<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Wazi</title>
	<atom:link href="http://olex.openlogic.com/wazi/feed/" rel="self" type="application/rss+xml" />
	<link>http://olex.openlogic.com/wazi</link>
	<description>Thinking OPEN</description>
	<lastBuildDate>Fri, 19 Mar 2010 03:29:34 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Audio %26 Video Library 2.7.0 [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/audio-%26-video-library-2-7-0-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/audio-%26-video-library-2-7-0-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[audio__video_library]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/audio-%26-video-library-2-7-0-high/</guid>
		<description><![CDATA[SQL injection vulnerability in login.php in Allomani Audio &#038; Video Library (Songs &#038; Clips version) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action....

CVE Identifier: CVE-2009-4735
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Audio %26 Video Library 2.7.0 [High]
</ul>
<h3>Description</h3>
<p>SQL injection vulnerability in login.php in Allomani Audio &#038; Video Library (Songs &#038; Clips version) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4735" target="_blank">CVE-2009-4735</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/audio-%26-video-library-2-7-0-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Movie Library 2.7.0 [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/movie-library-2-7-0-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/movie-library-2-7-0-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[movie_library]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/movie-library-2-7-0-high/</guid>
		<description><![CDATA[SQL injection vulnerability in login.php in Allomani Movies Library (Movies &#038; Clips) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action....

CVE Identifier: CVE-2009-4734
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Movie Library 2.7.0 [High]
</ul>
<h3>Description</h3>
<p>SQL injection vulnerability in login.php in Allomani Movies Library (Movies &#038; Clips) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4734" target="_blank">CVE-2009-4734</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/movie-library-2-7-0-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Simpleloginsys 0.5 [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/simpleloginsys-0-5-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2010/simpleloginsys-0-5-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[simpleloginsys]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/simpleloginsys-0-5-medium/</guid>
		<description><![CDATA[SQL injection vulnerability in checkuser.php in SimpleLoginSys 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter...

CVE Identifier: CVE-2009-4733
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Simpleloginsys 0.5 [Medium]
</ul>
<h3>Description</h3>
<p>SQL injection vulnerability in checkuser.php in SimpleLoginSys 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.  NOTE: some of these details are obtained from third party information.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4733" target="_blank">CVE-2009-4733</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/simpleloginsys-0-5-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tt Web Site Manager 0.5 [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/tt-web-site-manager-0-5-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2010/tt-web-site-manager-0-5-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[tt_web_site_manager]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/tt-web-site-manager-0-5-medium/</guid>
		<description><![CDATA[SQL injection vulnerability in tt/index.php in TT Web Site Manager 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tt_name parameter...

CVE Identifier: CVE-2009-4732
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Tt Web Site Manager 0.5 [Medium]
</ul>
<h3>Description</h3>
<p>SQL injection vulnerability in tt/index.php in TT Web Site Manager 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tt_name parameter.  NOTE: some of these details are obtained from third party information.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4732" target="_blank">CVE-2009-4732</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/tt-web-site-manager-0-5-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Model Agency Manager Pro  [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/model-agency-manager-pro-high-2/</link>
		<comments>http://olex.openlogic.com/wazi/2010/model-agency-manager-pro-high-2/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[model_agency_manager_pro]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/model-agency-manager-pro-high-2/</guid>
		<description><![CDATA[SQL injection vulnerability in photos.php in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allows remote attackers to execute arbitrary SQL commands via the album parameter....

CVE Identifier: CVE-2009-4731
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Model Agency Manager Pro  [High]
</ul>
<h3>Description</h3>
<p>SQL injection vulnerability in photos.php in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allows remote attackers to execute arbitrary SQL commands via the album parameter.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4731" target="_blank">CVE-2009-4731</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/model-agency-manager-pro-high-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adult Script 1.7 [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/adult-script-1-7-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/adult-script-1-7-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[adult_script]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/adult-script-1-7-high/</guid>
		<description><![CDATA[SQL injection vulnerability in report.php in x10 Adult Media Script 1.7 allows remote attackers to execute arbitrary SQL commands via the id parameter....

