<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title>IT Security Solutions</title>
<link>http://www.itsecuritysolutions.org/</link>
<description>IT security tools and research.</description>
<language>en-us</language>
<pubDate>Sat, 25 May 2013 11:58:34 GMT</pubDate>
<generator>IT Security Solutions</generator>
<item>
<title>Scrollout arbitrary command execution vulnerability</title>
<link>http://www.itsecuritysolutions.org/2013-01-29-Scrollout-arbitrary-command-execution-vulnerability/</link>
<description><p>Scrollout version 2012-10-03 allows authenticated remote attackers to execute arbitrary commands as the 'www-data' user.</p></description>
<pubDate>Tue, 29 Jan 2013 14:26:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2013-01-29-Scrollout-arbitrary-command-execution-vulnerability/</guid>
</item>
<item>
<title>ZoneMinder Video Server arbitrary command execution vulnerability</title>
<link>http://www.itsecuritysolutions.org/2013-01-22-ZoneMinder-Video-Server-arbitrary-command-execution-vulnerability/</link>
<description><p>ZoneMinder Video Server version 1.24.0 to 1.25.0 allows authenticated remote attackers to execute arbitrary commands as the web server user.</p></description>
<pubDate>Tue, 22 Jan 2013 23:59:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2013-01-22-ZoneMinder-Video-Server-arbitrary-command-execution-vulnerability/</guid>
</item>
<item>
<title>eXtplorer v2.1 authentication bypass vulnerability</title>
<link>http://www.itsecuritysolutions.org/2012-12-31-eXtplorer-v2.1-authentication-bypass-vulnerability/</link>
<description><p>eXtplorer versions 2.1.2, 2.1.1, 2.1.0 and 2.1.0RC5 allow an unauthenticated user to bypass authentication and execute arbitrary files as the webserver user.</p></description>
<pubDate>Mon, 31 Dec 2012 01:09:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2012-12-31-eXtplorer-v2.1-authentication-bypass-vulnerability/</guid>
</item>
<item>
<title>ZEN Load Balancer v2.0 and v3.0-rc1 multiple vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2012-09-21-ZEN-Load-Balancer-v2.0-and-v3.0-rc1-multiple-vulnerabilities</link>
<description><p>ZEN Load Balancer v2.0 and v3.0-rc1 allows authenticated remote attackers to execute arbitrary commands as the 'root' user.</p></description>
<pubDate>Fri, 21 Sep 2012 21:16:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2012-09-21-ZEN-Load-Balancer-v2.0-and-v3.0-rc1-multiple-vulnerabilities</guid>
</item>
<item>
<title>Openfiler v2.x multiple vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2012-09-06-Openfiler-v2.x-multiple-vulnerabilities/</link>
<description><p>Openfiler v2.x allows authenticated remote attackers to gain root access.</p></description>
<pubDate>Thu, 06 Sep 2012 21:16:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2012-09-06-Openfiler-v2.x-multiple-vulnerabilities/</guid>
</item>
<item>
<title>SugarCRM Community Edition 6.5.2 (Build 8410) multiple vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2012-08-30-SugarCRM-Community-Edition-6.5.2-multiple-vulnerabilities/</link>
<description><p>There are multiple security vulnerabilities in SugarCRM Community Edition 6.5.2 (Build 8410) which may allow an attacker to take control of the software.</p></description>
<pubDate>Thu, 30 Aug 2012 18:11:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2012-08-30-SugarCRM-Community-Edition-6.5.2-multiple-vulnerabilities/</guid>
</item>
<item>
<title>TestLink 1.9.3 multiple vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2012-08-13-TestLink-1.9.3-multiple-vulnerabilities/</link>
<description><p>There are multiple security vulnerabilities in TestLink 1.9.3 which may allow an unauthenticated user to execute arbitrary commands as the web server user.</p></description>
<pubDate>Mon, 13 Aug 2012 17:42:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2012-08-13-TestLink-1.9.3-multiple-vulnerabilities/</guid>
</item>
<item>
<title>WANem v2.3 multiple vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2012-08-12-WANem-v2.3-multiple-vulnerabilities/</link>
