<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Wazi &#187; Security Team</title>
	<atom:link href="http://olex.openlogic.com/wazi/author/security-team/feed/" rel="self" type="application/rss+xml" />
	<link>http://olex.openlogic.com/wazi</link>
	<description>Thinking OPEN</description>
	<lastBuildDate>Fri, 19 Mar 2010 03:29:34 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Kernel 2.6.9 [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/kernel-2-6-9-medium-2/</link>
		<comments>http://olex.openlogic.com/wazi/2010/kernel-2-6-9-medium-2/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[kernel]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/kernel-2-6-9-medium-2/</guid>
		<description><![CDATA[The nfs_lock function in fs/nfs/file.c in the Linux kernel 2.6.9 does not properly remove POSIX locks on files that are setgid without group-execute permission, which allows local users to cause a denial of service (BUG and system crash) by locking a file on an NFS filesystem and then changing this file's permissions, a related issue to CVE-2010-0727....

CVE Identifier: CVE-2007-6733
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Kernel 2.6.9 [Medium]
</ul>
<h3>Description</h3>
<p>The nfs_lock function in fs/nfs/file.c in the Linux kernel 2.6.9 does not properly remove POSIX locks on files that are setgid without group-execute permission, which allows local users to cause a denial of service (BUG and system crash) by locking a file on an NFS filesystem and then changing this file&#8217;s permissions, a related issue to CVE-2010-0727.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-6733" target="_blank">CVE-2007-6733</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/kernel-2-6-9-medium-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Com Abbrev 1.1 and prior [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/com-abbrev-1-1-and-prior-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/com-abbrev-1-1-and-prior-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[com_abbrev]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/com-abbrev-1-1-and-prior-high/</guid>
		<description><![CDATA[Directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a ....

CVE Identifier: CVE-2010-0985
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Com Abbrev 1.1 and prior [High]
</ul>
<h3>Description</h3>
<p>Directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.  NOTE: some of these details are obtained from third party information.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0985" target="_blank">CVE-2010-0985</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/com-abbrev-1-1-and-prior-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Acidcat Cms 3.5.3 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/acidcat-cms-3-5-3-and-prior-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2010/acidcat-cms-3-5-3-and-prior-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[acidcat_cms]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/acidcat-cms-3-5-3-and-prior-medium/</guid>
		<description><![CDATA[Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for databases/acidcat_3.mdb....

CVE Identifier: CVE-2010-0984
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Acidcat Cms 3.5.3 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for databases/acidcat_3.mdb.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0984" target="_blank">CVE-2010-0984</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/acidcat-cms-3-5-3-and-prior-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rezervi 3.0.2 [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/rezervi-3-0-2-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2010/rezervi-3-0-2-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[rezervi]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/rezervi-3-0-2-medium/</guid>
		<description><![CDATA[PHP remote file inclusion vulnerability in include/mail.inc.php in Rezervi 3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the root parameter, a different vector than CVE-2007-2156....

CVE Identifier: CVE-2010-0983
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Rezervi 3.0.2 [Medium]
</ul>
<h3>Description</h3>
<p>PHP remote file inclusion vulnerability in include/mail.inc.php in Rezervi 3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the root parameter, a different vector than CVE-2007-2156.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0983" target="_blank">CVE-2010-0983</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/rezervi-3-0-2-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Com Cartweberp 1.56.75 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/com-cartweberp-1-56-75-and-prior-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2010/com-cartweberp-1-56-75-and-prior-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[com_cartweberp]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/com-cartweberp-1-56-75-and-prior-medium/</guid>
		<description><![CDATA[Directory traversal vulnerability in the CARTwebERP (com_cartweberp) component 1.56.75 for Joomla! allows remote attackers to read arbitrary files via a ....

CVE Identifier: CVE-2010-0982
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Com Cartweberp 1.56.75 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Directory traversal vulnerability in the CARTwebERP (com_cartweberp) component 1.56.75 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0982" target="_blank">CVE-2010-0982</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/com-cartweberp-1-56-75-and-prior-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Com Tpjobs  [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/com-tpjobs-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/com-tpjobs-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[com_tpjobs]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/com-tpjobs-high/</guid>
		<description><![CDATA[SQL injection vulnerability in the TPJobs (com_tpjobs) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_c[] parameter in a resadvsearch action to index.php....

CVE Identifier: CVE-2010-0981
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Com Tpjobs  [High]
</ul>
<h3>Description</h3>
<p>SQL injection vulnerability in the TPJobs (com_tpjobs) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_c[] parameter in a resadvsearch action to index.php.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0981" target="_blank">CVE-2010-0981</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/com-tpjobs-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>L4d Stats 1.1 [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/l4d-stats-1-1-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/l4d-stats-1-1-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[l4d_stats]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/l4d-stats-1-1-high/</guid>
		<description><![CDATA[SQL injection vulnerability in player.php in Left 4 Dead (L4D) Stats 1.1 allows remote attackers to execute arbitrary SQL commands via the steamid parameter....

