<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Fri, 24 May 2013 00:16:48 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[ThinkPHP Blog: Developer Blog for PHProjekt 6 started]]></title>
      <guid>http://www.phpdeveloper.org/news/9870</guid>
      <link>http://www.phpdeveloper.org/news/9870</link>
      <description><![CDATA[<p>
On the ThinkPHP blog today, <i>Ute</i> has <a href="http://blog.thinkphp.de/archives/313-Developer-Blog-for-PHProjekt-6-started.html">posted about</a> a developer blog that has been started up for <a href="http://www.phprojekt.com/index.php?&newlang=eng">PHProjekt</a>:
</p>
<blockquote>
Seven and half years and a lot of downloads later the development team decided that a complete makeover is necessary not only to include more Web 2.0 features but also to add new functions to one of the most popular Open Source Groupware based on PHP. [...] There are still some months left till PHProjekt 6 will be released but for the time being you can follow the progress in a <a href="http://blog.phprojekt.com/">developers' blog</a> started recently.
</blockquote>
<p>
<a href="http://blog.phprojekt.com/">The blog</a> already has information on the upcoming version (PHProjekt 6) and a first part of a "what's new" series on additions to the project. <a href="http://www.phprojekt.com/index.php?&newlang=eng">PHProject</a> is an open source groupware application providing tools like shared calendars, project management and file management.
</p>]]></description>
      <pubDate>Thu, 27 Mar 2008 12:53:34 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Hardened-PHP Project: Advisory - PHProjekt (Remote) Include Vulnerabilities]]></title>
      <guid>http://www.phpdeveloper.org/news/6393</guid>
      <link>http://www.phpdeveloper.org/news/6393</link>
      <description><![CDATA[<p>
The Hardened-PHP Project has released a <a href="http://www.hardened-php.net/advisory_062006.129.html">new vulnerability</a> for the <a href="http://www.phprojekt.com/">PHProjekt</a> groupware software.
</p>
<blockquote>
<p>
While searching for applications that are vulnerable to a new class of vulnerabilities inside PHP applications we took a quick look into the current PHProjekt source code and discovered that a (remote) include vulnerability had been (re)introduced.
</p>
<p>
By overwriting a variable with user input it is possible to inject and execute arbitrary PHP code. Overwriting this variable is possible regardless of the register_globals setting.
</p>
</blockquote>
<p>
They give <a href="http://www.hardened-php.net/advisory_062006.129.html">a few more details</a> further down the posting and note that users should download and install the latest version (at the time of this post, 5.1.2).
</p>]]></description>
      <pubDate>Fri, 29 Sep 2006 10:01:00 -0500</pubDate>
    </item>
  </channel>
</rss>
