<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Information Security News and Exploits &#187; Exploits</title>
	<atom:link href="http://www.allinfosec.com/category/exploits/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.allinfosec.com</link>
	<description>Providing you with Security News and Exploits from all over the web.</description>
	<lastBuildDate>Fri, 18 May 2012 12:31:23 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>[webapps / 0day] &#8211; o0mBBS &lt;= 0.65B Remote File Upload</title>
		<link>http://www.allinfosec.com/2012/05/18/webapps-0day-o0mbbs-0-65b-remote-file-upload-13/</link>
		<comments>http://www.allinfosec.com/2012/05/18/webapps-0day-o0mbbs-0-65b-remote-file-upload-13/#comments</comments>
		<pubDate>Fri, 18 May 2012 12:31:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/18/webapps-0day-o0mbbs-0-65b-remote-file-upload-13/</guid>
		<description><![CDATA[ Source: http://1337day.com/exploits/18204
]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/18/webapps-0day-o0mbbs-0-65b-remote-file-upload-13/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[remote exploits] &#8211; Firefox 7/8 (&lt;= 8.0.1) nsSVGValue Out-of-Bounds Access Vulnerability</title>
		<link>http://www.allinfosec.com/2012/05/18/remote-exploits-firefox-78-8-0-1-nssvgvalue-out-of-bounds-access-vulnerability-10/</link>
		<comments>http://www.allinfosec.com/2012/05/18/remote-exploits-firefox-78-8-0-1-nssvgvalue-out-of-bounds-access-vulnerability-10/#comments</comments>
		<pubDate>Fri, 18 May 2012 12:31:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/18/remote-exploits-firefox-78-8-0-1-nssvgvalue-out-of-bounds-access-vulnerability-10/</guid>
		<description><![CDATA[##
    # This file is part of the Metasploit Framework and may be subject to
    # redistribution and commercial restrictions. Please see the Metasploit
    # Framework web site for more information on licensing and terms of use.
    #   http://metasploit.com/framework/
   [...]]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/18/remote-exploits-firefox-78-8-0-1-nssvgvalue-out-of-bounds-access-vulnerability-10/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[webapps / 0day] &#8211; Kerio WinRoute Firewall Web Server &lt; 6 Source Code Disclosure</title>
		<link>http://www.allinfosec.com/2012/05/18/webapps-0day-kerio-winroute-firewall-web-server-6-source-code-disclosure-8/</link>
		<comments>http://www.allinfosec.com/2012/05/18/webapps-0day-kerio-winroute-firewall-web-server-6-source-code-disclosure-8/#comments</comments>
		<pubDate>Fri, 18 May 2012 12:30:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/18/webapps-0day-kerio-winroute-firewall-web-server-6-source-code-disclosure-8/</guid>
		<description><![CDATA[# Exploit Title: Kerio WinRoute Firewall Embedded Web ServerVersion: Source
    Code Disclosure
    # Google Dork:
    # Date: 10.05.2012
    # Author: Eugene Salov, Andrey Komarov (Group-IB, http://group-ib.ru)
    # Software Link: http://winroute.ru/kerio_winroute_firewall.htm
    # Version: prior to 6
   [...]]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/18/webapps-0day-kerio-winroute-firewall-web-server-6-source-code-disclosure-8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[webapps / 0day] &#8211; Sockso &lt;=1.51 Persistent XSS Vulnerability</title>
		<link>http://www.allinfosec.com/2012/05/18/webapps-0day-sockso-1-51-persistent-xss-vulnerability-6/</link>
		<comments>http://www.allinfosec.com/2012/05/18/webapps-0day-sockso-1-51-persistent-xss-vulnerability-6/#comments</comments>
		<pubDate>Fri, 18 May 2012 12:30:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/18/webapps-0day-sockso-1-51-persistent-xss-vulnerability-6/</guid>
		<description><![CDATA[#######################################################################