CVE Identifier: CVE-2009-4730
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Adult Script 1.7 [High]
</ul>
<h3>Description</h3>
<p>SQL injection vulnerability in report.php in x10 Adult Media Script 1.7 allows remote attackers to execute arbitrary SQL commands via the id parameter.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4730" target="_blank">CVE-2009-4730</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/adult-script-1-7-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adult Script 1.7 [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/adult-script-1-7-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2010/adult-script-1-7-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[adult_script]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/adult-script-1-7-medium/</guid>
		<description><![CDATA[Multiple cross-site scripting (XSS) vulnerabilities in x10 Adult Media Script 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) pic_id parameter to includes/video_ad.php, (2) category parameter to linkvideos_listing.php, (3) id parameter to templates/header1.php, and (4) key parameter to video_listing.php....

CVE Identifier: CVE-2009-4729
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Adult Script 1.7 [Medium]
</ul>
<h3>Description</h3>
<p>Multiple cross-site scripting (XSS) vulnerabilities in x10 Adult Media Script 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) pic_id parameter to includes/video_ad.php, (2) category parameter to linkvideos_listing.php, (3) id parameter to templates/header1.php, and (4) key parameter to video_listing.php.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4729" target="_blank">CVE-2009-4729</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/adult-script-1-7-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Questions Answered 1.3 [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/questions-answered-1-3-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/questions-answered-1-3-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[questions_answered]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/questions-answered-1-3-high/</guid>
		<description><![CDATA[SQL injection vulnerability in the administrative interface in Questions Answered 1.3 allows remote attackers to execute arbitrary SQL commands via the username parameter...

CVE Identifier: CVE-2009-4728
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Questions Answered 1.3 [High]
</ul>
<h3>Description</h3>
<p>SQL injection vulnerability in the administrative interface in Questions Answered 1.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.  NOTE: some of these details are obtained from third party information.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4728" target="_blank">CVE-2009-4728</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/questions-answered-1-3-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ajax Short Url Script  [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/ajax-short-url-script-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/ajax-short-url-script-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[ajax_short_url_script]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/ajax-short-url-script-high/</guid>
		<description><![CDATA[SQL injection vulnerability in x/login in JungleScripts Ajax Short Url Script allows remote attackers to execute arbitrary SQL commands via the username parameter....

CVE Identifier: CVE-2009-4727
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Ajax Short Url Script  [High]
</ul>
<h3>Description</h3>
<p>SQL injection vulnerability in x/login in JungleScripts Ajax Short Url Script allows remote attackers to execute arbitrary SQL commands via the username parameter.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4727" target="_blank">CVE-2009-4727</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/ajax-short-url-script-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Quickdev4php  [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/quickdev4php-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2010/quickdev4php-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[quickdev4php]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/quickdev4php-medium/</guid>
		<description><![CDATA[Directory traversal vulnerability in download.php in Quickdev 4 PHP allows remote attackers to read arbitrary files via a ....

CVE Identifier: CVE-2009-4726
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Quickdev4php  [Medium]
</ul>
<h3>Description</h3>
<p>Directory traversal vulnerability in download.php in Quickdev 4 PHP allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4726" target="_blank">CVE-2009-4726</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/quickdev4php-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Arab Portal 2.2 [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/arab-portal-2-2-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2010/arab-portal-2-2-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[arab_portal]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/arab-portal-2-2-medium/</guid>
		<description><![CDATA[Directory traversal vulnerability in modules/aljazeera/admin/setup.php in Arab Portal 2.2 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a ....

