of the new mysqli extension for PHP may result in remote code execution.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Thu, 12 Jan 2006 16:36:23 +0000</pubDate>
</item>
<item>
<title>Advisory 01&#47;2006&#58; PHP ext&#47;session HTTP Response Splitting Vulnerability</title>
<link>http://www.hardened-php.net/advisory_012006.112.html</link>
<description>Due to a flaw in the session handling of PHP, applications using PHP5's session extension are vulnerable to HTTP Response Splitting attacks.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Thu, 12 Jan 2006 16:28:49 +0000</pubDate>
</item>
<item>
<title>Advisory 26&#47;2005&#58; TinyMCE Compressor Vulnerabilities</title>
<link>http://www.hardened-php.net/advisory_262005.111.html</link>
<description>TinyMCE Compressor uses unchecked user input directly within filenames or
prints it into the output buffer which allows disclosure of arbitrary files and XSS attacks</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Tue, 27 Dec 2005 17:48:07 +0000</pubDate>
</item>
<item>
<title>Advisory 25&#47;2005&#58; phpMyAdmin Variables Overwrite Vulnerability</title>
<link>http://www.hardened-php.net/advisory_252005.110.html</link>
<description>A vulnerability within the redesigned register_globals emulation layer of phpMyAdmin can be used to overwrite f.e. arbitrary configuration values and therefore eventually lead to execution of arbitrary code or injection of XSS.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Wed, 07 Dec 2005 09:50:47 +0000</pubDate>
</item>
<item>
<title>Advisory 24&#47;2005&#58; libcurl URL parsing vulnerability</title>
<link>http://www.hardened-php.net/advisory_242005.109.html</link>
<description>A vulnerability in the URL parser of (lib)Curl may lead to a heap overflow and unintended code execution, when a certain kind of malformed URL is requested through (lib)Curl.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Wed, 07 Dec 2005 08:37:26 +0000</pubDate>
</item>
<item>
<title>Advisory 23&#47;2005&#58; vTiger multiple vulnerabilities</title>
<link>http://www.hardened-php.net/advisory_232005.105.html</link>
<description>Multiple vulnerabilities in the commercial SugarCRM fork vTiger allow for privilege escalation, local and remote code execution, Cross-Site scripting and authentication bypass.
Attack classes found are SQL injection, XSS, unsafe file inclusion.</description>
<author>christopher.kunz@hardened-php.net (Christopher Kunz)</author><pubDate>Thu, 24 Nov 2005 10:07:39 +0000</pubDate>
</item>
<item>
<title>Advisory 22&#47;2005&#58;Multiple vulnerabilities in phpSysInfo</title>
<link>http://www.hardened-php.net/advisory_222005.81.html</link>
<description>Due to incorrect handling of global variables, attackers can view arbitrary files, perform XSS and HTTP Response Splitting attacks on a vulnerable phpSysInfo instance.</description>
<author>christopher.kunz@hardened-php.net (Christopher Kunz)</author><pubDate>Fri, 11 Nov 2005 10:08:34 +0000</pubDate>
</item>
<item>
<title>Advisory 21&#47;2005&#58; Multiple vulnerabilities in PHPKIT</title>
<link>http://www.hardened-php.net/advisory_212005.80.html</link>
<description>Multiple vulnerabilities in the commercial community management system PHPKIT allow for password hash disclosure, XSS and remote code execution.</description>
<author>christopher.kunz@hardened-php.net (Christopher Kunz)</author><pubDate>Tue, 08 Nov 2005 00:35:57 +0000</pubDate>
</item>
<item>
<title>Advisory 20&#47;2005&#58; PHP File-Upload &#36;GLOBALS Overwrite Vulnerability</title>
<link>http://www.hardened-php.net/advisory_202005.79.html</link>
<description>$GLOBALS overwrite can lead to unexpected behaviour of PHP applications, which can lead to execution of remote PHP code in many situations.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Mon, 31 Oct 2005 12:38:10 +0000</pubDate>
</item>
<item>
<title>Advisory 19&#47;2005&#58; PHP register_globals Activation Vulnerability in parse_str&#40;&#41;</title>
<link>http://www.hardened-php.net/advisory_192005.78.html</link>
<description>Unsafe termination of parse_str() by the memory_limit request shutdown may result in the register_globals directive turned back on.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Mon, 31 Oct 2005 12:37:51 +0000</pubDate>
</item>
<item>
<title>Advisory 18&#47;2005&#58; PHP Cross Site Scripting &#40;XSS&#41; Vulnerability in phpinfo&#40;&#41;</title>
<link>http://www.hardened-php.net/advisory_182005.77.html</link>
<description>A Cross Site Scripting (XSS) Vulnerability in phpinfo() could f.e. lead to cookie data exposure if an info script is left on a production server.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Mon, 31 Oct 2005 12:37:31 +0000</pubDate>
</item>
<item>
<title>Advisory 17&#47;2005&#58; phpBB Multiple Vulnerabilities</title>
<link>http://www.hardened-php.net/advisory_172005.75.html</link>
<description>Multiple vulnerabilities within phpBB &lt;= 2.0.17 allow XSS, SQL injection and even remote PHP code execution.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Sun, 30 Oct 2005 23:51:27 +0000</pubDate>
</item>
<item>
<title>Advisory 16&#47;2005&#58; phpMyAdmin Local File Inclusion Vulnerability</title>
<link>http://www.hardened-php.net/advisory_162005.73.html</link>
<description>A design flaw within phpMyAdmin allows inclusion of arbitrary files, which usually leads to remote code execution.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Sat, 22 Oct 2005 13:17:51 +0000</pubDate>
</item>
<item>
<title>Advisory 15&#47;2005&#58; PHPXMLRPC Remote PHP Code Injection Vulnerability</title>
<link>http://www.hardened-php.net/advisory_152005.67.html</link>
<description>A malformed XMLRPC request can result in execution of arbitrary injected PHP code in applications using PHPXMLRPC.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Mon, 15 Aug 2005 12:17:19 +0000</pubDate>
</item>
<item>
<title>Advisory 14&#47;2005&#58; PEAR XML_RPC Remote PHP Code Injection Vulnerability</title>
<link>http://www.hardened-php.net/advisory_142005.66.html</link>
<description>A malformed XMLRPC request can result in execution of arbitrary injected PHP code in applications using PEAR XML_RPC.</description>
<author>stefan@hardened-php.net (Stefan Esser)</author><pubDate>Mon, 15 Aug 2005 12:17:11 +0000</pubDate>
</item>
</channel></rss>