<description><p>WANem v2.3 allows unauthenticated remote attackers to gain root access.</p></description>
<pubDate>Sun, 12 Aug 2012 14:02:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2012-08-12-WANem-v2.3-multiple-vulnerabilities/</guid>
</item>
<item>
<title>QLogic SANsurfer FC HBA Manager 5.0.1 build 31 Directory Traversal vulnerability</title>
<link>http://www.itsecuritysolutions.org/2012-08-05-qlogic-sansurfer-fc-hba-manager-5.0.1-build-31-directory-traversal-vulnerability/</link>
<description><p>QLogic SANsurfer Fibre Channel (FC) Host Bus Adapter (HBA) Manager uses Fizmez 
Web Server for the web server component. Fizmez Web Server is vulnerable to 
directory traversal. The web server is not enabled by default.</p></description>
<pubDate>Sun, 05 Aug 2012 23:34:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2012-08-05-qlogic-sansurfer-fc-hba-manager-5.0.1-build-31-directory-traversal-vulnerability/</guid>
</item>
<item>
<title>Fizmez Web Server &amp;lt;= 1.3 Directory Traversal vulnerability</title>
<link>http://www.itsecuritysolutions.org/2012-08-05-fizmez-web-server-1.3-directory-traversal-vulnerability/</link>
<description><p>Fizmez Web Server is vulnerable to directory traversal.</p></description>
<pubDate>Sun, 05 Aug 2012 23:34:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2012-08-05-fizmez-web-server-1.3-directory-traversal-vulnerability/</guid>
</item>
<item>
<title>Zenoss 3.2.1 multiple security vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2012-07-30-zenoss-3.2.1-multiple-security-vulnerabilities/</link>
<description><p>There are multiple security vulnerabilities in Zenoss &amp;lt;= 3.2.1 which may allow an attacker to take control of the software.</p></description>
<pubDate>Mon, 30 Jul 2012 02:42:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2012-07-30-zenoss-3.2.1-multiple-security-vulnerabilities/</guid>
</item>
<item>
<title>CuteFlow 2.11.2 multiple security vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2012-07-01-CuteFlow-2.11.2-multiple-security-vulnerabilities/</link>
<description><p>There are multiple security vulnerabilities in CuteFlow 2.11.2 which may allow an attacker to take control of the software.</p></description>
<pubDate>Sun, 01 Jul 2012 22:19:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2012-07-01-CuteFlow-2.11.2-multiple-security-vulnerabilities/</guid>
</item>
<item>
<title>ActiveX, Remote DoS and XSS</title>
<link>http://www.itsecuritysolutions.org/2012-04-13-ActiveX,-Remote-DoS-and-XSS/</link>
<description><p>ActiveX, Remote DoS and XSS - because I've been busy and couldn't think of a better title for this post.</p></description>
<pubDate>Fri, 13 Apr 2012 11:23:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2012-04-13-ActiveX,-Remote-DoS-and-XSS/</guid>
</item>
<item>
<title>Privilege escalation and remote inter-protocol exploitation with EXTRACT 0.5.1</title>
<link>http://www.itsecuritysolutions.org/2011-12-16-Privilege-escalation-and-remote-inter-protocol-exploitation-with-EXTRACT-0.5.1/</link>
<description><p>Howdy folks. Today I'll be introducing you to the EXTRAnet Collaboration Tool (EXTRACT) 0.5.1. We'll explore leveraging EXTRACT to escalate privileges with a 0day bug. I'll also show you how you can enjoy some remote shell goodness thanks to inter-protocol exploitation (with some luck and a little user interaction).</p></description>
<pubDate>Fri, 16 Dec 2011 01:37:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2011-12-16-Privilege-escalation-and-remote-inter-protocol-exploitation-with-EXTRACT-0.5.1/</guid>
</item>
<item>
<title>Abusing browser news URL handlers</title>
<link>http://www.itsecuritysolutions.org/2011-09-18-Abusing-browser-news-URL-handlers/</link>
<description><p>Time for some more fun with browser URL handlers! This time we'll take a look into abusing the handlers for news/snews/nntp.</p></description>
<pubDate>Sun, 18 Sep 2011 11:00:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2011-09-18-Abusing-browser-news-URL-handlers/</guid>
</item>
<item>