    Application:     Sockso
http://sockso.pu-gh.com
    Versions:        &#60;= 1.5
    Platforms:       Windows, Mac, Linux
    Bug:             Persistant XSS
  [...]]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/18/webapps-0day-sockso-1-51-persistent-xss-vulnerability-6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[webapps / 0day] &#8211; phpThumb() v1.7.11 (dir &amp; title) Cross-Site Scripting Vulnerability</title>
		<link>http://www.allinfosec.com/2012/05/18/webapps-0day-phpthumb-v1-7-11-dir-title-cross-site-scripting-vulnerability-3/</link>
		<comments>http://www.allinfosec.com/2012/05/18/webapps-0day-phpthumb-v1-7-11-dir-title-cross-site-scripting-vulnerability-3/#comments</comments>
		<pubDate>Fri, 18 May 2012 12:30:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/18/webapps-0day-phpthumb-v1-7-11-dir-title-cross-site-scripting-vulnerability-3/</guid>
		<description><![CDATA[phpThumb() v1.7.11 (dir &#38; title) Cross-Site Scripting Vulnerability
    Vendor: SiliSoftware
    Product web page: http://www.silisoftware.com
    Affected version: 1.7.11-201108081537
    Summary: phpThumb() uses the GD library to create thumbnails from
    images (JPEG, PNG, GIF, BMP, etc) on the fly. The output size is
 [...]]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/18/webapps-0day-phpthumb-v1-7-11-dir-title-cross-site-scripting-vulnerability-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[local exploits] &#8211; Linux Kernel 3.3.x &lt;= 3.3.4 Buffer overflow in HFS plus filesystem</title>
		<link>http://www.allinfosec.com/2012/05/18/local-exploits-linux-kernel-3-3-x-3-3-4-buffer-overflow-in-hfs-plus-filesystem-3/</link>
		<comments>http://www.allinfosec.com/2012/05/18/local-exploits-linux-kernel-3-3-x-3-3-4-buffer-overflow-in-hfs-plus-filesystem-3/#comments</comments>
		<pubDate>Fri, 18 May 2012 12:30:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/18/local-exploits-linux-kernel-3-3-x-3-3-4-buffer-overflow-in-hfs-plus-filesystem-3/</guid>
		<description><![CDATA[* Affected product: Linux Kernel 3.3.x &#60;= 3.3.4
    2.6.x &#60;= 2.6.35.13
    * Impact: code execution / privilege escalation
    * Origin: HFS plus file system
    * Credit: Timo Warns (PRESENSE Technologies GmbH)
    * CVE Identifier: CVE-2012-2319
    Summary
  [...]]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/18/local-exploits-linux-kernel-3-3-x-3-3-4-buffer-overflow-in-hfs-plus-filesystem-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[webapps / 0day] &#8211; Division 6 IT &#8211; SQLi/XSS Vulnerability</title>
		<link>http://www.allinfosec.com/2012/05/18/webapps-0day-division-6-it-sqlixss-vulnerability/</link>
		<comments>http://www.allinfosec.com/2012/05/18/webapps-0day-division-6-it-sqlixss-vulnerability/#comments</comments>
		<pubDate>Fri, 18 May 2012 12:30:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/18/webapps-0day-division-6-it-sqlixss-vulnerability/</guid>
		<description><![CDATA[ 1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
     0      _                   __           __       __      [...]]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/18/webapps-0day-division-6-it-sqlixss-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[remote exploits] &#8211; Oracle Weblogic Apache Connector POST Request Buffer Overflow</title>
		<link>http://www.allinfosec.com/2012/05/18/remote-exploits-oracle-weblogic-apache-connector-post-request-buffer-overflow/</link>
		<comments>http://www.allinfosec.com/2012/05/18/remote-exploits-oracle-weblogic-apache-connector-post-request-buffer-overflow/#comments</comments>
		<pubDate>Fri, 18 May 2012 12:30:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/18/remote-exploits-oracle-weblogic-apache-connector-post-request-buffer-overflow/</guid>