CVE Identifier: CVE-2009-4725
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Arab Portal 2.2 [Medium]
</ul>
<h3>Description</h3>
<p>Directory traversal vulnerability in modules/aljazeera/admin/setup.php in Arab Portal 2.2 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4725" target="_blank">CVE-2009-4725</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/arab-portal-2-2-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ppscript  [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/ppscript-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/ppscript-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[ppscript]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/ppscript-high/</guid>
		<description><![CDATA[SQL injection vulnerability in shop.htm in PaymentProcessorScript.net PPScript allows remote attackers to execute arbitrary SQL commands via the cid parameter....

CVE Identifier: CVE-2009-4724
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Ppscript  [High]
</ul>
<h3>Description</h3>
<p>SQL injection vulnerability in shop.htm in PaymentProcessorScript.net PPScript allows remote attackers to execute arbitrary SQL commands via the cid parameter.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4724" target="_blank">CVE-2009-4724</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/ppscript-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Netpet Cms 1.9 [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/netpet-cms-1-9-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/netpet-cms-1-9-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[netpet_cms]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/netpet-cms-1-9-high/</guid>
		<description><![CDATA[Directory traversal vulnerability in confirm.php in Netpet CMS 1.9 allows remote attackers to include and execute arbitrary local files via a ....

CVE Identifier: CVE-2009-4723
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Netpet Cms 1.9 [High]
</ul>
<h3>Description</h3>
<p>Directory traversal vulnerability in confirm.php in Netpet CMS 1.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4723" target="_blank">CVE-2009-4723</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/netpet-cms-1-9-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Limny 1.01 [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/limny-1-01-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/limny-1-01-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[limny]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/limny-1-01-high/</guid>
		<description><![CDATA[SQL injection vulnerability in the CheckLogin function in includes/functions.php in Limny 1.01, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter....

CVE Identifier: CVE-2009-4722
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Limny 1.01 [High]
</ul>
<h3>Description</h3>
<p>SQL injection vulnerability in the CheckLogin function in includes/functions.php in Limny 1.01, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4722" target="_blank">CVE-2009-4722</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/limny-1-01-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Aw-bannerad 1.0 [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/aw-bannerad-1-0-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/aw-bannerad-1-0-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[aw-bannerad]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/aw-bannerad-1-0-high/</guid>
		<description><![CDATA[Multiple SQL injection vulnerabilities in Admin/index.asp in Andrews-Web (A-W) BannerAd 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) User and (2) Password parameters...

CVE Identifier: CVE-2009-4721
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Aw-bannerad 1.0 [High]
</ul>
<h3>Description</h3>
<p>Multiple SQL injection vulnerabilities in Admin/index.asp in Andrews-Web (A-W) BannerAd 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) User and (2) Password parameters. NOTE: some of these details are obtained from third party information.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4721" target="_blank">CVE-2009-4721</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/aw-bannerad-1-0-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Gnudip 2.1.1 [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/gnudip-2-1-1-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/gnudip-2-1-1-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[gnudip]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/gnudip-2-1-1-high/</guid>
		<description><![CDATA[SQL injection vulnerability in cgi-bin/gnudip.cgi in GnuDIP 2.1.1 allows remote attackers to execute arbitrary SQL commands via the username parameter...

CVE Identifier: CVE-2009-4720
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Gnudip 2.1.1 [High]
</ul>
<h3>Description</h3>
<p>SQL injection vulnerability in cgi-bin/gnudip.cgi in GnuDIP 2.1.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.  NOTE: some of these details are obtained from third party information.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4720" target="_blank">CVE-2009-4720</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/gnudip-2-1-1-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Discloser 0.0.4 [High]</title>
		<link>http://olex.openlogic.com/wazi/2010/discloser-0-0-4-high/</link>
		<comments>http://olex.openlogic.com/wazi/2010/discloser-0-0-4-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[discloser]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/discloser-0-0-4-high/</guid>
		<description><![CDATA[SQL injection vulnerability in index.php in Discloser 0.0.4 rc2 allows remote attackers to execute arbitrary SQL commands via the more parameter....

