<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
        <channel>
         <title>      @RISK: The Consensus Security Alert</title>
  <link>       http://www.sans.org/newsletters/risk/display.php</link>
  <description>All Updates From Vol: 8 - Issue: 47</description>
  <language>   en-us</language>
<copyright>(C) SANS Institute 2009</copyright>
             <webMaster>webmaster@sans.org</webMaster>
             <image>
               <title>SANS RSS Feed</title>
               <url>http://www.sans.org/images/rss_logo.gif</url>
               <link>http://www.sans.org/newsletters/risk/display.php</link>
             </image>
  <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/SansInstituteAtRiskAll" type="application/rss+xml" /><feedburner:browserFriendly></feedburner:browserFriendly><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
    <title>SANS 2009</title>
    <link>http://www.sans.org/info/35964/</link>
  <guid>       http://www.sans.org/info/35964/</guid>
    <description>More than 35 courses, SANS top instructors, all in one great place! SANS 2009 is being held in Orlando, FL on March 2-9. Register today!</description>
  </item>
  <item>
    <title>(1) CRITICAL: Apple Safari Multiple Vulnerabilities
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#widely1</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#widely1</guid>
    <description><![CDATA[ 
                                       <p><strong>Category:</strong> Widely Deployed Software</p> 
                                       <p><strong>Affected:</strong><ul class="affected"><li> Apple Safari versions prior to 4.0.4</li></ul></p>
                                      ]]></description>
  </item>
  <item>
    <title>(2) HIGH: RhinoSoft Serv-U FTP Server TEA Decoder Buffer Overflow Vulnerability
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#widely2</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#widely2</guid>
    <description><![CDATA[ 
                                       <p><strong>Category:</strong> Widely Deployed Software</p> 
                                       <p><strong>Affected:</strong><ul class="affected"><li> RhinoSoft Serv-U 9.0 .5</li><li>  RhinoSoft Serv-U 9.0.0.1</li></ul></p>
                                      ]]></description>
  </item>
  <item>
    <title>(3) MODERATE: Microsoft Windows SMB Packet Denial of Service Vulnerability
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#widely3</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#widely3</guid>
    <description><![CDATA[ 
                                       <p><strong>Category:</strong> Widely Deployed Software</p> 
                                       <p><strong>Affected:</strong><ul class="affected"><li> Microsoft Windows 7 for 32-bit Systems</li><li>  Microsoft Windows 7 for x64-based Systems</li><li>  Microsoft Windows Server 2008 R2 for x64-based Systems*</li><li>  Microsoft Windows Server 2008 R2 for Itanium-based Systems</li></ul></p>
                                      ]]></description>
  </item>
  <item>
    <title>(4) MODERATE: GIMP Image Parsing Integer Overflow Vulnerability
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#widely4</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#widely4</guid>
    <description><![CDATA[ 
                                       <p><strong>Category:</strong> Widely Deployed Software</p> 
                                       <p><strong>Affected:</strong><ul class="affected"><li> GIMP version 2.6.7 and prior</li></ul></p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.17 Apple Safari Shortcut Menu Options Information Disclosure
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.17</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.17</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-2842 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.18 Webkit Multiple Remote Code Execution, Denial of Service, and
 Information Disclosure Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.18</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.18</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-3384 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.19 WebKit Resource Load Callback Information Disclosure Weakness
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.19</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.19</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-2841 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.20 WebKit Preflight Request Same Origin Policy Bypass
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.20</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.20</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-2816 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.21 GIMP BMP Image Parsing Integer Overflow
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.21</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.21</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-1570 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.22 Adobe Flash Player Same Origin Policy Bypass
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.22</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.22</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.23 IBM WebSphere Application Server Administrative Console HTML
 Injection
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.23</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.23</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-2747 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.24 ngIRCd SSL/TLS Support MOTD Request Multiple Denial Of Service
 Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.24</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.24</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.25 libexif "exif-entry.c" Tag Format Conversion Heap Buffer
 Overflow Vulnerability
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.25</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.25</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.26 Sun VirtualBox Guest Additions Local Denial Of Service
 Vulnerability
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.26</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.26</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.27 FFmpeg TCP/UDP Memory Leak Denial Of ServiceVulnerability
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.27</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.27</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2008-4869 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.28 PHP "symlink()" "open_basedir" Restriction Bypass
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.28</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.28</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.29 Wikipedia Toolbar Remote Code Execution
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.29</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.29</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.30 Apple Safari CSS Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.30</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.30</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.31 GIMP PSD Image Parsing Integer Overflow
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.31</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.31</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-3909 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.32 Novell eDirectory "/dhost/httpstk;submit" Multiple Stack Buffer
 Overflow Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.32</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.32</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.11 Linux Kernel"megaraid_as" Local Privilege Escalation
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.11</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.11</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Linux
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.12 Linux Kernel KVM "KVM_MAX_MCE_BANKS" Memory Corruption
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.12</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.12</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Linux
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.13 Linux Kernel "hfc_usb.c" Local Privilege Escalation
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.13</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.13</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Linux
