<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Thu, 23 May 2013 10:46:43 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[Community News: Serendipity 1.1.3 and 1.2-beta2 released due to SQL exploit]]></title>
      <guid>http://www.phpdeveloper.org/news/8073</guid>
      <link>http://www.phpdeveloper.org/news/8073</link>
      <description><![CDATA[<p>
As <i>Christopher Kunz</i> <a href="http://www.christopher-kunz.de/archives/142-S9Y-security-announcement-Update-or-fix-now!.html">points out</a>, Serendipity users should check out <a href="http://www.christopher-kunz.de/exit.php?url_id=609&entry_id=142">a new blog posting</a> over on the CMS system's website concerning an immediate update they've released.
</p>
<blockquote>
Serendipity 1.1.3 and 1.2-beta2 have been released due to a SQL injection attack reported by Dr. Neal Krawetz today. It is possible to abuse a 'commentMode' variable to inject SQL code that was targeted to the function that fetches comment information. This variable was introduced to Serendipity 1.1 - all prior versions are not affected.
</blockquote>
<p>
They also suggest checking you access logs for a "commentMode" variable issued in requests to see if there were any kind of attacks made already. The fix is a simple matter of editing the functions_comments.inc.php file and replacing the line of code they give with the more secure versions. Again, this is recommended as an immediate upgrade for Serendipity users.
</p>]]></description>
      <pubDate>Tue, 19 Jun 2007 07:47:00 -0500</pubDate>
    </item>
  </channel>
</rss>
