<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title><![CDATA[Latest posts for the topic "Patch for new exploit"]]></title>
		<link>https://proxy2.de/forum/posts/list/3.php</link>
		<description><![CDATA[Latest messages posted in the topic "Patch for new exploit"]]></description>
		<generator>JForum - http://www.jforum.net</generator>
			<item>
				<title>Patch for new exploit</title>
				<description><![CDATA[ Ok firstly let me just say that a recently posted "exploit" on Security Focus claiming that peole could exploit the guestbook using the homepage field is incorrect as the guestbook already checks the submitted url.<br /> <br /> Anyway whilst disproving this exploit I realised there is an exploit that would require only minor knowledge to perform so I am submitting this patch before anyone else publicises the exploit.<br /> <br /> Open up lib/add.class.php. Find oth occurences of[code]$agent = getenv&#40;&quot;HTTP_USER_AGENT&quot;&#41;;[/code]and replace them with[code]$agent = htmlspecialchars&#40;getenv&#40;&quot;HTTP_USER_AGENT&quot;&#41;&#41;;[/code]Now you are patched.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4144/13326.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4144/13326.php</link>
				<pubDate><![CDATA[Sat, 22 Jan 2005 15:11:36]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ pre-emptive *bump*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4144/13336.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4144/13336.php</link>
				<pubDate><![CDATA[Sat, 22 Jan 2005 17:23:40]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Applied patch guestbook working fine. Another good job by carbonize. <img src="https://proxy2.de/forum//images/smilies/69934afc394145350659cd7add244ca9.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4144/13337.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4144/13337.php</link>
				<pubDate><![CDATA[Sat, 22 Jan 2005 17:24:04]]> GMT</pubDate>
				<author><![CDATA[ JTD]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Thanks Carbonize - patch inserted - so far, works fine. <br /> <br /> I'll let you know if I experience any problems with it.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4144/13353.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4144/13353.php</link>
				<pubDate><![CDATA[Sat, 22 Jan 2005 23:23:24]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Well this is a 0 day exploit meaning that it has not been published anywhere else yet to my knowledge. It's not the easiest exploit to actually pull off but better safe than sorry.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4144/13358.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4144/13358.php</link>
				<pubDate><![CDATA[Sun, 23 Jan 2005 00:05:22]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *bump*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4144/13362.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4144/13362.php</link>
				<pubDate><![CDATA[Sun, 23 Jan 2005 00:54:24]]> GMT</pubDate>
				<author><![CDATA[ Auron]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ OK I misread the exploit posted on the security focus site. With the discovery of these two exploits I am going to have to bring forward the release of Advanced Guestbook 2.4. It will not be that major an update but will patch several exploits, add Yahoo &amp; MSN fields, add a third option to gender and some other midnor differences.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4144/13365.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4144/13365.php</link>
				<pubDate><![CDATA[Sun, 23 Jan 2005 01:01:36]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *bump*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4144/13423.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4144/13423.php</link>
				<pubDate><![CDATA[Mon, 24 Jan 2005 20:35:12]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ applyed patch now looking forward the the update 2.4]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4144/13537.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4144/13537.php</link>
				<pubDate><![CDATA[Wed, 26 Jan 2005 18:04:40]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
	</channel>
</rss>