<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hell - Spy . De &#187; Sec</title>
	<atom:link href="http://www.hell-spy.de/category/sec/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hell-spy.de</link>
	<description>Anyone who has never made a mistake has never tried anything new. - Albert Einstein</description>
	<lastBuildDate>Mon, 22 Feb 2010 13:24:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>PHP Web Stat XSS</title>
		<link>http://www.hell-spy.de/2009/05/php-web-stat-xss/</link>
		<comments>http://www.hell-spy.de/2009/05/php-web-stat-xss/#comments</comments>
		<pubDate>Sat, 16 May 2009 09:19:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Sec]]></category>

		<guid isPermaLink="false">http://www.hell-spy.de/?p=51</guid>
		<description><![CDATA[The newest version of PHP Web Stat (3.6.28) is vulnerable to a Cross Site Scripting attack, allowing code injection by malicious users. You can find my Proof of Concept here.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.hell-spy.de%2F2009%2F05%2Fphp-web-stat-xss%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.hell-spy.de%2F2009%2F05%2Fphp-web-stat-xss%2F&amp;source=cavka&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>The newest version of PHP Web Stat (3.6.28) is vulnerable to a Cross Site Scripting attack, allowing code injection by malicious users. You can find my Proof of Concept <a href="http://www.hell-spy.de/sec/CAV-2009-02.txt">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hell-spy.de/2009/05/php-web-stat-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lansuite / phgstats XSS</title>
		<link>http://www.hell-spy.de/2009/05/lansuite-xss/</link>
		<comments>http://www.hell-spy.de/2009/05/lansuite-xss/#comments</comments>
		<pubDate>Sun, 03 May 2009 19:32:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Sec]]></category>

		<guid isPermaLink="false">http://www.hell-spy.de/?p=43</guid>
		<description><![CDATA[Looks like it&#8217;s blogging time. For unknown reasons (unknown my ass &#8211; boredom and lack of beer), I took a deeper look at Lansuite. The last version (v3.someting CVS) was full of XSS and SQL injection bugs but after reporting it they fixed many, but not all of them. There are still 3 XSS bugs. [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.hell-spy.de%2F2009%2F05%2Flansuite-xss%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.hell-spy.de%2F2009%2F05%2Flansuite-xss%2F&amp;source=cavka&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Looks like it&#8217;s blogging time. For unknown reasons (unknown my ass &#8211; boredom and lack of beer), I took a deeper look at Lansuite. The last version (v3.someting CVS) was full of XSS and SQL injection bugs but after reporting it they fixed many, but not all of them. There are still 3 XSS bugs. Well they don&#8217;t directly affect Lansuite but phgstats. You can find a few details about it <a href="http://www.hell-spy.de/sec/CAV-2009-01.txt">here</a>. Have fun.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hell-spy.de/2009/05/lansuite-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
