<?xml version="1.0" encoding="utf-8"?>
<!--If you can view this message, then you are viewing the
raw RSS (XML) source. This file is intended to be viewed with an
RSS reader or for syndication between websites. For more information,
try a web search for RSS.
Created by Siteframe http://siteframe.org.-->
<rss version="2.0" xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>Security @ Siteframe</title>
    <link>http://siteframe.org/security</link>
    <description>&lt;p&gt;Notices and information about enhancing security for your Siteframe website.&lt;/p&gt;</description>
    <language>en-US</language>
    <copyright>&amp;copy;2005-7 Glen Campbell</copyright>
    <lastBuildDate>Sat, 11 Feb 2006 15:38:33 PST</lastBuildDate>
    <generator>Siteframe 5.0.6</generator>
    <webMaster>webmaster@siteframe.org</webMaster>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <ttl>30</ttl>
    <item>
      <title>XSS Vulnerability in Siteframe 5.0.1</title>
      <description>In search.php, an unmodified $_GET variable is assigned to a Smarty variable, where it can be displayed on a page. A malicious intruder could insert evil Javascript into the query string and execute it from the page.&#13;
IMMEDIATE FIX&#13;
On line 64 of search.php, wrap the $_GET['q'] in the...</description>
      <pubDate>Sat, 11 Feb 2006 15:38:33 PST</pubDate>
      <guid isPermaLink="true">http://siteframe.org/p/xss_vulnerability_in_siteframe_501</guid>
      <link>http://siteframe.org/p/xss_vulnerability_in_siteframe_501</link>
      <category>security</category>
      <category>xss</category>
    </item>
    <item>
      <title>Siteframe 3: Cross-Site Scripting (XSS) Vulnerability</title>
      <description>Siteframe has, unfortunately, been shown to be vulnerable to&#13;
cross-site scripting attacks. In this case, an attacker from a remote&#13;
site can use a security hole in Siteframe to access files on the&#13;
attacked computer.There is a fix; you need to edit the file web/siteframe.php and change this line...</description>
      <pubDate>Sat, 26 Nov 2005 22:40:46 PST</pubDate>
      <guid isPermaLink="true">http://siteframe.org/p/siteframe_3_crosssite_scriptiong_xss_vulnerability</guid>
      <link>http://siteframe.org/p/siteframe_3_crosssite_scriptiong_xss_vulnerability</link>
      <category>security</category>
      <category>siteframe</category>
      <category>xss</category>
    </item>
  </channel>
</rss>


<!-- rss.php/0.1073 secs -->