<title>ActivDesk 3.0 multiple security vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2011-06-24-ActivDesk-3.0-multiple-security-vulnerabilities/</link>
<description><p>There are multiple security vulnerabilities in ActivDesk 3.0 which may allow an attacker to take control of the software.</p></description>
<pubDate>Fri, 24 Jun 2011 03:00:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2011-06-24-ActivDesk-3.0-multiple-security-vulnerabilities/</guid>
</item>
<item>
<title>iSupport 1.8 SQL Injection Vulnerability</title>
<link>http://www.itsecuritysolutions.org/2011-06-23-iSupport-1.8-SQL-Injection-Vulnerability/</link>
<description><p>There is a SQL Injection vulnerability in iSupport 1.8 which may allow an attacker to take control of the software.</p></description>
<pubDate>Thu, 23 Jun 2011 15:50:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2011-06-23-iSupport-1.8-SQL-Injection-Vulnerability/</guid>
</item>
<item>
<title>BrewBlogger 2.3.2 multiple security vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2011-06-23_BrewBlogger_2.3.2_multiple_security_vulnerabilities/</link>
<description><p>There are multiple security vulnerabilities in BrewBlogger 2.3.2 which may allow an attacker to take control of the software.</p></description>
<pubDate>Thu, 23 Jun 2011 09:30:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2011-06-23_BrewBlogger_2.3.2_multiple_security_vulnerabilities/</guid>
</item>
<item>
<title>iGiveTest 2.1.0 SQL Injection Vulnerability</title>
<link>http://www.itsecuritysolutions.org/2011-06-22-iGiveTest-2.1.0-SQL-Injection-Vulnerability/</link>
<description><p>There is an SQL Injection vulnerability in iGiveTest 2.1.0 which may allow an attacker to take control of the software.</p></description>
<pubDate>Wed, 22 Jun 2011 03:50:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2011-06-22-iGiveTest-2.1.0-SQL-Injection-Vulnerability/</guid>
</item>
<item>
<title>Bitcoin - fun, profit and anonymity on the wire - part 1</title>
<link>http://www.itsecuritysolutions.org/2011-05-20-Bitcoin-fun-profit-and-anonymity-on-the-wire-part-1/</link>
<description><p>Bitcoin - fun, profit and anonymity on the wire. A brief analysis of the BitCoin network.</p></description>
<pubDate>Fri, 20 May 2011 20:48:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2011-05-20-Bitcoin-fun-profit-and-anonymity-on-the-wire-part-1/</guid>
</item>
<item>
<title>DoceboLMS 4.0.4 multiple security vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2011-03-27_DoceboLMS_4.0.4_multiple_security_vulnerabilities/</link>
<description><p>There is a reflected Cross Site Scripting (XSS) vulnerability in DoceboLMS 4.0.4 which may allow an attacker to take control of the software. There are also numerous Full Path Disclosure vulnerabilities. Previous versions may also be affected.</p></description>
<pubDate>Sun, 27 Mar 2011 19:15:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2011-03-27_DoceboLMS_4.0.4_multiple_security_vulnerabilities/</guid>
</item>
<item>
<title>PHP Event Calendar 1.4 multiple vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2011-03-24_PHP_Event_Calendar_1.4_multiple_vulnerabilities/</link>
<description><p>There are multiple Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerabilities in PHP Event Calendar 1.4 which may allow an attacker to take control of the software if a user with admin privileges browses a malicious page while authorized.</p></description>
<pubDate>Thu, 24 Mar 2011 17:50:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2011-03-24_PHP_Event_Calendar_1.4_multiple_vulnerabilities/</guid>
</item>
<item>
<title>Cachelogic Expired Domains Script 1.0 multiple security vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2011-03-24_Cachelogic_Expired_Domains_Script_1.0_multiple_security_vulnerabilities/</link>
<description><p>There are multiple security vulnerabilities in Cachelogic Expired Domains Script 1.0 which may allow a remote attacker to take control of the software.</p></description>
<pubDate>Thu, 24 Mar 2011 17:18:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2011-03-24_Cachelogic_Expired_Domains_Script_1.0_multiple_security_vulnerabilities/</guid>
