<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Recognize-Security &#187; Advisories</title>
	<atom:link href="http://www.rec-sec.com/category/advisories/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rec-sec.com</link>
	<description>a non-profit information security web site authored by Moshe Ben Abu (Trancer), focusing on vulnerability research, exploit development (mainly for the Metasploit Framework), web application security, information security and hacking news from around the world.</description>
	<lastBuildDate>Sun, 14 Mar 2010 17:44:35 +0000</lastBuildDate>
	<generator>http://www.rec-sec.com</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='www.rec-sec.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com" />
	<atom:link rel="hub" href="http://superfeedr.com/hubbub" />
			<item>
		<title>cPanel HTTP Response Splitting Vulnerability</title>
		<link>http://www.rec-sec.com/2010/01/21/cpanel-http-response-splitting-vulnerability/</link>
		<comments>http://www.rec-sec.com/2010/01/21/cpanel-http-response-splitting-vulnerability/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 05:28:10 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Advisories]]></category>

		<guid isPermaLink="false">http://www.rec-sec.com/?p=892</guid>
		<description><![CDATA[Security Advisory for cPanel and WHM (WebHost Manager) versions 11.25.
Vulnerabilities found:

HTTP Response Splitting vulnerability
Open Redirection vulnerability

 cPanel HTTP Response Splitting Vulnerability &#8211; Security Advisory (PDF).
 cPanel HTTP Response Splitting Vulnerability &#8211; Security Advisory (TXT).
I&#8217;d like to point out the lame work of the cPanel Security Team on these vulnerabilities. Usually when I report a vulnerability, [...]]]></description>
			<content:encoded><![CDATA[<p><img alt="cPanel" width="125" height="66" class="right" src="images/cpanel.png" />Security Advisory for cPanel and WHM (WebHost Manager) versions 11.25.<br />
Vulnerabilities found:</p>
<ul>
<li><abbr title="Hypertext Transfer Protocol">HTTP</abbr> Response Splitting vulnerability</li>
<li>Open Redirection vulnerability</li>
</ul>
<p><img alt="PDF Format" width="16" height="18" src="images/format_pdf_small.png" /> <a href="advisories/cpanel_http_response_splitting_vulnerability.pdf" title="cPanel HTTP Response Splitting Vulnerability - Security Advisory (PDF)">cPanel HTTP Response Splitting Vulnerability &#8211; Security Advisory (<abbr title="Portable Document Format">PDF</abbr>)</a>.<br />
<img alt="TXT Format" width="16" height="18" src="images/format_text_small.png" /> <a href="advisories/cpanel_http_response_splitting_vulnerability.txt" title="cPanel HTTP Response Splitting Vulnerability - Security Advisory (TXT)">cPanel HTTP Response Splitting Vulnerability &#8211; Security Advisory (TXT)</a>.</p>
<p>I&#8217;d like to point out the lame work of the cPanel Security Team on these vulnerabilities. Usually when I report a vulnerability, I get some kind of interaction with the vendor developers and/or the security team, most of the times I enjoy working with the people involved. In this case, the cPanel Security Team were unresponsive. Eventually I was forced to release the security advisory even though one of the vulnerabilities (the Open Redirection vulnerability) is still unpatched.</p>
<p>References:<br />
<a href="http://www.securityfocus.com/bid/37902" title="cPanel and WHM 'failurl' Parameter HTTP Response Splitting Vulnerability"><abbr title="Bugtraq ID">BID</abbr> 37902</a><br />
<a href="http://osvdb.org/show/osvdb/61954" title="61954: cPanel login/index.php failurl Parameter HTTP Response Splitting"><abbr title="Open Source Vulnerability Database">OSVDB</abbr> 61954</a><br />
<a href="http://www.exploit-db.com/exploits/11211" title="cPanel HTTP Response Splitting Vulnerability">exploit-db 11211</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2010/01/21/cpanel-http-response-splitting-vulnerability/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Caucho Resin UTF-7 Cross-Site Scripting Vulnerability</title>
		<link>http://www.rec-sec.com/2008/10/05/caucho-resin-utf-7-cross-site-scripting-vulnerability/</link>
		<comments>http://www.rec-sec.com/2008/10/05/caucho-resin-utf-7-cross-site-scripting-vulnerability/#comments</comments>
		<pubDate>Sun, 05 Oct 2008 17:11:13 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Advisories]]></category>

		<guid isPermaLink="false">http://www.rec-sec.com/?p=49</guid>
		<description><![CDATA[Security Advisory for Caucho Resin Application Server version 3.2 and below.
Vulnerabilities found:

UTF-7 Cross-Site Scripting

 PDF version.
 TXT version.
This actually mean that every web application hosted on a Caucho Resin application server is vulnerable to Cross-Site Scripting&#8230; If you have one, I seriously recommend you patch your server :-)
References:
Caucho Resin 3.2.1 Release Notes
Caucho bug ID 2965
]]></description>
			<content:encoded><![CDATA[<p><img alt="Caucho" width="100" height="42" class="right" src="images/caucho_logo.png" />Security Advisory for Caucho Resin Application Server version 3.2 and below.<br />
Vulnerabilities found:</p>
<ul>
<li><abbr title="7-bit Unicode Transformation Format">UTF-7</abbr> Cross-Site Scripting</li>
</ul>
<p><img alt="PDF Format" width="16" height="18" src="images/format_pdf_small.png" /> <a href="advisories/Resin_UTF-7_XSS_Vulnerability.pdf" title="Caucho Resin UTF-7 Cross-Site Scripting Vulnerability - PDF version"><abbr title="Portable Document Format">PDF</abbr> version</a>.<br />
<img alt="TXT Format" width="16" height="18" src="images/format_text_small.png" /> <a href="advisories/Resin_UTF-7_XSS_Vulnerability.txt" title="Caucho Resin UTF-7 Cross-Site Scripting Vulnerability - TXT version">TXT version</a>.</p>
<p>This actually mean that every web application hosted on a Caucho Resin application server is vulnerable to Cross-Site Scripting&#8230; If you have one, I seriously recommend you patch your server :-)</p>
<p>References:<br />
<a href="http://www.caucho.com/resin/changes/resin-3.2.1.xtp" title="Caucho Resin 3.2.1 Release Notes">Caucho Resin 3.2.1 Release Notes</a><br />
<a href="http://bugs.caucho.com/view.php?id=2965" title="Caucho bug ID 2965">Caucho bug ID 2965</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2008/10/05/caucho-resin-utf-7-cross-site-scripting-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenNMS Multiple Vulnerabilities</title>
		<link>http://www.rec-sec.com/2008/10/05/opennms-multiple-vulnerabilities/</link>
		<comments>http://www.rec-sec.com/2008/10/05/opennms-multiple-vulnerabilities/#comments</comments>
		<pubDate>Sun, 05 Oct 2008 14:02:21 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Advisories]]></category>

		<guid isPermaLink="false">http://www.rec-sec.com/?p=47</guid>
		<description><![CDATA[Security Advisory for OpenNMS version 1.5.93-1 and below.
Vulnerabilities found:

HTTP Response Splitting
Cross-Site Scripting

 PDF version.
 TXT version.
Also on:
BID 31577
milw0rm
]]></description>
			<content:encoded><![CDATA[<p><img alt="OpenNMS" width="135" height="42" class="right" src="images/opennms_logo.png" />Security Advisory for OpenNMS version 1.5.93-1 and below.<br />
Vulnerabilities found:</p>
<ul>
<li><abbr title="Hypertext Transfer Protocol">HTTP</abbr> Response Splitting</li>
<li>Cross-Site Scripting</li>
</ul>
<p><img alt="PDF Format" width="16" height="18" src="images/format_pdf_small.png" /> <a href="advisories/OpenNMS_Multiple_Vulnerabilities.pdf" title="OpenNMS Multiple Vulnerabilities Security Advisory - PDF version"><abbr title="Portable Document Format">PDF</abbr> version</a>.<br />
<img alt="TXT Format" width="16" height="18" src="images/format_text_small.png" /> <a href="advisories/OpenNMS_Multiple_Vulnerabilities.txt" title="OpenNMS Multiple Vulnerabilities Security Advisory - TXT version">TXT version</a>.</p>
<p>Also on:<br />
<a href="http://www.securityfocus.com/bid/31577" title="OpenNMS HTTP Response Splitting Vulnerability"><abbr title="Bugtraq ID">BID</abbr> 31577</a><br />
<a href="http://www.milw0rm.com/exploits/6676" title="OpenNMS &lt; 1.5.96 Multiple Remote Vulnerabilities">milw0rm</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2008/10/05/opennms-multiple-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>JSPWiki Multiple Vulnerabilities</title>
		<link>http://www.rec-sec.com/2008/01/15/jspwiki-multiple-vulnerabilities/</link>
		<comments>http://www.rec-sec.com/2008/01/15/jspwiki-multiple-vulnerabilities/#comments</comments>
		<pubDate>Tue, 15 Jan 2008 19:54:32 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Advisories]]></category>

		<guid isPermaLink="false">http://www.rec-sec.com/?p=51</guid>
		<description><![CDATA[Security Advisory for JSPWiki versions 2.4.104 (latest stable release), 2.5.139 (latest beta version) and below.
Vulnerabilities found:

.jsp Local File Inclusion
Cross-Site Scripting

JSPWiki allow users to upload (attach) files to entry pages. Combined with the LFI vulnerability, an attacker can use the information disclosed by the installation file to upload a malicious .jsp file and locally execute it.
By [...]]]></description>
			<content:encoded><![CDATA[<p><img alt="JSPWiki" width="64" height="64" class="right" src="images/jspwiki_logo.png" />Security Advisory for JSPWiki versions 2.4.104 (latest stable release), 2.5.139 (latest beta version) and below.<br />
Vulnerabilities found:</p>
<ul>
<li>.<abbr title="JavaServer Pages">jsp</abbr> Local File Inclusion</li>
<li>Cross-Site Scripting</li>
</ul>
<p>JSPWiki allow users to upload (attach) files to entry pages. Combined with the <abbr title="Local File Inclusion">LFI</abbr> vulnerability, an attacker can use the information disclosed by the installation file to upload a malicious .<abbr title="JavaServer Pages">jsp</abbr> file and locally execute it.<br />
By executing malicious server-side code, an attacker may be able to compromise the server.</p>
<p>Actually, this is the only published file inclusion vulnerability I&#8217;ve ever seen on a Java based web application.<br />
Well, there&#8217;s more out there :-)</p>
<p><img alt="PDF Format" width="16" height="18" src="images/format_pdf_small.png" /> <a href="advisories/JSPWiki_Multiple_Vulnerabilities.pdf" title="JSPWiki Multiple Vulnerabilities Security Advisory - PDF version"><abbr title="Portable Document Format">PDF</abbr> version</a>.<br />
<img alt="TXT Format" width="16" height="18" src="images/format_text_small.png" /> <a href="advisories/JSPWiki_Multiple_Vulnerabilities.txt" title="JSPWiki Multiple Vulnerabilities Security Advisory - TXT version">TXT version</a>.</p>
<p>Also on:<br />
<a href="http://www.securityfocus.com/bid/27785" title="JSPWiki 'Edit.jsp' Multiple Input Validation Vulnerabilities"><abbr title="Bugtraq ID">BID</abbr> 27785</a><br />
<a href="http://www.milw0rm.com/exploits/5112" title="JSPWiki 2.4.104 / 2.5.139 Multiple Remote Vulnerabilities">milw0rm</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2008/01/15/jspwiki-multiple-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MediaWiki Cross-Site Scripting Vulnerabilities</title>
		<link>http://www.rec-sec.com/2007/02/18/mediawiki-cross-site-scripting-vulnerabilities/</link>
		<comments>http://www.rec-sec.com/2007/02/18/mediawiki-cross-site-scripting-vulnerabilities/#comments</comments>
		<pubDate>Sun, 18 Feb 2007 11:07:47 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Advisories]]></category>

		<guid isPermaLink="false">http://www.rec-sec.com/?p=91</guid>
		<description><![CDATA[Security Advisory for MediaWiki versions:
1.6.x branch before 1.6.10
1.7.x branch before 1.7.3
1.8.x branch before 1.8.4
1.9.x branch before 1.9.3
Vulnerabilities found:

Cross-Site Scripting
UTF-7 Cross-Site Scripting

 TXT version.
Also on:
BID 21956
MediaWiki patch announcement
RSnake expand the MediaWiki 1.9.2 UTF-7 XSS exploit
]]></description>
			<content:encoded><![CDATA[<p><img alt="MediaWiki" width="100" height="100" class="right" src="images/mediawiki_logo.png" />Security Advisory for MediaWiki versions:<br />
1.6.x branch before 1.6.10<br />
1.7.x branch before 1.7.3<br />
1.8.x branch before 1.8.4<br />
1.9.x branch before 1.9.3</p>
<p>Vulnerabilities found:</p>
<ul>
<li>Cross-Site Scripting</li>
<li><abbr title="7-bit Unicode Transformation Format">UTF-7</abbr> Cross-Site Scripting</li>
</ul>
<p><img alt="TXT Format" width="16" height="18" src="images/format_text_small.png" /> <a href="advisories/MediaWiki_UTF-7_Cross-Site_Scripting_Vulnerability.txt" title="MediaWiki Cross-Site Scripting Vulnerabilities Security Advisory - TXT version">TXT version</a>.</p>
<p>Also on:<br />
<a href="http://www.securityfocus.com/bid/21956" title="MediaWiki AJAX Index.PHP Cross-Site Scripting Vulnerability"><abbr title="Bugtraq ID">BID</abbr> 21956</a><br />
<a href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2007-February/000060.html" title="[MediaWiki-announce] MediaWiki 1.9.3, 1.8.4, 1.7.3, 1.6.10 released">MediaWiki patch announcement</a><br />
<a href="http://ha.ckers.org/blog/20070220/mediawiki-192-utf-7-xss/" title="MediaWiki 1.9.2 UTF-7 XSS">RSnake expand the MediaWiki 1.9.2 <abbr title="7-bit Unicode Transformation Format">UTF-7</abbr> <abbr title="Cross-Site Scripting">XSS</abbr> exploit</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2007/02/18/mediawiki-cross-site-scripting-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