CVE Identifier: CVE-2009-4719
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Discloser 0.0.4 [High]
</ul>
<h3>Description</h3>
<p>SQL injection vulnerability in index.php in Discloser 0.0.4 rc2 allows remote attackers to execute arbitrary SQL commands via the more parameter.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4719" target="_blank">CVE-2009-4719</a><br />
Severity: High
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/discloser-0-0-4-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Broadcom  and prior [Unknown Severity]</title>
		<link>http://olex.openlogic.com/wazi/2010/broadcom-and-prior-unknown-severity-6/</link>
		<comments>http://olex.openlogic.com/wazi/2010/broadcom-and-prior-unknown-severity-6/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[broadcom]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/broadcom-and-prior-unknown-severity-6/</guid>
		<description><![CDATA[Unspecified vulnerability in the Broadcom Integrated NIC Management Firmware 1.x before 1.40.0.0 and 8.x before 8.08 on the HP Small Form Factor and Microtower platforms allows remote attackers to execute arbitrary code via unknown vectors....

CVE Identifier: CVE-2010-0104
Vulnerability Type(s): 
Severity: Unknown Severity
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Broadcom  and prior [Unknown Severity]
</ul>
<h3>Description</h3>
<p>Unspecified vulnerability in the Broadcom Integrated NIC Management Firmware 1.x before 1.40.0.0 and 8.x before 8.08 on the HP Small Form Factor and Microtower platforms allows remote attackers to execute arbitrary code via unknown vectors.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0104" target="_blank">CVE-2010-0104</a><br />
Severity: Unknown Severity
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/broadcom-and-prior-unknown-severity-6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Broadcom  and prior [Unknown Severity]</title>
		<link>http://olex.openlogic.com/wazi/2010/broadcom-and-prior-unknown-severity-5/</link>
		<comments>http://olex.openlogic.com/wazi/2010/broadcom-and-prior-unknown-severity-5/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[broadcom]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/broadcom-and-prior-unknown-severity-5/</guid>
		<description><![CDATA[Unspecified vulnerability in the Broadcom Integrated NIC Management Firmware 1.x before 1.40.0.0 and 8.x before 8.08 on the HP Small Form Factor and Microtower platforms allows remote attackers to execute arbitrary code via unknown vectors....

CVE Identifier: CVE-2010-0104
Vulnerability Type(s): 
Severity: Unknown Severity
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Broadcom  and prior [Unknown Severity]
</ul>
<h3>Description</h3>
<p>Unspecified vulnerability in the Broadcom Integrated NIC Management Firmware 1.x before 1.40.0.0 and 8.x before 8.08 on the HP Small Form Factor and Microtower platforms allows remote attackers to execute arbitrary code via unknown vectors.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0104" target="_blank">CVE-2010-0104</a><br />
Severity: Unknown Severity
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/broadcom-and-prior-unknown-severity-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Broadcom  and prior [Unknown Severity]</title>
		<link>http://olex.openlogic.com/wazi/2010/broadcom-and-prior-unknown-severity-4/</link>
		<comments>http://olex.openlogic.com/wazi/2010/broadcom-and-prior-unknown-severity-4/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[broadcom]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/broadcom-and-prior-unknown-severity-4/</guid>
		<description><![CDATA[Unspecified vulnerability in the Broadcom Integrated NIC Management Firmware 1.x before 1.40.0.0 and 8.x before 8.08 on the HP Small Form Factor and Microtower platforms allows remote attackers to execute arbitrary code via unknown vectors....

CVE Identifier: CVE-2010-0104
Vulnerability Type(s): 
Severity: Unknown Severity
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Broadcom  and prior [Unknown Severity]
</ul>
<h3>Description</h3>
<p>Unspecified vulnerability in the Broadcom Integrated NIC Management Firmware 1.x before 1.40.0.0 and 8.x before 8.08 on the HP Small Form Factor and Microtower platforms allows remote attackers to execute arbitrary code via unknown vectors.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0104" target="_blank">CVE-2010-0104</a><br />
Severity: Unknown Severity
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/broadcom-and-prior-unknown-severity-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