</item>
<item>
<title>KSearch 1.5b multiple Cross-Site Scripting Vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2011-03-20_KSearch_1.5b_multiple_Cross-Site_Scripting_Vulnerabilities/</link>
<description><p>There are two reflected Cross Site Scripting (XSS) vulnerabilities in KSearch 1.5b. Prior versions are presumably affected however only version 1.4 has been tested.</p></description>
<pubDate>Sun, 20 Mar 2011 22:50:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2011-03-20_KSearch_1.5b_multiple_Cross-Site_Scripting_Vulnerabilities/</guid>
</item>
<item>
<title>rightscripts.com PHP Website Content Monitor Persistent Cross-Site Scripting (XSS) Vulnerability</title>
<link>http://www.itsecuritysolutions.org/2010-12-27_rightscripts.com_PHP_website_content_monitor_Persistent_Cross-Site_Scripting_Vulnerability/</link>
<description><p>There is a Persistent Cross-Site Scripting (XSS) vulnerability in rightscripts.com PHP Website Content Monitor which may allow an attacker to take control of the software.</p></description>
<pubDate>Mon, 27 Dec 2010 07:00:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2010-12-27_rightscripts.com_PHP_website_content_monitor_Persistent_Cross-Site_Scripting_Vulnerability/</guid>
</item>
<item>
<title>rightscripts.com Extract Website Script Local File Inclusion Vulnerability</title>
<link>http://www.itsecuritysolutions.org/2010-12-27_rightscripts.com_Extract_Website_Script_Local_File_Inclusion_Vulnerability/</link>
<description><p>There is a Local File Inclusion (LFI) vulnerability in rightscripts.com Extract Website Script which may allow an attacker to take control of the web-server.</p></description>
<pubDate>Mon, 27 Dec 2010 07:00:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2010-12-27_rightscripts.com_Extract_Website_Script_Local_File_Inclusion_Vulnerability/</guid>
</item>
<item>
<title>rToTalMaTch 1.2a Cross-Site Scripting (XSS) vulnerability</title>
<link>http://www.itsecuritysolutions.org/2010-12-27_rToTalMaTch_1.2a_Cross-Site_Scripting_vulnerability/</link>
<description><p>There is a Cross-Site Scripting (XSS) vulnerability in ToTalMaTch 1.2a which may allow an unauthorized user to take control of the software if an authenticated user browses a malicious page.</p></description>
<pubDate>Mon, 27 Dec 2010 07:00:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2010-12-27_rToTalMaTch_1.2a_Cross-Site_Scripting_vulnerability/</guid>
</item>
<item>
<title>InDoors Software InDoorsLogger 7.7 multiple security vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2010-12-27_InDoors_Software_InDoorsLogger_7.7_multiple_security_vulnerabilities/</link>
<description><p>There are multiple security vulnerabilities in InDoorsLogger (IDLogger) version 7.7 which may allow an attacker to take control of the software.</p></description>
<pubDate>Mon, 27 Dec 2010 07:00:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2010-12-27_InDoors_Software_InDoorsLogger_7.7_multiple_security_vulnerabilities/</guid>
</item>
<item>
<title>phpRechnung 1.6 RC2 multiple security vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2010-12-17_phpRechnung_1.6_RC2_multiple_security_vulnerabilities/</link>
<description><p>There are multiple security vulnerabilities in phpRechnung 1.6 RC2 which allow an unauthorized user to take control of the software.</p></description>
<pubDate>Fri, 17 Dec 2010 11:55:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2010-12-17_phpRechnung_1.6_RC2_multiple_security_vulnerabilities/</guid>
</item>
<item>
<title>thERP multiple security vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2010-11-23_thERP_multiple_security_vulnerabilities/</link>
<description><p>There are multiple security vulnerabilities in thERP which allow an unauthorized user to take control of the software.</p></description>
<pubDate>Tue, 23 Nov 2010 03:20:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2010-11-23_thERP_multiple_security_vulnerabilities/</guid>
</item>
<item>