CVE Identifier: CVE-2010-0980
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>L4d Stats 1.1 [High]
</ul>
<h3>Description</h3>
<p>SQL injection vulnerability in player.php in Left 4 Dead (L4D) Stats 1.1 allows remote attackers to execute arbitrary SQL commands via the steamid parameter.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0980" target="_blank">CVE-2010-0980</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/l4d-stats-1-1-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Image-gallery 1.1 [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/image-gallery-1-1-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2010/image-gallery-1-1-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[image-gallery]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/image-gallery-1-1-medium/</guid>
		<description><![CDATA[Cross-site scripting (XSS) vulnerability in display.php in Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to inject arbitrary web script or HTML via the folder parameter....

CVE Identifier: CVE-2010-0979
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Image-gallery 1.1 [Medium]
</ul>
<h3>Description</h3>
<p>Cross-site scripting (XSS) vulnerability in display.php in Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0979" target="_blank">CVE-2010-0979</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/image-gallery-1-1-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Guestbook 1.0 [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/guestbook-1-0-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2010/guestbook-1-0-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[guestbook]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/guestbook-1-0-medium/</guid>
		<description><![CDATA[KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb....

CVE Identifier: CVE-2010-0978
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Guestbook 1.0 [Medium]
</ul>
<h3>Description</h3>
<p>KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0978" target="_blank">CVE-2010-0978</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/guestbook-1-0-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pd Portal 4.0 [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/pd-portal-4-0-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2010/pd-portal-4-0-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[pd_portal]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/pd-portal-4-0-medium/</guid>
		<description><![CDATA[PD PORTAL 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb....

CVE Identifier: CVE-2010-0977
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Pd Portal 4.0 [Medium]
</ul>
<h3>Description</h3>
<p>PD PORTAL 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0977" target="_blank">CVE-2010-0977</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/pd-portal-4-0-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Acidcat Cms 3.5.3 and prior [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/acidcat-cms-3-5-3-and-prior-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/acidcat-cms-3-5-3-and-prior-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[acidcat_cms]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/acidcat-cms-3-5-3-and-prior-high/</guid>
		<description><![CDATA[Acidcat CMS 3.5.x does not prevent access to install.asp after installation finishes, which might allow remote attackers to restart the installation process and have unspecified other impact via requests to install.asp and other install_*.asp scripts...

CVE Identifier: CVE-2010-0976
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Acidcat Cms 3.5.3 and prior [High]
</ul>
<h3>Description</h3>
<p>Acidcat CMS 3.5.x does not prevent access to install.asp after installation finishes, which might allow remote attackers to restart the installation process and have unspecified other impact via requests to install.asp and other install_*.asp scripts.  NOTE: the final installation screen states &#8220;Important: you must now delete all files beginning with &#8216;install&#8217; from the root directory.&#8221;</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0976" target="_blank">CVE-2010-0976</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/acidcat-cms-3-5-3-and-prior-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Barnowl 1.5 and prior [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/barnowl-1-5-and-prior-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/barnowl-1-5-and-prior-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[barnowl]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/barnowl-1-5-and-prior-high/</guid>
		<description><![CDATA[Buffer overflow in BarnOwl before 1.5.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted CC: header....

CVE Identifier: CVE-2010-0793
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Barnowl 1.5 and prior [High]
</ul>
<h3>Description</h3>
<p>Buffer overflow in BarnOwl before 1.5.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted CC: header.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0793" target="_blank">CVE-2010-0793</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/barnowl-1-5-and-prior-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Enterprise Linux 4 [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/enterprise-linux-4-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2010/enterprise-linux-4-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[enterprise_linux]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/enterprise-linux-4-medium/</guid>
		<description><![CDATA[A certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 4 on the ia64 platform allows local users to use ptrace on an arbitrary process, and consequently gain privileges, via vectors related to a missing ptrace_check_attach call....

CVE Identifier: CVE-2010-0729
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Enterprise Linux 4 [Medium]
</ul>
<h3>Description</h3>
<p>A certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 4 on the ia64 platform allows local users to use ptrace on an arbitrary process, and consequently gain privileges, via vectors related to a missing ptrace_check_attach call.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0729" target="_blank">CVE-2010-0729</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/enterprise-linux-4-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Kernel 6 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/kernel-6-and-prior-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2010/kernel-6-and-prior-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[kernel]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/kernel-6-and-prior-medium/</guid>
		<description><![CDATA[The gfs2_lock function in the Linux kernel before 2.6.34-rc1-next-20100312, and the gfs_lock function in the Linux kernel on Red Hat Enterprise Linux (RHEL) 5 and 6, does not properly remove POSIX locks on files that are setgid without group-execute permission, which allows local users to cause a denial of service (BUG and system crash) by locking a file on a (1) GFS or (2) GFS2 filesystem, and then changing this file's permissions....

