<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Wed, 19 Jun 2013 13:56:11 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[FrSIRT: Vivvo Article Management CMS SQL Injection and PHP File Inclusion Vulnerabilities]]></title>
      <guid>http://www.phpdeveloper.org/news/6298</guid>
      <link>http://www.phpdeveloper.org/news/6298</link>
      <description><![CDATA[<p>
The FrSIRT site has posted <a href="http://www.frsirt.com/english/advisories/2006/3548">a new advisory</a> for users of the Vivvo Article Management CMS software about potential holes that could allow for some very large-scale damage to be done.
</p>
<blockquote>
<p>
Multiple vulnerabilities have been identified in Vivvo Article Management CMS, which could be exploited by remote attackers to compromise a vulnerable server.
</p>
<p>
The first issue is due to an input validation error in the "pdf_version.php" script that does not validate the "id" parameter before being used in SQL statements, which could be exploited by malicious people to conduct SQL injection attacks.
</p>
<p>
The second vulnerability is due to an input validation error in the "index.php" script that do not validate the "classified_path" parameter, which may be exploited by remote attackers to include local or remote scripts with the privileges of the web server.
</p>
</blockquote>
<p>
Versions 3.2 and higher of the software are effected, and, unfortunately, there has been no patch issued for the issue.
</p>]]></description>
      <pubDate>Mon, 18 Sep 2006 14:08:57 -0500</pubDate>
    </item>
  </channel>
</rss>
