<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Webremix Articles</title>
    <link>http://www.webremix.info/</link>
    <description>Webremix : all the web new, remixed</description>
    <dc:creator>webremix.info</dc:creator>
    <item>
      <title>Basic OOP In PHP Part One</title>
      <link>http://www.topix.net/tech/java/2010/08/basic-oop-in-php-part-one?fromrss=1</link>
      <description>&lt;p&gt;Object-Oriented Programming, OOP for short, is a concept that has root as far back as the 1960's, but has not been in common use within mainstream software development until the 1990's. With the release of PHP5 in 2004, the PHP code finally gained a whole OOP infrastructure to compete with the likes of Java and C# and the popularity of using OOP in ...&lt;/p&gt;</description>
      <pubDate>Fri, 27 Aug 2010 18:59:26 GMT</pubDate>
      <guid>http://www.topix.net/tech/java/2010/08/basic-oop-in-php-part-one?fromrss=1</guid>
      <dc:date>2010-08-27T18:59:26Z</dc:date>
    </item>
    <item>
      <title>CVE-2009-4993</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4993</link>
      <description>PHP remote file inclusion vulnerability in home.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.</description>
      <pubDate>Wed, 25 Aug 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4993</guid>
      <dc:date>2010-08-25T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2009-4985 (accessories_me_php_affiliate_script)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4985</link>
      <description>SQL injection vulnerability in browse.php in Accessories Me PHP Affiliate Script 1.4 allows remote attackers to execute arbitrary SQL commands via the Go parameter.</description>
      <pubDate>Wed, 25 Aug 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4985</guid>
      <dc:date>2010-08-25T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2009-4977 (mybackup)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4977</link>
      <description>PHP remote file inclusion vulnerability in index.php in MyBackup 1.4.0 allows remote authenticated users to execute arbitrary PHP code via a URL in the main_content parameter.</description>
      <pubDate>Wed, 25 Aug 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4977</guid>
      <dc:date>2010-08-25T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2009-4984 (accessories_me_php_affiliate_script)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4984</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in Accessories Me PHP Affiliate Script 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) Keywords parameter to search.php and (2) SearchIndex parameter to browse.php.</description>
      <pubDate>Wed, 25 Aug 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4984</guid>
      <dc:date>2010-08-25T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2009-4980 (photokorn_gallery)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4980</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in Photokorn Gallery 1.81 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) where[] parameter to search.php and (2) qc parameter to admin.php.</description>
      <pubDate>Wed, 25 Aug 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4980</guid>
      <dc:date>2010-08-25T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2009-4983 (silurus_system)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4983</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in Silurus Classifieds 1.0 allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) category.php and (2) wcategory.php, and the (3) keywords parameter to search.php.</description>
      <pubDate>Wed, 25 Aug 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4983</guid>
      <dc:date>2010-08-25T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-3056 (phpmyadmin)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3056</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) db_search.php, (2) db_sql.php, (3) db_structure.php, (4) js/messages.php, (5) libraries/common.lib.php, (6) libraries/database_interface.lib.php, (7) libraries/dbi/mysql.dbi.lib.php, (8) libraries/dbi/mysqli.dbi.lib.php, (9) libraries/db_info.inc.php, (10) libraries/sanitizing.lib.php, (11) lib...</description>
      <pubDate>Tue, 24 Aug 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3056</guid>
      <dc:date>2010-08-24T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-2545 (cacti)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2545</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7g, as used in Red Hat High Performance Computing (HPC) Solution and other products, allow remote attackers to inject arbitrary web script or HTML via (1) the name element in an XML template to templates_import.php; and allow remote authenticated administrators to inject arbitrary web script or HTML via vectors related to (2) cdef.php, (3) data_input.php, (4) data_queries.php, (5) data_sources.php, (6) data_templates.php,...</description>
