<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Webremix Articles</title>
    <link>http://www.webremix.info/</link>
    <description>Webremix : all the web new, remixed</description>
    <dc:creator>webremix.info</dc:creator>
    <item>
      <title>Bugtraq: [SECURITY] [DSA 2403-1] php5 security update</title>
      <link>http://www.securityfocus.com/archive/1/521479</link>
      <description>[SECURITY] [DSA 2403-1] php5 security update</description>
      <pubDate>Fri, 03 Feb 2012 22:23:13 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/521479</guid>
      <dc:date>2012-02-03T22:23:13Z</dc:date>
    </item>
    <item>
      <title>Vuln: PHP 'php_register_variable_ex()' Function Arbitrary Code Execution Vulnerability</title>
      <link>http://www.securityfocus.com/bid/51830</link>
      <description>PHP 'php_register_variable_ex()' Function Arbitrary Code Execution Vulnerability</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/51830</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: PHP CVE-2012-0057 Security Bypass Vulnerability</title>
      <link>http://www.securityfocus.com/bid/51806</link>
      <description>PHP CVE-2012-0057 Security Bypass Vulnerability</description>
      <pubDate>Thu, 02 Feb 2012 11:28:58 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/51806</guid>
      <dc:date>2012-02-02T11:28:58Z</dc:date>
    </item>
    <item>
      <title>CVE-2012-0980</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0980</link>
      <description>SQL injection vulnerability in download.php in phux Download Manager allows remote attackers to execute arbitrary SQL commands via the file parameter.</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0980</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Bugtraq: [SECURITY] [DSA 2399-2] php5 regression fix</title>
      <link>http://www.securityfocus.com/archive/1/521426</link>
      <description>[SECURITY] [DSA 2399-2] php5 regression fix</description>
      <pubDate>Tue, 31 Jan 2012 23:11:52 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/521426</guid>
      <dc:date>2012-01-31T23:11:52Z</dc:date>
    </item>
    <item>
      <title>Bugtraq: [SECURITY] [DSA 2399-1] php5 security update</title>
      <link>http://www.securityfocus.com/archive/1/521420</link>
      <description>[SECURITY] [DSA 2399-1] php5 security update</description>
      <pubDate>Tue, 31 Jan 2012 22:56:52 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/521420</guid>
      <dc:date>2012-01-31T22:56:52Z</dc:date>
    </item>
    <item>
      <title>Bank Of The Philippine Islands 2011 Net Profit Up 13% At PHP12.8 Billion</title>
      <link>http://story.venezuelastar.com/index.php/ct/9/cid/3a8a80d6f705f8cc/id/203072114/</link>
      <description>MANILA &amp;ndash; Bank of the Philippine Islands' (BPI.PH) 2011 net profit increased 13% to PHP12.8 billion ($299 million) from PHP11. 3 billion in 2010, buoyed by a larger net loan portfolio and  ...</description>
      <pubDate>Mon, 30 Jan 2012 05:57:53 GMT</pubDate>
      <guid>http://story.venezuelastar.com/index.php/ct/9/cid/3a8a80d6f705f8cc/id/203072114/</guid>
      <dc:date>2012-01-30T05:57:53Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-5073</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5073</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to inject arbitrary web script or HTML via the (1) mode parameter to contact_support.php; (2) contractid parameter to contract_add_service.php; (3) user parameter to edit_backup_users.php; (4) id parameter to edit_escalation_path.php; the Referer to (5) forgotpwd.php, (6) an approvalpage action to billable_incidents.php, or (7) transactions.php; (8) action parameter to...</description>
      <pubDate>Sun, 29 Jan 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5073</guid>
      <dc:date>2012-01-29T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-5072</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5072</link>
      <description>Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to execute arbitrary SQL commands via the (1) start parameter to portal/kb.php; (2) contractid parameter to contract_add_service.php; (3) id parameter to edit_escalation_path.php; (4) unlock, (5) lock, or (6) selected parameter to holding_queue.php; inc parameter in a report action to (7) report_customers.php or (8) report_incidents_by_site.php; (9) start parameter to search.php; o...</description>
      <pubDate>Sun, 29 Jan 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5072</guid>
      <dc:date>2012-01-29T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4337</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4337</link>
      <description>Static code injection vulnerability in translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to inject arbitrary PHP code into an executable language file in the i18n directory via the lang variable.</description>
      <pubDate>Sun, 29 Jan 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4337</guid>
      <dc:date>2012-01-29T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2012-0934</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0934</link>