		<description><![CDATA[##
    # This file is part of the Metasploit Framework and may be subject to
    # redistribution and commercial restrictions. Please see the Metasploit
    # web site for more information on licensing and terms of use.
    #   http://metasploit.com/
    [...]]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/18/remote-exploits-oracle-weblogic-apache-connector-post-request-buffer-overflow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[local exploits] &#8211; SkinCrafter ActiveX Control version 3.0 Buffer Overflow</title>
		<link>http://www.allinfosec.com/2012/05/18/local-exploits-skincrafter-activex-control-version-3-0-buffer-overflow/</link>
		<comments>http://www.allinfosec.com/2012/05/18/local-exploits-skincrafter-activex-control-version-3-0-buffer-overflow/#comments</comments>
		<pubDate>Fri, 18 May 2012 12:30:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/18/local-exploits-skincrafter-activex-control-version-3-0-buffer-overflow/</guid>
		<description><![CDATA[# Software  : SkinCrafter from NMSoft Technologies
    # Version   : SkinCrafter version 3.0
    # Title     : Buffer overflow in skincrafter3_vs2005.dll of skinCrafter vs3.0
    # Link      : http://www.skincrafter.com/downloads/SkinCrafter_Demo_2005_2008_x86.zip
    # Date   [...]]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/18/local-exploits-skincrafter-activex-control-version-3-0-buffer-overflow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[dos / poc] &#8211; SkinCrafter 3.0 Buffer Overflow</title>
		<link>http://www.allinfosec.com/2012/05/18/dos-poc-skincrafter-3-0-buffer-overflow/</link>
		<comments>http://www.allinfosec.com/2012/05/18/dos-poc-skincrafter-3-0-buffer-overflow/#comments</comments>
		<pubDate>Fri, 18 May 2012 12:30:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/18/dos-poc-skincrafter-3-0-buffer-overflow/</guid>
		<description><![CDATA[# Software  : SkinCrafter from NMSoft Technologies
    # Version   : SkinCrafter version 3.0
    # Title     : Buffer overflow in skincrafter3_vs2005.dll of skinCrafter vs3.0
    # Link      : http://www.skincrafter.com/downloads/SkinCrafter_Demo_2005_2008_x86.zip
    # Date   [...]]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/18/dos-poc-skincrafter-3-0-buffer-overflow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[webapps / 0day] &#8211; Cryptographp Local File Inclusion / HTTP Response Splitting</title>
		<link>http://www.allinfosec.com/2012/05/18/webapps-0day-cryptographp-local-file-inclusion-http-response-splitting/</link>
		<comments>http://www.allinfosec.com/2012/05/18/webapps-0day-cryptographp-local-file-inclusion-http-response-splitting/#comments</comments>
		<pubDate>Fri, 18 May 2012 12:30:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/18/webapps-0day-cryptographp-local-file-inclusion-http-response-splitting/</guid>
		<description><![CDATA[ Source: http://1337day.com/exploits/18297
]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/18/webapps-0day-cryptographp-local-file-inclusion-http-response-splitting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[remote exploits] &#8211; HP VSA Command Execution</title>
		<link>http://www.allinfosec.com/2012/05/18/remote-exploits-hp-vsa-command-execution/</link>
		<comments>http://www.allinfosec.com/2012/05/18/remote-exploits-hp-vsa-command-execution/#comments</comments>
		<pubDate>Fri, 18 May 2012 12:30:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/18/remote-exploits-hp-vsa-command-execution/</guid>
		<description><![CDATA[ Source: http://1337day.com/exploits/18299
]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/18/remote-exploits-hp-vsa-command-execution/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[remote exploits] &#8211; PHP 5.4 Win32 Code Execution</title>
		<link>http://www.allinfosec.com/2012/05/18/remote-exploits-php-5-4-win32-code-execution/</link>