      <pubDate>Mon, 23 Aug 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2545</guid>
      <dc:date>2010-08-23T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: SlideShowPro Director 'p.php' Directory Traversal Vulnerability</title>
      <link>http://www.securityfocus.com/bid/42566</link>
      <description>SlideShowPro Director 'p.php' Directory Traversal Vulnerability</description>
      <pubDate>Fri, 20 Aug 2010 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/42566</guid>
      <dc:date>2010-08-20T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: CMS Made Simple 'modules/Printing/output.php' CMS Local File Include Vulnerability</title>
      <link>http://www.securityfocus.com/bid/36005</link>
      <description>CMS Made Simple 'modules/Printing/output.php' CMS Local File Include Vulnerability</description>
      <pubDate>Thu, 19 Aug 2010 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/36005</guid>
      <dc:date>2010-08-19T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Run PHP tests in your Perl test suite</title>
      <link>http://feedproxy.google.com/~r/PerlBuzz/~3/RIk5nyxbFjo/run-php-tests-in-your-perl-test-suite.html</link>
      <description>Sometimes you've got a big codebase that isn't just Perl. Maybe you've got PHP mixed in with it, and you want to test the PHP along with all the Perl code, too. Perl's prove program doesn't care if the testing...</description>
      <pubDate>Tue, 17 Aug 2010 22:30:54 GMT</pubDate>
      <guid>http://feedproxy.google.com/~r/PerlBuzz/~3/RIk5nyxbFjo/run-php-tests-in-your-perl-test-suite.html</guid>
      <dc:date>2010-08-17T22:30:54Z</dc:date>
    </item>
    <item>
      <title>Run PHP tests in your Perl test suite</title>
      <link>http://perlbuzz.com/2010/08/run-php-tests-in-your-perl-test-suite.html</link>
      <description>Sometimes you've got a big codebase that isn't just Perl. Maybe you've got PHP mixed in with it, and you want to test the PHP along with all the Perl code, too. Perl's prove program doesn't care if the testing...</description>
      <pubDate>Tue, 17 Aug 2010 22:30:54 GMT</pubDate>
      <guid>http://perlbuzz.com/2010/08/run-php-tests-in-your-perl-test-suite.html</guid>
      <dc:date>2010-08-17T22:30:54Z</dc:date>
    </item>
    <item>
      <title>Embarcadero tackles the cloud with tools for PHP and Windows</title>
      <link>http://www.topix.net/science/computer-science/2010/08/embarcadero-tackles-the-cloud-with-tools-for-php-and-windows?fromrss=1</link>
      <description>&lt;p&gt;Embarcadero Technologies will release later this month upgraded development tools for Windows and PHP as part of its RAD Studio XE suite.&lt;/p&gt;</description>
      <pubDate>Tue, 17 Aug 2010 13:47:38 GMT</pubDate>
      <guid>http://www.topix.net/science/computer-science/2010/08/embarcadero-tackles-the-cloud-with-tools-for-php-and-windows?fromrss=1</guid>
      <dc:date>2010-08-17T13:47:38Z</dc:date>
    </item>
    <item>
      <title>Vuln: Retired: CruxCMS 'login.php' Cross-Site Scripting Vulnerability</title>
      <link>http://www.securityfocus.com/bid/41501</link>
      <description>Retired: CruxCMS 'login.php' Cross-Site Scripting Vulnerability</description>
      <pubDate>Mon, 16 Aug 2010 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/41501</guid>
      <dc:date>2010-08-16T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: CMSQLite 'admin/mediaAdmin.php' Arbitrary File Upload Vulnerability</title>
      <link>http://www.securityfocus.com/bid/42465</link>
      <description>CMSQLite 'admin/mediaAdmin.php' Arbitrary File Upload Vulnerability</description>
      <pubDate>Mon, 16 Aug 2010 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/42465</guid>
      <dc:date>2010-08-16T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: clearBudget 'controller.class.php' Remote File Include Vulnerability</title>
      <link>http://www.securityfocus.com/bid/42351</link>
      <description>clearBudget 'controller.class.php' Remote File Include Vulnerability</description>
      <pubDate>Wed, 11 Aug 2010 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/42351</guid>
      <dc:date>2010-08-11T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: PHP Versions Prior to 5.3.3/5.2.14 Multiple Vulnerabilities</title>
      <link>http://www.securityfocus.com/bid/41991</link>
      <description>PHP Versions Prior to 5.3.3/5.2.14 Multiple Vulnerabilities</description>
      <pubDate>Mon, 09 Aug 2010 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/41991</guid>
      <dc:date>2010-08-09T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-2790 (zabbix)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2790</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function in frontends/php/include/classes/class.curl.php in Zabbix before 1.8.3rc1 allow remote attackers to inject arbitrary web script or HTML via the (1) filter_set, (2) show_details, (3) filter_rst, or (4) txt_select parameters to the triggers page (tr_status.php).  NOTE: some of these details are obtained from third party information.</description>
