<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Wed, 22 May 2013 05:40:10 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[Christopher Kunz's Blog: PHPKIT vulnerabilities revisited]]></title>
      <guid>http://www.phpdeveloper.org/news/4792</guid>
      <link>http://www.phpdeveloper.org/news/4792</link>
      <description><![CDATA[On his blog, <i>Christopher Kunz</i> has <a href="http://www.christopher-kunz.de/serendipity/archives/90-PHPKIT-vulnerabilities-revisited.html">a new note</a> for all of those out there specifically running PHPKIT - some security issues that came up and weren't addressed as quickly as need be.
<p>
<quote>
<i>
A while back, I reported several vulnerabilities in PHPKIT to the vendors. Although not very well-known in the rest of the world, there's an abundance of installations of this product in german-speaking countries, since it is very easy to install, provides a german user (and administration) interface and has about the same feature set as the infamous PHP-Nuke.
<p>
After I reported the vulnerability, no response whatsoever was received. I phoned the vendor, and they told me something about an ominous "community release" and that I should report the issues in their forum. I gave the advisory (including PoC for each hole) to the forum administrator and told them to get a fix out of the door. They responded in a very weird fashion, but allegedly fixed the bugs and released an inofficial patch in the forum.
</i>
</quote>
<p>
He <a href="http://www.christopher-kunz.de/serendipity/archives/90-PHPKIT-vulnerabilities-revisited.html">goes on</a> in the post, stating why a distribution menthod like is isn't the wisest course of action. Patches are slow in distribution and applicataion versus a full version release. Especially ones distributed via less than an "official" means...]]></description>
      <pubDate>Mon, 06 Feb 2006 06:40:05 -0600</pubDate>
    </item>
  </channel>
</rss>