<title>newswall 1.05 multiple security vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2010-11-22_newswall_1.05_multiple_security_vulnerabilities/</link>
<description><p>There are multiple security vulnerabilities in newswall which may allow an attacker to compromise the web server.</p></description>
<pubDate>Mon, 22 Nov 2010 17:20:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2010-11-22_newswall_1.05_multiple_security_vulnerabilities/</guid>
</item>
<item>
<title>CodeCharge Studio 4.3 scripts Cross-Site Request Forgery vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2010-11-22_CodeCharge_Studio_4.3_scripts_Cross-Site_Request_Forgery_vulnerabilities/</link>
<description><p>All scripts generated by CodeCharge Studio 4.3 contain Cross-Site Request Forgery (CSRF) vulnerabilities which may allow an attacker to take control of the software if an authorized user browses a malicious page while authorized.</p></description>
<pubDate>Mon, 22 Nov 2010 04:25:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2010-11-22_CodeCharge_Studio_4.3_scripts_Cross-Site_Request_Forgery_vulnerabilities/</guid>
</item>
<item>
<title>MonoQL 0.1a multiple security vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2010-11-22_MonoQL_0.1a_multiple_security_vulnerabilities/</link>
<description><p>There are multiple security vulnerabilities in MonoQL 0.1a which may allow an attacker to take control of the software.</p></description>
<pubDate>Mon, 22 Nov 2010 03:00:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2010-11-22_MonoQL_0.1a_multiple_security_vulnerabilities/</guid>
</item>
<item>
<title>Dolibarr ERP CRM 3.0.0-alpha multiple security vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2010-11-21_Dolibarr_ERP_CRM_3.0.0-alpha_multiple_security_vulnerabilities/</link>
<description><p>There are multiple security vulnerabilities in Dolibarr ERP CRM 3.0.0-alpha which may allow an attacker to take control of the software.</p></description>
<pubDate>Sun, 21 Nov 2010 21:00:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2010-11-21_Dolibarr_ERP_CRM_3.0.0-alpha_multiple_security_vulnerabilities/</guid>
</item>
<item>
<title>SmartCJ Pro 1.45 multiple security vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2010-11-17_SmartCJ_Pro_1.45_multiple_security_vulnerabilities/</link>
<description><p>There are multiple security vulnerabilities in SmartCJ Pro 1.45 which may allow an attacker to take control of the software if an authorized user browses a malicious page while authenticated.</p></description>
<pubDate>Wed, 17 Nov 2010 00:10:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2010-11-17_SmartCJ_Pro_1.45_multiple_security_vulnerabilities/</guid>
</item>
<item>
<title>SocketTimesheet 3.0 multiple Cross-Site Scripting vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2010-11-15_SocketTimesheet_3.0_multiple_Cross-Site_Scripting_vulnerabilities/</link>
<description><p>There are multiple Cross-Site Scripting vulnerabilities in SocketTimesheet 3.0 which may allow an attacker to take control of the software if an authenticated user browses a malicious page.</p></description>
<pubDate>Mon, 15 Nov 2010 16:20:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2010-11-15_SocketTimesheet_3.0_multiple_Cross-Site_Scripting_vulnerabilities/</guid>
</item>
<item>
<title>Webmedia Explorer 6.13.2 multiple security vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2010-11-13_Webmedia_Explorer_6.13.2_multiple_security_vulnerabilities/</link>
<description><p>There are multiple Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerabilities in Webmedia Explorer 6.13.2 which may allow an attacker to take control of the software if a user with admin privileges browses a malicious page.</p></description>
<pubDate>Sat, 13 Nov 2010 20:30:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2010-11-13_Webmedia_Explorer_6.13.2_multiple_security_vulnerabilities/</guid>
</item>
<item>
<title>Truworth PHP Invoice Software 2.1 multiple vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2010-11-13_Truworth_PHP_Invoice_Software_2.1_multiple_vulnerabilities/</link>