      <pubDate>Thu, 05 Aug 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2790</guid>
      <dc:date>2010-08-05T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: RETIRED: PhotoPost PHP 'index.php' SQL Injection Vulnerability</title>
      <link>http://www.securityfocus.com/bid/41916</link>
      <description>RETIRED: PhotoPost PHP 'index.php' SQL Injection Vulnerability</description>
      <pubDate>Tue, 03 Aug 2010 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/41916</guid>
      <dc:date>2010-08-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: All Enthusiast Photopost PHP Pro Multiple Input Validation Vulnerabilities</title>
      <link>http://www.securityfocus.com/bid/9994</link>
      <description>All Enthusiast Photopost PHP Pro Multiple Input Validation Vulnerabilities</description>
      <pubDate>Tue, 03 Aug 2010 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/9994</guid>
      <dc:date>2010-08-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-2918</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2918</link>
      <description>PHP remote file inclusion vulnerability in core/include/myMailer.class.php in the Visites (com_joomla-visites) component 1.1 RC2 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.</description>
      <pubDate>Fri, 30 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2918</guid>
      <dc:date>2010-07-30T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: PHP Traverser 'mp3_id.php' Remote File Include Vulnerability</title>
      <link>http://www.securityfocus.com/bid/41899</link>
      <description>PHP Traverser 'mp3_id.php' Remote File Include Vulnerability</description>
      <pubDate>Thu, 29 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/41899</guid>
      <dc:date>2010-07-29T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-2909</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2909</link>
      <description>SQL injection vulnerability in ttvideo.php in the TTVideo (com_ttvideo) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a video action to index.php.</description>
      <pubDate>Wed, 28 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2909</guid>
      <dc:date>2010-07-28T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Bugtraq: [ MDVSA-2010:140 ] php</title>
      <link>http://www.securityfocus.com/archive/1/512686</link>
      <description>[ MDVSA-2010:140 ] php</description>
      <pubDate>Tue, 27 Jul 2010 23:20:51 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/512686</guid>
      <dc:date>2010-07-27T23:20:51Z</dc:date>
    </item>
    <item>
      <title>Vuln: vBulletin 'faq.php' Information Disclosure Vulnerability</title>
      <link>http://www.securityfocus.com/bid/41875</link>
      <description>vBulletin 'faq.php' Information Disclosure Vulnerability</description>
      <pubDate>Thu, 22 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/41875</guid>
      <dc:date>2010-07-22T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2009-4936 (small_pirate)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4936</link>
      <description>Multiple SQL injection vulnerabilities in Small Pirate (SPirate) 2.1 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to the default URI in an rss .xml action, or the id parameter to (2) pag1.php, (3) pag1-guest.php, (4) rss-comment_post.php (aka rss-coment_post.php), or (5) rss-pic-comment.php.</description>
      <pubDate>Thu, 22 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4936</guid>
      <dc:date>2010-07-22T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Philippine-Listed Firms 1Q Combined Net Profit More Than Doubled To PHP137 Billion</title>
      <link>http://story.venezuelastar.com/index.php/ct/9/cid/3a8a80d6f705f8cc/id/37056169/</link>
      <description>MANILA -(Dow Jones)- The combined net earnings of companies listed on the local bourse more than doubled to PHP137.08  billion ($2.95 billion) in the first quarter from PHP64.08 billion a year earlier...</description>
      <pubDate>Tue, 20 Jul 2010 08:16:58 GMT</pubDate>
      <guid>http://story.venezuelastar.com/index.php/ct/9/cid/3a8a80d6f705f8cc/id/37056169/</guid>
      <dc:date>2010-07-20T08:16:58Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-2715 (tcw_php_album)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2715</link>
      <description>Cross-site scripting (XSS) vulnerability in photos/index.php in TCW PHP Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the album parameter.</description>
      <pubDate>Tue, 13 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2715</guid>
      <dc:date>2010-07-13T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-2714 (tcw_php_album)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2714</link>