		<comments>http://www.allinfosec.com/2012/05/18/remote-exploits-php-5-4-win32-code-execution/#comments</comments>
		<pubDate>Fri, 18 May 2012 12:30:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/18/remote-exploits-php-5-4-win32-code-execution/</guid>
		<description><![CDATA[// Exploit Title: PHP 5.4 (5.4.3) Code Execution 0day (Win32)
    // Exploit author: 0in (Maksymilian Motyl)
    // Email: 0in(dot)email(at)gmail.com
    // * Bug with Variant type parsing originally discovered by Condis
    // Tested on Windows XP SP3 fully patched (Polish)
    ===================
 [...]]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/18/remote-exploits-php-5-4-win32-code-execution/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[remote exploits] &#8211; Squiggle 1.7 SVG Browser Java Code Execution</title>
		<link>http://www.allinfosec.com/2012/05/18/remote-exploits-squiggle-1-7-svg-browser-java-code-execution/</link>
		<comments>http://www.allinfosec.com/2012/05/18/remote-exploits-squiggle-1-7-svg-browser-java-code-execution/#comments</comments>
		<pubDate>Fri, 18 May 2012 12:30:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/18/remote-exploits-squiggle-1-7-svg-browser-java-code-execution/</guid>
		<description><![CDATA[##
    # This file is part of the Metasploit Framework and may be subject to
    # redistribution and commercial restrictions. Please see the Metasploit
    # Framework web site for more information on licensing and terms of use.
    #   http://metasploit.com/framework/
   [...]]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/18/remote-exploits-squiggle-1-7-svg-browser-java-code-execution/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[dos / poc] &#8211; Mozilla Firefox &lt;= 12.0 Denial Of Service Exploit</title>
		<link>http://www.allinfosec.com/2012/05/17/dos-poc-mozilla-firefox-12-0-denial-of-service-exploit-13/</link>
		<comments>http://www.allinfosec.com/2012/05/17/dos-poc-mozilla-firefox-12-0-denial-of-service-exploit-13/#comments</comments>
		<pubDate>Thu, 17 May 2012 12:31:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/17/dos-poc-mozilla-firefox-12-0-denial-of-service-exploit-13/</guid>
		<description><![CDATA[Title: Mozilla Firefox &#60;=12.0 Denial Of Service Exploit
    Author: L20ot &#8211; l20ot[at]yahoo[dot]com
    Software Link: http://www.mozilla-europe.org/en/firefox/
    Version: 12.0 &#8211; lastversion
    Tested on: Windows 7 x32&#215;64
    Description: visiting this php page you&#8217;ll get an instant crash of Firefox
    Greetz: [...]]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/17/dos-poc-mozilla-firefox-12-0-denial-of-service-exploit-13/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[webapps / 0day] &#8211; o0mBBS &lt;= 0.65B Remote File Upload</title>
		<link>http://www.allinfosec.com/2012/05/17/webapps-0day-o0mbbs-0-65b-remote-file-upload-12/</link>
		<comments>http://www.allinfosec.com/2012/05/17/webapps-0day-o0mbbs-0-65b-remote-file-upload-12/#comments</comments>
		<pubDate>Thu, 17 May 2012 12:31:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/17/webapps-0day-o0mbbs-0-65b-remote-file-upload-12/</guid>
		<description><![CDATA[ Source: http://1337day.com/exploits/18204
]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/17/webapps-0day-o0mbbs-0-65b-remote-file-upload-12/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[remote exploits] &#8211; Firefox 7/8 (&lt;= 8.0.1) nsSVGValue Out-of-Bounds Access Vulnerability</title>
		<link>http://www.allinfosec.com/2012/05/17/remote-exploits-firefox-78-8-0-1-nssvgvalue-out-of-bounds-access-vulnerability-9/</link>
		<comments>http://www.allinfosec.com/2012/05/17/remote-exploits-firefox-78-8-0-1-nssvgvalue-out-of-bounds-access-vulnerability-9/#comments</comments>
		<pubDate>Thu, 17 May 2012 12:31:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/17/remote-exploits-firefox-78-8-0-1-nssvgvalue-out-of-bounds-access-vulnerability-9/</guid>
