<?xml version="1.0" encoding="ISO-8859-1" ?>
<rss version="2.0">
	<channel>
	<title>Packet Storm Security Last 20</title>
	<link>http://packetstormsecurity.org/</link>
	<description>20 Most Recent Packet Storm File Additions</description>
	<language>en-us</language>

<item>
	<title>phpauction32-rfi.txt</title>
	<link>http://packetstormsecurity.org/0809-exploits/phpauction32-rfi.txt</link>
	<description>PHP Auction version 3.2 suffers from remote file inclusion and information disclosure vulnerabilities. </description>
</item>
<item>
	<title>silentum-xss.txt</title>
	<link>http://packetstormsecurity.org/0809-exploits/silentum-xss.txt</link>
	<description>Silentum LoginSys version 1.0.0 suffers from a cross site scripting vulnerability. </description>
</item>
<item>
	<title>iranmc-sql.txt</title>
	<link>http://packetstormsecurity.org/0809-exploits/iranmc-sql.txt</link>
	<description>IranMC CMS suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>citectodbc-fivews.txt</title>
	<link>http://packetstormsecurity.org/papers/attack/citectodbc-fivews.txt</link>
	<description>This is a paper detailing the Five Ws of the Citect ODBC vulnerability that affects Citect versions 5, 6, and 7. </description>
</item>
<item>
	<title>citect_scada_odbc.rb.txt</title>
	<link>http://packetstormsecurity.org/0809-exploits/citect_scada_odbc.rb.txt</link>
	<description>This Metasploit module exploits a stack overflow in CitectSCADA's ODBC daemon. This has only been tested against Citect versions 5, 6, and 7. </description>
</item>
<item>
	<title>flockweb-dos.txt</title>
	<link>http://packetstormsecurity.org/0809-exploits/flockweb-dos.txt</link>
	<description>Flock Social Web Browser version 1.2.5 looping denial of service exploit. </description>
</item>
<item>
	<title>google-chrome-dos4.txt</title>
	<link>http://packetstormsecurity.org/0809-exploits/google-chrome-dos4.txt</link>
	<description>Google Chrome Browser version 0.2.149.27 Inspect Element denial of service exploit. </description>
</item>
<item>
	<title>google-download2.txt</title>
	<link>http://packetstormsecurity.org/0809-exploits/google-download2.txt</link>
	<description>Google Chrome Browser version 0.2.149.27 automatic file download exploit that uses window.setTimeout. </description>
</item>
<item>
	<title>PLSA-2008-41.txt</title>
	<link>http://packetstormsecurity.org/0809-advisories/PLSA-2008-41.txt</link>
	<description>Pardus Linux Security Advisory - Romain Francoise has found a security risk in a feature of GNU Emacs related to how Emacs interacts with Python. </description>
</item>
<item>
	<title>PLSA-2008-40.txt</title>
	<link>http://packetstormsecurity.org/0809-advisories/PLSA-2008-40.txt</link>
	<description>Pardus Linux Security Advisory - A security issue has been reported in Postfix, which can be exploited by malicious, local users to cause a DoS (Denial of Service). </description>
</item>
<item>
	<title>PLSA-2008-39.txt</title>
	<link>http://packetstormsecurity.org/0809-advisories/PLSA-2008-39.txt</link>
	<description>Pardus Linux Security Advisory - Multiple vulnerabilities have been discovered in Clamav including a DoS (Denial of Service) vulnerability and memory leaks. </description>
</item>
<item>
	<title>PLSA-2008-38.txt</title>
	<link>http://packetstormsecurity.org/0809-advisories/PLSA-2008-38.txt</link>
	<description>Pardus Linux Security Advisory - Some vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service). </description>
</item>
<item>
	<title>PLSA-2008-37.txt</title>
	<link>http://packetstormsecurity.org/0809-advisories/PLSA-2008-37.txt</link>
	<description>Pardus Linux Security Advisory - A vulnerability has been reported in Django, which can be exploited by malicious people to conduct cross-site request forgery attacks. </description>
</item>
<item>
	<title>MDVSA-2008-188.txt</title>
	<link>http://packetstormsecurity.org/0809-advisories/MDVSA-2008-188.txt</link>
	<description>Mandriva Linux Security Advisory - A number of vulnerabilities have been discovered in the Apache Tomcat server. The default catalina.policy in the JULI logging component did not restrict certain permissions for web applications which could allow a remote attacker to modify logging configuration options and overwrite arbitrary files. A cross-site scripting vulnerability was found in the HttpServletResponse.sendError() method which could allow a remote attacker to inject arbitrary web script or HTML via forged HTTP headers. A cross-site scripting vulnerability was found in the host manager application that could allow a remote attacker to inject arbitrary web script or HTML via the hostname parameter. A traversal vulnerability was found when using a RequestDispatcher in combination with a servlet or JSP that could allow a remote attacker to utilize a specially-crafted request parameter to access protected web resources. A traversal vulnerability was found when the 'allowLinking' and 'URIencoding' settings were actived which could allow a remote attacker to use a UTF-8-encoded request to extend their privileges and obtain local files accessible to the Tomcat process. The updated packages have been patched to correct these issues. </description>
</item>
<item>
	<title>glsa-200809-05.txt</title>
	<link>http://packetstormsecurity.org/0809-advisories/glsa-200809-05.txt</link>
	<description>Gentoo Linux Security Advisory GLSA 200809-05 - It has been discovered that some input (e.g. the username) passed to the Courier Authentication library are not properly sanitised before being used in SQL queries. Versions less than 0.60.6 are affected. </description>
</item>
<item>
	<title>freebsd-revcon.txt</title>
	<link>http://packetstormsecurity.org/shellcode/freebsd-revcon.txt</link>
	<description>90 byte rev connect, recv, jmp, return results shellcode for freebsd/x86. </description>
</item>
<item>
	<title>webcmsportal-blindsql.txt</title>
	<link>http://packetstormsecurity.org/0809-exploits/webcmsportal-blindsql.txt</link>
	<description>webCMS Portal Edition blind SQL injection exploit that leverages index.php. </description>
</item>
<item>
	<title>esfaq-sql.txt</title>
	<link>http://packetstormsecurity.org/0809-exploits/esfaq-sql.txt</link>
	<description>EsFaq version 2.0 suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>vastal-itechcosmetics.txt</title>
	<link>http://packetstormsecurity.org/0809-exploits/vastal-itechcosmetics.txt</link>
	<description>Vastal I-Tech Cosmetics Zone suffers from a remote SQL injection vulnerability in view_products_cat.php. </description>
</item>
<item>
	<title>vastal-itechfreelance.txt</title>
	<link>http://packetstormsecurity.org/0809-exploits/vastal-itechfreelance.txt</link>
	<description>Vastal I-Tech Freelance Zone suffers from a remote SQL injection vulnerability in view_cresume.php. </description>
</item></channel>
</rss>
