<?xml version="1.0"?>
<rss version="2.0" xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>CNET Forums: Message List - VULNERABILITIES / FIXES - April 27, 2012</title>
    <link>http://forums.cnet.com/</link>
    <description>The latest posts in VULNERABILITIES / FIXES - April 27, 2012.</description>
    <image>
    <title>CNET Forums: Message List - VULNERABILITIES / FIXES - April 27, 2012</title>
    <url>http://i.i.com.com/cnwk.1d/i/cobd/cnet/cnet_88x31.gif</url>
    <link>http://forums.cnet.com/</link>
    <width>31</width>
    <height>88</height>
    </image>
    <category>CNET.com</category>
    <generator>CNET</generator>
    <docs>http://www.cnet.com</docs>


    <item>
      <title>Car Portal CMS Cross-Site Request Forgery Vulnerability</title>
      <description>Release Date : 2012-04-27&lt;br&gt;&lt;br&gt;Criticality level : Less critical&lt;br&gt;Impact : Cross Site Scripting&lt;br&gt;Where : From remo ...</description>
      <link>http://forums.cnet.com/7726-6132_102-5304473.html</link>
      <guid isPermalink="true">http://forums.cnet.com/7726-6132_102-5304473.html</guid>      
      <pubDate>27 Apr 2012 17:29:08 PDT</pubDate>
    </item>

    <item>
      <title>DiY-CMS Cross-Site Request Forgery Vulnerability</title>
      <description>Release Date : 2012-04-27&lt;br&gt;&lt;br&gt;Criticality level : Less critical&lt;br&gt;Impact : Cross Site Scripting&lt;br&gt;Where : From remo ...</description>
      <link>http://forums.cnet.com/7726-6132_102-5304428.html</link>
      <guid isPermalink="true">http://forums.cnet.com/7726-6132_102-5304428.html</guid>      
      <pubDate>27 Apr 2012 16:10:32 PDT</pubDate>
    </item>

    <item>
      <title>eFront &amp;quot;courses_ID&amp;quot; Path Disclosure Weakness</title>
      <description>Release Date : 2012-04-27&lt;br&gt;&lt;br&gt;Criticality level : Not critical&lt;br&gt;Impact : Exposure of system information&lt;br&gt;Where : ...</description>
      <link>http://forums.cnet.com/7726-6132_102-5304441.html</link>
      <guid isPermalink="true">http://forums.cnet.com/7726-6132_102-5304441.html</guid>      
      <pubDate>27 Apr 2012 16:09:36 PDT</pubDate>
    </item>

    <item>
      <title>Oracle Database Multiple Vulnerabilities</title>
      <description>Release Date: 2012-04-18 &lt;br&gt;Last Update: 2012-04-27 &lt;br&gt;&lt;br&gt;Criticality level : Moderately critical&lt;br&gt;Impact : Securit ...</description>
      <link>http://forums.cnet.com/7726-6132_102-5304400.html</link>
      <guid isPermalink="true">http://forums.cnet.com/7726-6132_102-5304400.html</guid>      
      <pubDate>27 Apr 2012 14:05:37 PDT</pubDate>
    </item>

    <item>
      <title>concrete5 &amp;quot;approveImmediately&amp;quot; Cross-Site Scripting</title>
      <description>&lt;b&gt;concrete5 &amp;quot;approveImmediately&amp;quot; Cross-Site Scripting Vulnerability&lt;/b&gt;&lt;br&gt;&lt;br&gt;Release Date : 2012-04-27&lt;br&gt;&lt; ...</description>
      <link>http://forums.cnet.com/7726-6132_102-5304369.html</link>
      <guid isPermalink="true">http://forums.cnet.com/7726-6132_102-5304369.html</guid>      
      <pubDate>27 Apr 2012 13:44:00 PDT</pubDate>
    </item>