      <description>PHP remote file inclusion vulnerability in ajax/savetag.php in the Theme Tuner plugin for WordPress before 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the tt-abspath parameter.</description>
      <pubDate>Sat, 28 Jan 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0934</guid>
      <dc:date>2012-01-28T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-5071</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5071</link>
      <description>Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to execute arbitrary SQL commands via the (1) exc[] parameter to report_marketing.php, (2) selected[] parameter to tasks.php, (3) sites[] parameter to billable_incidents.php, or (4) search_string parameter to search.php. NOTE: some of these details are obtained from third party information.</description>
      <pubDate>Sat, 28 Jan 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5071</guid>
      <dc:date>2012-01-28T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-3832</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3832</link>
      <description>Eval injection vulnerability in config.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated administrators to execute arbitrary PHP code via the application_name parameter in a save action.</description>
      <pubDate>Sat, 28 Jan 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3832</guid>
      <dc:date>2012-01-28T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-5070</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5070</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to inject arbitrary web script or HTML via (1) the file name to incident_attachments.php; (2) unspecified vectors in link_add.php, possibly involving origref, linkref, linktype parameters, which are not properly handled in the clean_int function in lib/base.inc.php, or the redirect parameter, which is not properly handled in the html_redirect function in lib/html.inc.php; and...</description>
      <pubDate>Sat, 28 Jan 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5070</guid>
      <dc:date>2012-01-28T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-3833</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3833</link>
      <description>Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in an unspecified directory.</description>
      <pubDate>Sat, 28 Jan 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3833</guid>
      <dc:date>2012-01-28T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2012-0069</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0069</link>
      <description>SQL injection vulnerability in ajax.php in Batavi before 1.2.1 allows remote attackers to execute arbitrary SQL commands via the boxToReload parameter.</description>
      <pubDate>Tue, 24 Jan 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0069</guid>
      <dc:date>2012-01-24T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Bugtraq: Wordpress Kish Guest Posting Plugin 1.0 (uploadify.php) Unrestricted File Upload Vulnerability</title>
      <link>http://www.securityfocus.com/archive/1/521337</link>
      <description>Wordpress Kish Guest Posting Plugin 1.0 (uploadify.php) Unrestricted File Upload Vulnerability</description>
      <pubDate>Mon, 23 Jan 2012 22:57:29 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/521337</guid>
      <dc:date>2012-01-23T22:57:29Z</dc:date>
    </item>
    <item>
      <title>CVE-2012-0900</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0900</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in Beehive Forum 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) forum/register.php or (2) forum/logon.php.</description>
      <pubDate>Fri, 20 Jan 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0900</guid>
      <dc:date>2012-01-20T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2012-0899</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0899</link>
      <description>Cross-site scripting (XSS) vulnerability in referencement/sites_inscription.php in Annuaire PHP allows remote attackers to inject arbitrary web script or HTML via the url parameter and possibly the nom parameter.</description>
      <pubDate>Fri, 20 Jan 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0899</guid>
      <dc:date>2012-01-20T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Bugtraq: Advisory 01/2012: Suhosin PHP Extension Transparent Cookie Encryption Stack Buffer Overflow</title>
      <link>http://www.securityfocus.com/archive/1/521309</link>
      <description>Advisory 01/2012: Suhosin PHP Extension Transparent Cookie Encryption Stack Buffer Overflow</description>
      <pubDate>Thu, 19 Jan 2012 23:12:12 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/521309</guid>
      <dc:date>2012-01-19T23:12:12Z</dc:date>
    </item>
    <item>
      <title>Installing Apache2 With PHP5 And MySQL Support On Fedora 16 (LAMP)</title>
      <link>http://www.howtoforge.com/installing-apache2-with-php5-and-mysql-support-on-fedora-16-lamp</link>
      <description>Installing Apache2 With PHP5 And MySQL Support On Fedora 16 (LAMP)