CVE Identifier: CVE-2010-0727
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Kernel 6 and prior [Medium]
</ul>
<h3>Description</h3>
<p>The gfs2_lock function in the Linux kernel before 2.6.34-rc1-next-20100312, and the gfs_lock function in the Linux kernel on Red Hat Enterprise Linux (RHEL) 5 and 6, does not properly remove POSIX locks on files that are setgid without group-execute permission, which allows local users to cause a denial of service (BUG and system crash) by locking a file on a (1) GFS or (2) GFS2 filesystem, and then changing this file&#8217;s permissions.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0727" target="_blank">CVE-2010-0727</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/kernel-6-and-prior-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Php 5.3.1 [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/php-5-3-1-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2010/php-5-3-1-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[php]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/php-5-3-1-medium/</guid>
		<description><![CDATA[The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument....

CVE Identifier: CVE-2010-0397
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Php 5.3.1 [Medium]
</ul>
<h3>Description</h3>
<p>The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0397" target="_blank">CVE-2010-0397</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/php-5-3-1-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phpcityportal  [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/phpcityportal-high-2/</link>
		<comments>http://olex.openlogic.com/wazi/2010/phpcityportal-high-2/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[phpcityportal]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/phpcityportal-high-2/</guid>
		<description><![CDATA[PHP remote file inclusion vulnerability in external.php in PHPCityPortal allows remote attackers to execute arbitrary PHP code via a URL in the url parameter....

CVE Identifier: CVE-2010-0975
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Phpcityportal  [High]
</ul>
<h3>Description</h3>
<p>PHP remote file inclusion vulnerability in external.php in PHPCityPortal allows remote attackers to execute arbitrary PHP code via a URL in the url parameter.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0975" target="_blank">CVE-2010-0975</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/phpcityportal-high-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phpcityportal  [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/phpcityportal-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/phpcityportal-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[phpcityportal]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/phpcityportal-high/</guid>
		<description><![CDATA[Multiple SQL injection vulnerabilities in PHPCityPortal allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) video_show.php, (2) spotlight_detail.php, (3) real_estate_details.php, and (4) auto_details.php....

CVE Identifier: CVE-2010-0974
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Phpcityportal  [High]
</ul>
<h3>Description</h3>
<p>Multiple SQL injection vulnerabilities in PHPCityPortal allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) video_show.php, (2) spotlight_detail.php, (3) real_estate_details.php, and (4) auto_details.php.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0974" target="_blank">CVE-2010-0974</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/phpcityportal-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Domain Verkaus And Auktions Portal  [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/domain-verkaus-and-auktions-portal-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/domain-verkaus-and-auktions-portal-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[domain_verkaus_and_auktions_portal]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/domain-verkaus-and-auktions-portal-high/</guid>
		<description><![CDATA[SQL injection vulnerability in index.php in phppool media Domain Verkaus and Auktions Portal allows remote attackers to execute arbitrary SQL commands via the id parameter....

CVE Identifier: CVE-2010-0973
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Domain Verkaus And Auktions Portal  [High]
</ul>
<h3>Description</h3>
<p>SQL injection vulnerability in index.php in phppool media Domain Verkaus and Auktions Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0973" target="_blank">CVE-2010-0973</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/domain-verkaus-and-auktions-portal-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Com Gcalendar 2.1.5 and prior [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/com-gcalendar-2-1-5-and-prior-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/com-gcalendar-2-1-5-and-prior-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[com_gcalendar]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/com-gcalendar-2-1-5-and-prior-high/</guid>
		<description><![CDATA[Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a ....

CVE Identifier: CVE-2010-0972
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Com Gcalendar 2.1.5 and prior [High]
</ul>
<h3>Description</h3>
<p>Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0972" target="_blank">CVE-2010-0972</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/com-gcalendar-2-1-5-and-prior-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Atutor 1.6.4 [Low]</title>
		<link>http://olex.openlogic.com/wazi/2010/atutor-1-6-4-low/</link>
		<comments>http://olex.openlogic.com/wazi/2010/atutor-1-6-4-low/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[atutor]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/atutor-1-6-4-low/</guid>
		<description><![CDATA[Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.6.4 allow remote authenticated users, with Instructor privileges, to inject arbitrary web script or HTML via the (1) Question and (2) Choice fields in tools/polls/add.php, the (3) Type and (4) Title fields in tools/groups/create_manual.php, and the (5) Title field in assignments/add_assignment.php...

CVE Identifier: CVE-2010-0971
Vulnerability Type(s): 
Severity: Low
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Atutor 1.6.4 [Low]
</ul>
<h3>Description</h3>
<p>Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.6.4 allow remote authenticated users, with Instructor privileges, to inject arbitrary web script or HTML via the (1) Question and (2) Choice fields in tools/polls/add.php, the (3) Type and (4) Title fields in tools/groups/create_manual.php, and the (5) Title field in assignments/add_assignment.php.  NOTE: some of these details are obtained from third party information.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0971" target="_blank">CVE-2010-0971</a><br />
Severity: Low
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/atutor-1-6-4-low/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