    <item>
      <title>HP LaserJet Printers / Digital Senders Unauthorized Firmware</title>
      <description>&lt;b&gt;HP LaserJet Printers / Digital Senders Unauthorized Firmware Update Security Issue&lt;/b&gt;&lt;br&gt;&lt;br&gt;Release Date: 2011-12-0 ...</description>
      <link>http://forums.cnet.com/7726-6132_102-5304373.html</link>
      <guid isPermalink="true">http://forums.cnet.com/7726-6132_102-5304373.html</guid>      
      <pubDate>27 Apr 2012 12:38:05 PDT</pubDate>
    </item>

    <item>
      <title>TwonkyManager TwonkyServer Directory Traversal Vulnerability</title>
      <description>Release Date : 2012-04-27&lt;br&gt;&lt;br&gt;Criticality level : Less critical&lt;br&gt;Impact : Exposure of sensitive information&lt;br&gt;Wher ...</description>
      <link>http://forums.cnet.com/7726-6132_102-5304370.html</link>
      <guid isPermalink="true">http://forums.cnet.com/7726-6132_102-5304370.html</guid>      
      <pubDate>27 Apr 2012 12:29:12 PDT</pubDate>
    </item>

    <item>
      <title>TwonkyServer Directory Traversal Vulnerability</title>
      <description>Release Date : 2012-04-27&lt;br&gt;&lt;br&gt;Criticality level : Less critical&lt;br&gt;Impact : Exposure of sensitive information&lt;br&gt;Wher ...</description>
      <link>http://forums.cnet.com/7726-6132_102-5304329.html</link>
      <guid isPermalink="true">http://forums.cnet.com/7726-6132_102-5304329.html</guid>      
      <pubDate>27 Apr 2012 12:26:11 PDT</pubDate>
    </item>

    <item>
      <title>Drupal Ubercart Module Script Insertion and Code Injection</title>
      <description>&lt;b&gt;Drupal Ubercart Module Script Insertion and Code Injection Vulnerabilities&lt;/b&gt;&lt;br&gt;&lt;br&gt;Release Date : 2012-04-27&lt;br&gt;&lt;b ...</description>
      <link>http://forums.cnet.com/7726-6132_102-5304238.html</link>
      <guid isPermalink="true">http://forums.cnet.com/7726-6132_102-5304238.html</guid>      
      <pubDate>27 Apr 2012 07:29:12 PDT</pubDate>
    </item>

    <item>
      <title>VMware ESX Server Multiple Vulnerabilities</title>
      <description>Release Date : 2012-04-27&lt;br&gt;&lt;br&gt;Criticality level : Highly critical&lt;br&gt;Impact : Privilege escalation&lt;br&gt;DoS&lt;br&gt;System a ...</description>
      <link>http://forums.cnet.com/7726-6132_102-5304243.html</link>
      <guid isPermalink="true">http://forums.cnet.com/7726-6132_102-5304243.html</guid>      
      <pubDate>27 Apr 2012 07:21:29 PDT</pubDate>
    </item>

    <item>
      <title>WordPress Zingiri Web Shop Plugin Cross-Site Scripting</title>
      <description>&lt;b&gt;WordPress Zingiri Web Shop Plugin Cross-Site Scripting and Script Insertion Vulnerabilities&lt;/b&gt;&lt;br&gt;&lt;br&gt;Release Date : ...</description>
      <link>http://forums.cnet.com/7726-6132_102-5304209.html</link>
      <guid isPermalink="true">http://forums.cnet.com/7726-6132_102-5304209.html</guid>      
      <pubDate>27 Apr 2012 07:15:06 PDT</pubDate>
    </item>

    <item>
      <title>Debian update for spip</title>
      <description>Release Date : 2012-04-27&lt;br&gt;&lt;br&gt;Criticality level : Less critical&lt;br&gt;Impact : Cross Site Scripting&lt;br&gt;Where : From remo ...</description>
      <link>http://forums.cnet.com/7726-6132_102-5304229.html</link>
      <guid isPermalink="true">http://forums.cnet.com/7726-6132_102-5304229.html</guid>      
      <pubDate>27 Apr 2012 07:02:44 PDT</pubDate>
    </item>