 LAMP is short for Linux, Apache, MySQL, PHP.
  This tutorial shows how you can install an Apache2 webserver on a 
Fedora 16 server with PHP5 support (mod_php) and MySQL support.</description>
      <pubDate>Sun, 15 Jan 2012 19:40:20 GMT</pubDate>
      <guid>http://www.howtoforge.com/installing-apache2-with-php5-and-mysql-support-on-fedora-16-lamp</guid>
      <dc:date>2012-01-15T19:40:20Z</dc:date>
    </item>
    <item>
      <title>PHP mysqli quickstart is online!</title>
      <link>http://blog.ulf-wendel.de/2012/php-mysqli-quickstart-is-online/</link>
      <description>New in the PHP manual: a mysqli quickstart.  You are new to PHP but you know how to code, you know SQL, you know relational databases and MySQL? Then, I hope, this is for you.  All you need is a quick overview on the concepts? The rest is in the reference section! Here you go.

	
The quickstart contains:
	
	Dual procedural and object-oriented interface:
something pioneerd by MySQL when PHP learned OOP at 5.0 times.

	Connections: how, options, persistent/pooled connections.
	Executing statements: buffered, unbuffered, impact of MySQL Client Server protocol flavour used
	Prepared Statements: what, how, pros and cons
	Stored Procedures: how, parameters, prepared statements
	Multiple Statements: what, security considerations
	API support for transactions
	Metadata
	
	
In case you prefer listening over reading there is a PHP MySQL web seminar series  on PHP for you (hint: search &amp;quot;On Demand&amp;quot; for more).  To please everybody, we are giving a webinar summary in german as well on 18.01.2012, register now.

	
Please, note that I am inpatient and linking to the PHP documentation teams server: http://docs.php.net/manual/en/mysqli.quickstart.php. The php.net mirrors will need a while to catch up.

	Happy hacking!
	
@Ulf_Wendel</description>
      <pubDate>Thu, 12 Jan 2012 18:31:40 GMT</pubDate>
      <guid>http://blog.ulf-wendel.de/2012/php-mysqli-quickstart-is-online/</guid>
      <dc:date>2012-01-12T18:31:40Z</dc:date>
    </item>
    <item>
      <title>Upcoming talks</title>
      <link>http://schlueters.de/blog/archives/165-guid.html</link>
      <description>Over the last few weeks I had been quite silent, but that's about to change: Over the next few weeks I'll give a few presentations. Feel free to join any of those. 
 
January, 18th: Erstellung hochperformanter PHP-Anwendungen mit MySQL (German)MySQL Webinar, Online 
February, 9th: MySQL Konnectoren (German)OTN Developer Day: MySQL, Frankfurt, Germany 
February 24th/25th: PHP under the hood (English)PHP UK Conference, London, UK</description>
      <pubDate>Thu, 12 Jan 2012 10:54:40 GMT</pubDate>
      <guid>http://schlueters.de/blog/archives/165-guid.html</guid>
      <dc:date>2012-01-12T10:54:40Z</dc:date>
    </item>
    <item>
      <title>Installing Apache2 With PHP5 And MySQL Support On CentOS 6.1 (LAMP)</title>
      <link>http://www.howtoforge.com/installing-apache2-with-php5-and-mysql-support-on-centos-6.1-lamp</link>
      <description>Installing Apache2 With PHP5 And MySQL Support On CentOS 6.1 (LAMP)