<description><p>There are multiple security vulnerabilities in Truworth PHP Invoice Software 2.1 which allow an attacker to remotely compromise the software.</p></description>
<pubDate>Sat, 13 Nov 2010 20:20:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2010-11-13_Truworth_PHP_Invoice_Software_2.1_multiple_vulnerabilities/</guid>
</item>
<item>
<title>Truworth Online Time Sheet 2.1 Authentication Bypass vulnerability</title>
<link>http://www.itsecuritysolutions.org/2010-11-13_Truworth_Online_Time_Sheet_2.1_Authentication_Bypass_vulnerability/</link>
<description><p>There is an authentication bypass vulnerability in Truworth Online Time Sheet 2.1 due to the application failing to properly sanitize user-supplied input during authentication. Exploitation of this vulnerability would permit unauthorized access with admin privilages.</p></description>
<pubDate>Sat, 13 Nov 2010 20:20:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2010-11-13_Truworth_Online_Time_Sheet_2.1_Authentication_Bypass_vulnerability/</guid>
</item>
<item>
<title>QNAP TS-239 Firmware 3.3.1 Build 0720T - multiple vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2010-08-04_QNAP_TS-239_firmware_3.3.1_build_0720T_multiple_vulnerabilities/</link>
<description><p>Multiple security vulnerabilities exist in the QNAP TS-239 Pro network attached storage device which could allow an attacker to take control of the device if a user with administrator privileges browses a malicious web page.</p></description>
<pubDate>Wed, 04 Aug 2010 17:42:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2010-08-04_QNAP_TS-239_firmware_3.3.1_build_0720T_multiple_vulnerabilities/</guid>
</item>
<item>
<title>Fingerprinting Browsers Using Protocol Handlers</title>
<link>http://www.itsecuritysolutions.org/2010-03-29_fingerprinting_browsers_using_protocol_handlers/</link>
<description><p>If a user is masking their user-agent in Internet Explorer or Mozilla Firefox it is still possible to identify their browser and operating system using protocols which are unique to the browser.</p></description>
<pubDate>Mon, 29 Mar 2010 23:53:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2010-03-29_fingerprinting_browsers_using_protocol_handlers/</guid>
</item>
<item>
<title>Wordpress 2.7.1 multiple minor vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2009-05-07_wordpress_2.7.1_multiple_minor_vulnerabilities/</link>
<description><p>Multiple vulnerabilities exist in the Wordpress 2.7.1 blogging software however successful exploitation requires admin roles.</p></description>
<pubDate>Thu, 07 May 2009 02:09:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2009-05-07_wordpress_2.7.1_multiple_minor_vulnerabilities/</guid>
</item>
<item>
<title>Belkin Broadband Voice Modem/Router - wireless 4 port - F1PI242EGau multiple vulnerabilities</title>
<link>http://www.itsecuritysolutions.org/2009-05-04_belkin_wireless_F1PI242EGau_iinet_multiple_vulnerabilities/</link>
<description><p>Multiple vulnerabilities exist in the Belkin F1PI242EGau (wireless 4 port) router distributed by Australian ISP iiNet which could allow an attacker complete control over the user's router if the user browses a malicious web page. CSRF and XSS issues in the web administration interface lead to denial of service, information disclosure and DNS Hijacking.</p></description>
<pubDate>Mon, 04 May 2009 01:57:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2009-05-04_belkin_wireless_F1PI242EGau_iinet_multiple_vulnerabilities/</guid>
</item>
<item>
<title>Escalating Wordpress 2.6 search XSS to arbitrary file upload</title>
<link>http://www.itsecuritysolutions.org/2008-08-27_escalating_wordpress_2.6_search_xss_to_arbitrary_file_upload/</link>
<description><p>Escalating Wordpress 2.6 search XSS to Arbitrary File Upload</p></description>
<pubDate>Wed, 27 Aug 2008 00:00:00 GMT</pubDate>
<guid>http://www.itsecuritysolutions.org/2008-08-27_escalating_wordpress_2.6_search_xss_to_arbitrary_file_upload/</guid>
</item>
</channel>
</rss>