		<description><![CDATA[##
    # This file is part of the Metasploit Framework and may be subject to
    # redistribution and commercial restrictions. Please see the Metasploit
    # Framework web site for more information on licensing and terms of use.
    #   http://metasploit.com/framework/
   [...]]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/17/remote-exploits-firefox-78-8-0-1-nssvgvalue-out-of-bounds-access-vulnerability-9/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[webapps / 0day] &#8211; Kerio WinRoute Firewall Web Server &lt; 6 Source Code Disclosure</title>
		<link>http://www.allinfosec.com/2012/05/17/webapps-0day-kerio-winroute-firewall-web-server-6-source-code-disclosure-7/</link>
		<comments>http://www.allinfosec.com/2012/05/17/webapps-0day-kerio-winroute-firewall-web-server-6-source-code-disclosure-7/#comments</comments>
		<pubDate>Thu, 17 May 2012 12:30:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/17/webapps-0day-kerio-winroute-firewall-web-server-6-source-code-disclosure-7/</guid>
		<description><![CDATA[# Exploit Title: Kerio WinRoute Firewall Embedded Web ServerVersion: Source
    Code Disclosure
    # Google Dork:
    # Date: 10.05.2012
    # Author: Eugene Salov, Andrey Komarov (Group-IB, http://group-ib.ru)
    # Software Link: http://winroute.ru/kerio_winroute_firewall.htm
    # Version: prior to 6
   [...]]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/17/webapps-0day-kerio-winroute-firewall-web-server-6-source-code-disclosure-7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[webapps / 0day] &#8211; Sockso &lt;=1.51 Persistent XSS Vulnerability</title>
		<link>http://www.allinfosec.com/2012/05/17/webapps-0day-sockso-1-51-persistent-xss-vulnerability-5/</link>
		<comments>http://www.allinfosec.com/2012/05/17/webapps-0day-sockso-1-51-persistent-xss-vulnerability-5/#comments</comments>
		<pubDate>Thu, 17 May 2012 12:30:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/17/webapps-0day-sockso-1-51-persistent-xss-vulnerability-5/</guid>
		<description><![CDATA[#######################################################################
    Application:     Sockso
http://sockso.pu-gh.com
    Versions:        &#60;= 1.5
    Platforms:       Windows, Mac, Linux
    Bug:             Persistant XSS
  [...]]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/17/webapps-0day-sockso-1-51-persistent-xss-vulnerability-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[webapps / 0day] &#8211; phpThumb() v1.7.11 (dir &amp; title) Cross-Site Scripting Vulnerability</title>
		<link>http://www.allinfosec.com/2012/05/17/webapps-0day-phpthumb-v1-7-11-dir-title-cross-site-scripting-vulnerability-2/</link>
		<comments>http://www.allinfosec.com/2012/05/17/webapps-0day-phpthumb-v1-7-11-dir-title-cross-site-scripting-vulnerability-2/#comments</comments>
		<pubDate>Thu, 17 May 2012 12:30:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.allinfosec.com/2012/05/17/webapps-0day-phpthumb-v1-7-11-dir-title-cross-site-scripting-vulnerability-2/</guid>
		<description><![CDATA[phpThumb() v1.7.11 (dir &#38; title) Cross-Site Scripting Vulnerability
    Vendor: SiliSoftware
    Product web page: http://www.silisoftware.com
    Affected version: 1.7.11-201108081537
    Summary: phpThumb() uses the GD library to create thumbnails from
    images (JPEG, PNG, GIF, BMP, etc) on the fly. The output size is
 [...]]]></description>
		<wfw:commentRss>http://www.allinfosec.com/2012/05/17/webapps-0day-phpthumb-v1-7-11-dir-title-cross-site-scripting-vulnerability-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

