<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Tue, 21 May 2013 20:33:06 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[FrSIRT Advisory: P-News Arbitrary PHP File Upload and Remote Information Disclosure Vulnerabilities]]></title>
      <guid>http://www.phpdeveloper.org/news/6798</guid>
      <link>http://www.phpdeveloper.org/news/6798</link>
      <description><![CDATA[<p>
According to <a href="http://www.frsirt.com/english/advisories/2006/4770">this advisory</a> on the FrSIRT website, users of the P-News package have two somethings to worry about - a file upload and remote information disclosure vulnerability.
</p>
<blockquote>
Multiple vulnerabilities have been identified in P-News, which could be exploited by remote attackers to compromise a vulnerable server or disclose sensitive information.
</blockquote>
<p>
The file upload issue has to do with the ability to upload an Avatar to the system that doesn't validate the file extension and the second is a design flaw for the location of the user information (a text file) inside the document root.
</p>
<p>
Unfortunately, so official patch has been supplied at this time, but a few quick edits to the code can make these issues go away.
</p>]]></description>
      <pubDate>Thu, 30 Nov 2006 09:51:00 -0600</pubDate>
    </item>
  </channel>
</rss>