      <description>SQL injection vulnerability in photos/index.php in TCW PHP Album 1.0 allows remote attackers to execute arbitrary SQL commands via the album parameter.</description>
      <pubDate>Tue, 13 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2714</guid>
      <dc:date>2010-07-13T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-2718 (cruxpa)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2718</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in CruxSoftware CruxPA 2.00, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) txtusername parameter to login.php, (2) todo parameter to newtodo.php, and unspecified vectors to (3) newtelephone.php and (4) newappointment.php.</description>
      <pubDate>Tue, 13 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2718</guid>
      <dc:date>2010-07-13T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-2716 (psnews)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2716</link>
      <description>Multiple SQL injection vulnerabilities in PsNews 1.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) ndetail.php and (2) print.php.</description>
      <pubDate>Tue, 13 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2716</guid>
      <dc:date>2010-07-13T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2009-4926 (online_contact_manager)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4926</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in Online Contact Manager (formerly EContact PRO) 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) showGroup parameter to (a) index.php and the (2) id parameter to (b) view.php, (c) email.php, (d) edit.php, and (e) delete.php.</description>
      <pubDate>Mon, 12 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4926</guid>
      <dc:date>2010-07-12T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-2681 (com_sef)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2681</link>
      <description>PHP remote file inclusion vulnerability in the SEF404x (com_sef) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig.absolute.path parameter to index.php.</description>
      <pubDate>Mon, 12 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2681</guid>
      <dc:date>2010-07-12T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2009-4928 (totalcalendar)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4928</link>
      <description>PHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922 and CVE-2006-7055.</description>
      <pubDate>Mon, 12 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4928</guid>
      <dc:date>2010-07-12T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-2700</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2700</link>
      <description>Cross-site scripting (XSS) vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to inject arbitrary web script or HTML via the search parameter.</description>
      <pubDate>Mon, 12 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2700</guid>
      <dc:date>2010-07-12T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-2699</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2699</link>
      <description>SQL injection vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to execute arbitrary SQL commands via the search parameter.</description>
      <pubDate>Mon, 12 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2699</guid>
      <dc:date>2010-07-12T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-2691 (custom_t-shirt_design_script)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2691</link>
      <description>Multiple SQL injection vulnerabilities in 2daybiz Custom T-Shirt Design Script allow remote attackers to execute arbitrary SQL commands via the (1) sbid parameter to products_details.php, (2) pid parameter to products/products.php, and (3) designid parameter to designview.php.</description>
      <pubDate>Mon, 12 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2691</guid>
      <dc:date>2010-07-12T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-2654 (advanced_management_module)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2654</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, allow remote attackers to inject arbitrary web script or HTML via the (1) INDEX or (2) IPADDR parameter to private/cindefn.php, (3) the domain parameter to private/power_management_policy_options.php, the slot parameter to (4) private/pm_temp.php or (5) private/power_module.php, (6) the WEBINDEX parameter to...</description>
      <pubDate>Thu, 08 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2654</guid>
      <dc:date>2010-07-08T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-2677</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2677</link>