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.49 NETGEAR WNDAP330 Management Frame Remote Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.49</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.49</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-0052 </p> 
                                       <p><strong>Platform:</strong> Network Device
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.50 McAfee Network Security Manager Information Disclosure
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.50</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.50</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-3566 </p> 
                                       <p><strong>Platform:</strong> Network Device
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.51 Linksys WAP4400N Association Request Remote Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.51</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.51</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2007-5475 </p> 
                                       <p><strong>Platform:</strong> Network Device
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.16 Novell eDirectory "/dhost/modules?I:" Buffer Overflow
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.16</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.16</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Novell
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.14 Sun Solaris TCP Sockets Local Denial Of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.14</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.14</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Solaris
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.2 Yahoo! Messenger
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.2</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.2</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.3 XM Easy Personal FTP Server "NLST" Command Remote Denial of
 Service
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.3</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.3</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.4 XM Easy Personal FTP Server "APPE' and 'DELE" Commands Remote
 Denial of Service Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.4</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.4</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.5 Avast! Antivirus 'aswRsr.sys' Driver Local Privilege Escalation
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.5</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.5</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.6 Home FTP Server "SITE INDEX' Command Remote Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.6</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.6</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.7 HP Discovery and Dependency Mapping Inventory Unspecified
 Remote Code Execution
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.7</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.7</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-3841 </p> 
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.8 Home FTP Server 'MKD' Command Directory Traversal
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.8</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.8</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.9 Kaspersky Anti-Virus "kl1.sys" Driver Local Privilege
 Escalation
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.9</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.9</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.10 HP OpenView Network Node Manager "ovdbrun.exe" Denial of
 Service
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.10</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.10</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-3840 </p> 
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.15 CUPS File Descriptors Handling Remote Denial Of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.15</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.15</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-3553 </p> 
                                       <p><strong>Platform:</strong> Unix
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.38 Drupal RootCandy Theme URI Value HTML Injection
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.38</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.38</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.39 Drupal AddToAny Node Title HTML Injection
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.39</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.39</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.40 Drupal Web Services Module Authentication Bypass
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.40</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.40</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.41 HP ProCurve Switch Management Interface Multiple HTML Injection
 Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.41</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.41</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.42 Wordpress "wp-admin/includes/file.php" Arbitrary File Upload
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.42</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.42</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.43 UseBB BBcode Parsing Remote Denial Of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.43</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.43</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.44 Wordpress Unspecified Cross-Site Scripting
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.44</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.44</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.45 XOOPS Profile Activation Security Bypass Vulnerability
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.45</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.45</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.46 PHD Help Desk Multiple Cross-Site Scripting Vulnerabilities
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.46</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.46</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.47 SemanticScuttle Prior to 0.94.1 Multiple Unspecified Cross-Site
 Scripting Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.47</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.47</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.48 Joomla! eZine Component "d4m_ajax_pagenav.php" Remote File
 Include
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.48</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.48</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.33 Apple Mac OS X Apache HTTP TRACE Cross-Site Scripting
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.33</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.33</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-2823 </p> 
                                       <p><strong>Platform:</strong> Web Application - Cross Site Scripting
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.34 phpMyFAQ Search Page Cross-Site Scripting
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.34</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.34</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - Cross Site Scripting
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.35 Alteon OS BBI Cross-Site Request Forgery and HTML Injection
 Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.35</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.35</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - Cross Site Scripting
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.36 Multiple JiRo's Products "files/login.asp" Multiple SQL
 Injection Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.36</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.36</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.37 ActiveWebSoftwares Active Bids "default.asp" SQL Injection
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.37</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.37</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
  <item>
    <title>09.47.1 Microsoft Windows "KeAccumulateTicks()" SMB2 Packet Remote
 Denial of Service
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.1</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=47&amp;rss=Y#09.47.1</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-3676 </p> 
                                       <p><strong>Platform:</strong> Windows
</p>
                                      ]]></description>
  </item>
</channel>
</rss>