    <item>
      <title>gpEasy CMS &amp;quot;jsoncallback&amp;quot; Cross-Site Scripting Vulnerability</title>
      <description>Release Date : 2012-04-27&lt;br&gt;&lt;br&gt;Criticality level : Less critical&lt;br&gt;Impact : Cross Site Scripting&lt;br&gt;Where : From remo ...</description>
      <link>http://forums.cnet.com/7726-6132_102-5304228.html</link>
      <guid isPermalink="true">http://forums.cnet.com/7726-6132_102-5304228.html</guid>      
      <pubDate>27 Apr 2012 07:02:40 PDT</pubDate>
    </item>

    <item>
      <title>Ubuntu update for jetty</title>
      <description>Release Date : 2012-04-27&lt;br&gt;&lt;br&gt;Criticality level : Less critical&lt;br&gt;Impact : DoS&lt;br&gt;Where : From remote&lt;br&gt;Solution St ...</description>
      <link>http://forums.cnet.com/7726-6132_102-5304227.html</link>
      <guid isPermalink="true">http://forums.cnet.com/7726-6132_102-5304227.html</guid>      
      <pubDate>27 Apr 2012 07:02:36 PDT</pubDate>
    </item>

    <item>
      <title>HP NonStop Server Java Multiple Vulnerabilities</title>
      <description>Release Date : 2012-04-27&lt;br&gt;&lt;br&gt;Criticality level : Highly critical&lt;br&gt;Impact : Manipulation of data&lt;br&gt;Exposure of sen ...</description>
      <link>http://forums.cnet.com/7726-6132_102-5304241.html</link>
      <guid isPermalink="true">http://forums.cnet.com/7726-6132_102-5304241.html</guid>      
      <pubDate>27 Apr 2012 07:00:52 PDT</pubDate>
    </item>

    <item>
      <title>Quest Toad for Data Analysts Insecure Default Directory</title>
      <description>&lt;b&gt;Quest Toad for Data Analysts Insecure Default Directory Permissions&lt;/b&gt;&lt;br&gt;&lt;br&gt;Release Date : 2012-04-27&lt;br&gt;&lt;br&gt;Criti ...</description>
      <link>http://forums.cnet.com/7726-6132_102-5304202.html</link>
      <guid isPermalink="true">http://forums.cnet.com/7726-6132_102-5304202.html</guid>      
      <pubDate>27 Apr 2012 05:17:26 PDT</pubDate>
    </item>

    <item>
      <title>Joomla! nBill Component &amp;quot;message&amp;quot; Cross-Site Scripting</title>
      <description>&lt;b&gt;Joomla! nBill Component &amp;quot;message&amp;quot; Cross-Site Scripting Vulnerability&lt;/b&gt;&lt;br&gt;&lt;br&gt;Release Date : 2012-04-27&lt;b ...</description>
      <link>http://forums.cnet.com/7726-6132_102-5304201.html</link>
      <guid isPermalink="true">http://forums.cnet.com/7726-6132_102-5304201.html</guid>      
      <pubDate>27 Apr 2012 05:17:22 PDT</pubDate>
    </item>

    <item>
      <title>VULNERABILITIES / FIXES - April 27, 2012</title>
      <description>&lt;b&gt;PHP Volunteer Management Cross-Site Scripting and SQL Injection Vulnerabilities&lt;/b&gt;&lt;br&gt;&lt;br&gt;Release Date : 2012-04-27&lt; ...</description>
      <link>http://forums.cnet.com/7726-6132_102-5304189.html</link>
      <guid isPermalink="true">http://forums.cnet.com/7726-6132_102-5304189.html</guid>      
      <pubDate>27 Apr 2012 05:10:16 PDT</pubDate>
    </item>
  </channel>
</rss>