 LAMP is short for Linux, Apache, MySQL, PHP.
  This tutorial shows how you can install an Apache2 webserver on a 
CentOS 6.1 server with PHP5 support (mod_php) and MySQL support.</description>
      <pubDate>Mon, 09 Jan 2012 17:42:56 GMT</pubDate>
      <guid>http://www.howtoforge.com/installing-apache2-with-php5-and-mysql-support-on-centos-6.1-lamp</guid>
      <dc:date>2012-01-09T17:42:56Z</dc:date>
    </item>
    <item>
      <title>Vuln: ImpressPages CMS 'actions.php' Remote Code Execution Vulnerability</title>
      <link>http://www.securityfocus.com/bid/49798</link>
      <description>ImpressPages CMS 'actions.php' Remote Code Execution Vulnerability</description>
      <pubDate>Thu, 05 Jan 2012 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/49798</guid>
      <dc:date>2012-01-05T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: WordPress 'wp-comments-post.php' Cross Site Scripting Vulnerability</title>
      <link>http://www.securityfocus.com/bid/51237</link>
      <description>WordPress 'wp-comments-post.php' Cross Site Scripting Vulnerability</description>
      <pubDate>Wed, 04 Jan 2012 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/51237</guid>
      <dc:date>2012-01-04T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4920</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4920</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.26, and other versions before 1.0.0, allow remote attackers to inject arbitrary web script or HTML via the URL to (1) e107_images/thumb.php or (2) rate.php, (3) resend_name parameter to e107_admin/users.php, and (4) link BBCode in user signatures.</description>
      <pubDate>Wed, 04 Jan 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4920</guid>
      <dc:date>2012-01-04T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Bugtraq: Re: PHP Booking Calendar 10e XSS</title>
      <link>http://www.securityfocus.com/archive/1/521096</link>
      <description>Re: PHP Booking Calendar 10e XSS</description>
      <pubDate>Tue, 03 Jan 2012 23:06:24 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/521096</guid>
      <dc:date>2012-01-03T23:06:24Z</dc:date>
    </item>
    <item>
      <title>Vuln: PHP Web Form Hash Collision Denial Of Service Vulnerability</title>
      <link>http://www.securityfocus.com/bid/51193</link>
      <description>PHP Web Form Hash Collision Denial Of Service Vulnerability</description>
      <pubDate>Mon, 02 Jan 2012 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/51193</guid>
      <dc:date>2012-01-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: WordPress WP Live.php 's' Parameter Cross Site Scripting Vulnerability</title>
      <link>http://www.securityfocus.com/bid/51220</link>
      <description>WordPress WP Live.php 's' Parameter Cross Site Scripting Vulnerability</description>
      <pubDate>Sun, 01 Jan 2012 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/51220</guid>
      <dc:date>2012-01-01T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Bugtraq: [ MDVSA-2011:197 ] php</title>
      <link>http://www.securityfocus.com/archive/1/521060</link>
      <description>[ MDVSA-2011:197 ] php</description>
      <pubDate>Fri, 30 Dec 2011 22:50:39 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/521060</guid>
      <dc:date>2011-12-30T22:50:39Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-5045</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5045</link>
      <description>Cross-site scripting (XSS) vulnerability in details_view.php in PHP Booking Calendar 10e allows remote attackers to inject arbitrary web script or HTML via the page_info_message parameter.</description>
      <pubDate>Fri, 30 Dec 2011 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5045</guid>
      <dc:date>2011-12-30T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-5040</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5040</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in Infoproject Biznis Heroj allow remote attackers to inject arbitrary web script or HTML via the config parameter to (1) nalozi_naslov.php and (2) widget.dokumenti_lista.php.</description>
      <pubDate>Fri, 30 Dec 2011 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5040</guid>
      <dc:date>2011-12-30T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-5039</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5039</link>
      <description>Multiple SQL injection vulnerabilities in Infoproject Biznis Heroj allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to login.php, (3) the filter parameter to widget.dokumenti_lista.php, and (4) the fin_nalog_id parameter to nalozi_naslov.php.</description>
      <pubDate>Fri, 30 Dec 2011 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5039</guid>
      <dc:date>2011-12-30T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4615</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4615</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the gname parameter (aka host groups name) to (1) hostgroups.php and (2) usergrps.php, the update action to (3) hosts.php and (4) scripts.php, and (5) maintenance.php.</description>
      <pubDate>Thu, 29 Dec 2011 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4615</guid>
      <dc:date>2011-12-29T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-5029</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5029</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.7.0 and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry parameter to delete.php or (2) category parameter to index.php.</description>
      <pubDate>Thu, 29 Dec 2011 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5029</guid>
      <dc:date>2011-12-29T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-5022 (pligg_cms)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5022</link>
      <description>SQL injection vulnerability in search.php in Pligg CMS 1.1.2 allows remote attackers to execute arbitrary SQL commands via the status parameter.</description>
      <pubDate>Thu, 29 Dec 2011 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5022</guid>
      <dc:date>2011-12-29T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-3835</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3835</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in Wuzly 2.0 allow remote attackers to inject arbitrary web script or HTML via the Referer header to (1) admin/login.php and (2) admin/404.php; the (3) q parameter to search.php; the (4) theme_name parameter to theme_settings.php, (5) extension_name parameter to extension_settings.php, (6) q parameter to search.php, (7) type parameter to comments.php, sort parameter to (8) pages.php and (9) posts.php, and the (10) type and (11) q parameter t...</description>
