<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ethicalhack3r &#187; Advisories</title>
	<atom:link href="http://www.ethicalhack3r.co.uk/category/advisories/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ethicalhack3r.co.uk</link>
	<description></description>
	<lastBuildDate>Tue, 24 Jan 2012 13:20:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>WordPress Plugin Disqus Comment System XSS</title>
		<link>http://www.ethicalhack3r.co.uk/security/wordpress-plugin-disqus-comment-system-xss/</link>
		<comments>http://www.ethicalhack3r.co.uk/security/wordpress-plugin-disqus-comment-system-xss/#comments</comments>
		<pubDate>Sun, 11 Dec 2011 16:15:17 +0000</pubDate>
		<dc:creator>ethicalhack3r</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=16648</guid>
		<description><![CDATA[# Exploit Title: WordPress Plugin Disqus Comment System < = 2.68 Reflected Cross-Site Scripting (XSS) # Google Dork: inurl:/wp-content/plugins/disqus-comment-system/ # Date: 11.12.11 # Author: Ryan Dewhurst (@ethicalhack3r) # Software Link: http://downloads.wordpress.org/plugin/disqus-comment-system.2.68.zip # Version: 2.68 # Tested on: Cross-Platform ** Vulnerability Description ** The WordPress Disqus Commment System version 2.68 was found to be effected by [...]]]></description>
		<wfw:commentRss>http://www.ethicalhack3r.co.uk/security/wordpress-plugin-disqus-comment-system-xss/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Concrete5 </title>
		<link>http://www.ethicalhack3r.co.uk/security/concrete5/</link>
		<comments>http://www.ethicalhack3r.co.uk/security/concrete5/#comments</comments>
		<pubDate>Tue, 04 Oct 2011 11:52:06 +0000</pubDate>
		<dc:creator>ethicalhack3r</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=16555</guid>
		<description><![CDATA[# Exploit Title: Concrete5 < = 5.4.2.1 SQL Injection and XSS Vulnerabilities # Date: 2011-10-04 # Author: Ryan Dewhurst (ryandewhurst at gmail) (@ethicalhack3r)(www.ethicalhack3r.co.uk) # Software Link: http://sourceforge.net/projects/concretecms/files/concrete5/5.4.2.1/ # Version: 5.4.2.1 (tested) 1.Vulnerability Description Multiple SQL Injection, Cross-Site Scripting (XSS) and Information Disclosure vulnerabilities were identified within Concrete5 version 5.4.2.1 Please note: Only a select few [...]]]></description>
		<wfw:commentRss>http://www.ethicalhack3r.co.uk/security/concrete5/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>WordPress &gt;= 2.9 Failure to Restrict URL Access</title>
		<link>http://www.ethicalhack3r.co.uk/security/wordpress-2-9-failure-to-restrict-url-access/</link>
		<comments>http://www.ethicalhack3r.co.uk/security/wordpress-2-9-failure-to-restrict-url-access/#comments</comments>
		<pubDate>Sat, 13 Feb 2010 18:23:16 +0000</pubDate>
		<dc:creator>ethicalhack3r</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=569</guid>
		<description><![CDATA[1. *Advisory Information* Title: WordPress &#62;= 2.9 Failure to Restrict URL Access Date published: 13/02/2010 2. *Vulnerability Information* Class: Failure to Restrict URL Access Remotely Exploitable: Yes Locally Exploitable: Yes 3. *Software Description* WordPress is a state-of-the-art publishing platform with a focus on aesthetics, web standards, and usability. WordPress is both free and priceless at [...]]]></description>
		<wfw:commentRss>http://www.ethicalhack3r.co.uk/security/wordpress-2-9-failure-to-restrict-url-access/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>[BONSAI] XSS and SQL Injection in Achievo </title>
		<link>http://www.ethicalhack3r.co.uk/security/bonsai-xss-and-sql-injection-in-achievo/</link>
		<comments>http://www.ethicalhack3r.co.uk/security/bonsai-xss-and-sql-injection-in-achievo/#comments</comments>
		<pubDate>Sat, 17 Oct 2009 13:10:22 +0000</pubDate>
		<dc:creator>ethicalhack3r</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=345</guid>
		<description><![CDATA[Today Andres Riancho owner of Bonsai Information Security (Argentina) and lead developer of w3af has released a couple of advisories on vulnerabilities in Achievo &#60;= 1.3.4 which we found a few months ago after our vulnerability research into common web applications. The affected web application is Achievo &#60;= 1.3.4. Achievo suffered from multiple simple persistent [...]]]></description>
		<wfw:commentRss>http://www.ethicalhack3r.co.uk/security/bonsai-xss-and-sql-injection-in-achievo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[BONSAI] SQL Injection in CS-Cart </title>
		<link>http://www.ethicalhack3r.co.uk/security/bonsai-sql-injection-in-cs-cart/</link>
		<comments>http://www.ethicalhack3r.co.uk/security/bonsai-sql-injection-in-cs-cart/#comments</comments>
		<pubDate>Tue, 04 Aug 2009 22:49:02 +0000</pubDate>
		<dc:creator>ethicalhack3r</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=253</guid>
		<description><![CDATA[Here is one of the vulnerabilities which I found during my research for Bonsai Security a few weeks ago. The research consisted of vulnerability assessing commercial and open source ecommerce web applications over a 2 week period. During the time of my research I learnt a great deal from Andres Riancho (w3af/bonsai-sec owner) and from [...]]]></description>
		<wfw:commentRss>http://www.ethicalhack3r.co.uk/security/bonsai-sql-injection-in-cs-cart/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