      <description>PHP remote file inclusion vulnerability in mw_plugin.php in Open Web Analytics (OWA) 1.2.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter.  NOTE: some of these details are obtained from third party information.</description>
      <pubDate>Thu, 08 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2677</guid>
      <dc:date>2010-07-08T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Resources: Windows Azure for PHP developers</title>
      <link>http://www.topix.net/tech/java/2010/07/resources-windows-azure-for-php-developers?fromrss=1</link>
      <description>&lt;p&gt;Many thanks to the folks who came out for my talk last week at Atlanta PHP on Windows Azure.&lt;/p&gt;</description>
      <pubDate>Tue, 06 Jul 2010 22:59:11 GMT</pubDate>
      <guid>http://www.topix.net/tech/java/2010/07/resources-windows-azure-for-php-developers?fromrss=1</guid>
      <dc:date>2010-07-06T22:59:11Z</dc:date>
    </item>
    <item>
      <title>Vuln: BrotherScripts Auto Dealer Software 'info.php' SQL Injection Vulnerability</title>
      <link>http://www.securityfocus.com/bid/41384</link>
      <description>BrotherScripts Auto Dealer Software 'info.php' SQL Injection Vulnerability</description>
      <pubDate>Tue, 06 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/41384</guid>
      <dc:date>2010-07-06T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-1328 (tornadostore)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-1328</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) tipo or (2) destino parameter to login_registrese.php3 in the Services section, (3) the rubro parameter to precios.php3 in the Products section, (4) the arti parameter to recomenda_articulo.php3 in the Products section, (5) the descrip parameter in a profile action to control/abm_det.php3 in the e-Commerce section, (6) the tit paramete...</description>
      <pubDate>Tue, 06 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-1328</guid>
      <dc:date>2010-07-06T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: phpFK PHP Forum ohne 'search.php' Cross Site Scripting Vulnerability</title>
      <link>http://www.securityfocus.com/bid/41330</link>
      <description>phpFK PHP Forum ohne 'search.php' Cross Site Scripting Vulnerability</description>
      <pubDate>Mon, 05 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/41330</guid>
      <dc:date>2010-07-05T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: iScripts SocialWare 'events.php' SQL Injection Vulnerability</title>
      <link>http://www.securityfocus.com/bid/28669</link>
      <description>iScripts SocialWare 'events.php' SQL Injection Vulnerability</description>
      <pubDate>Mon, 05 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/28669</guid>
      <dc:date>2010-07-05T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: Wiki Web Help 'uploadimage.php' Arbitrary File Upload Vulnerability</title>
      <link>http://www.securityfocus.com/bid/41309</link>
      <description>Wiki Web Help 'uploadimage.php' Arbitrary File Upload Vulnerability</description>
      <pubDate>Mon, 05 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/41309</guid>
      <dc:date>2010-07-05T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-2624</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2624</link>
      <description>Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) comment parameter to add_comments.php, (2) values parameter to tags_details.php, or (3) begin parameter to greetings.php.</description>
      <pubDate>Fri, 02 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2624</guid>
      <dc:date>2010-07-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-2618 (adapcms)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2618</link>
      <description>PHP remote file inclusion vulnerability in inc/smarty/libs/init.php in AdaptCMS 2.0.0 Beta, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the sitepath parameter.</description>
      <pubDate>Fri, 02 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2618</guid>
      <dc:date>2010-07-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-2617 (php_bible_search)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2617</link>
      <description>Cross-site scripting (XSS) vulnerability in bible.php in PHP Bible Search allows remote attackers to inject arbitrary web script or HTML via the chapter parameter.</description>
      <pubDate>Fri, 02 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2617</guid>
      <dc:date>2010-07-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-2616 (php_bible_search)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2616</link>
      <description>SQL injection vulnerability in bible.php in PHP Bible Search, probably 0.99, allows remote attackers to execute arbitrary SQL commands via the chapter parameter.</description>
      <pubDate>Fri, 02 Jul 2010 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2616</guid>
      <dc:date>2010-07-02T00:00:00Z</dc:date>
    </item>
  </channel>
</rss>