      <pubDate>Sat, 24 Dec 2011 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3835</guid>
      <dc:date>2011-12-24T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-3838</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3838</link>
      <description>Multiple SQL injection vulnerabilities in Wuzly 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) u parameter to fp.php, (2) epage parameter to newpage.php, (3) epost parameter to newpost.php, and (4) username parameter to login.php in admin/; or the (5) username parameter to mobile/login.php.</description>
      <pubDate>Sat, 24 Dec 2011 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3838</guid>
      <dc:date>2011-12-24T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-3837</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3837</link>
      <description>Directory traversal vulnerability in blog_system/data_functions.php in Wuzly 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the preview parameter to index.php.</description>
      <pubDate>Sat, 24 Dec 2011 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3837</guid>
      <dc:date>2011-12-24T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Bugtraq: Tiki Wiki CMS Groupware &lt;= 8.2 (snarf_ajax.php) Remote PHP Code Injection</title>
      <link>http://www.securityfocus.com/archive/1/521009</link>
      <description>Tiki Wiki CMS Groupware &amp;lt;= 8.2 (snarf_ajax.php) Remote PHP Code Injection</description>
      <pubDate>Fri, 23 Dec 2011 23:10:06 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/521009</guid>
      <dc:date>2011-12-23T23:10:06Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4453 (pmwiki)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4453</link>
      <description>The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequences in a crafted order parameter in a pagelist directive, leading to unintended use of the PHP create_function function.</description>
      <pubDate>Thu, 22 Dec 2011 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4453</guid>
      <dc:date>2011-12-22T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4753 (parallels_plesk_small_business_panel)</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4753</link>
      <description>Multiple SQL injection vulnerabilities in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by domains/sitebuilder_edit.php and certain other files.</description>
      <pubDate>Fri, 16 Dec 2011 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4753</guid>
      <dc:date>2011-12-16T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Bugtraq: [ MDVSA-2011:187 ] php-pear</title>
      <link>http://www.securityfocus.com/archive/1/520887</link>
      <description>[ MDVSA-2011:187 ] php-pear</description>
      <pubDate>Thu, 15 Dec 2011 22:38:28 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/520887</guid>
      <dc:date>2011-12-15T22:38:28Z</dc:date>
    </item>
    <item>
      <title>Bugtraq: PHP-SCMS 1.6.8 "lang" parameter XSS vulnerability</title>
      <link>http://www.securityfocus.com/archive/1/520877</link>
      <description>PHP-SCMS 1.6.8 &amp;quot;lang&amp;quot; parameter XSS vulnerability</description>
      <pubDate>Wed, 14 Dec 2011 22:53:53 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/520877</guid>
      <dc:date>2011-12-14T22:53:53Z</dc:date>
    </item>
    <item>
      <title>Facebook Looks to Fix PHP performance with HipHop Virtual Machine</title>
      <link>http://osnews.com/story/25426/Facebook_Looks_to_Fix_PHP_performance_with_HipHop_Virtual_Machine</link>
      <description>PHP's popularity and simplicity made it easy for the company's developers to quickly build new features. But PHP's (lack of) performance makes scaling Facebook's site to handle hundreds of billions of page views a month problematic, so Facebook has made big investments in making it leaner and faster. The latest product of those efforts is the HipHop VM (HHVM), a PHP virtual machine that significantly boosts performance of dynamic pages . And Facebook is sharing it with the world as open-source.</description>
      <pubDate>Wed, 14 Dec 2011 16:01:35 GMT</pubDate>
      <guid>http://osnews.com/story/25426/Facebook_Looks_to_Fix_PHP_performance_with_HipHop_Virtual_Machine</guid>
      <dc:date>2011-12-14T16:01:35Z</dc:date>
    </item>
    <item>
      <title>Four short links: 14 December 2011</title>
      <link>http://feedproxy.google.com/~r/oreilly/radar/atom/~3/SU1EAI98NwM/four-short-links-14-december-2-2.html</link>
      <description>The HipHop Virtual Machine (Facebook) -- inside the new virtual machine for PHP from Facebook. PHP Fog's Free Thinkup Hosting (Expert Labs) -- ThinkUp archives your tweets and other social media activity for you to search, visualize, and analyze. PHPFog hosts PHP apps scalably, and I'm delighted to be an advisor. Andy's made a video showing how to get...</description>
      <pubDate>Wed, 14 Dec 2011 11:00:00 GMT</pubDate>
      <guid>http://feedproxy.google.com/~r/oreilly/radar/atom/~3/SU1EAI98NwM/four-short-links-14-december-2-2.html</guid>
      <dc:date>2011-12-14T11:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: PHP 'exif_process_IFD_TAG()' Remote Integer Overflow Vulnerability</title>
      <link>http://www.securityfocus.com/bid/50907</link>
      <description>PHP 'exif_process_IFD_TAG()' Remote Integer Overflow Vulnerability</description>
      <pubDate>Wed, 14 Dec 2011 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/50907</guid>
      <dc:date>2011-12-14T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4827</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4827</link>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in AutoSec Tools V-CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) p parameter to redirect.php and (2) box parameter to includes/TrueColorPicker/index.php, which is not properly handled in includes/TrueColorPicker/class.TrueColorPicker.php.</description>
      <pubDate>Wed, 14 Dec 2011 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4827</guid>
      <dc:date>2011-12-14T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4825</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4825</link>
      <description>Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.</description>
      <pubDate>Wed, 14 Dec 2011 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4825</guid>
      <dc:date>2011-12-14T00:00:00Z</dc:date>
    </item>
  </channel>
</rss>


