<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Top Web Vulnerabilities</title><link>http://www.communities.hp.com/securitysoftware/blogs/top5/default.aspx</link><description>The Top Web Vulnerabilities, reported as they happen, from SPI Labs</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 (Build: 20917.1142)</generator><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/TopWebVulnerabilities" type="application/rss+xml" /><item><title>Top Five Web Application Vulnerabilities 7/7/08 - 7/20/08</title><link>http://feeds.feedburner.com/~r/TopWebVulnerabilities/~3/341869574/top-five-web-application-vulnerabilities-7-7-08-7-20-08.aspx</link><pubDate>Mon, 21 Jul 2008 20:03:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:83940</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/top5/rsscomments.aspx?PostID=83940</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/07/21/top-five-web-application-vulnerabilities-7-7-08-7-20-08.aspx#comments</comments><description>&lt;p&gt;1) Microsoft Outlook Web Access for Exchange Server Email Field Cross-Site Scripting Vulnerability&lt;/p&gt;
&lt;p&gt;Microsoft Outlook Web Access (OWA) for Exchange Server is susceptible to a Cross-Site Scripting vulnerability. An attacker can leverage this issue to execute script code in the browsers of unsuspecting users in context of the affected application, possibly leading to theft of authentication credentials and other attacks. An advisory and updates which address this issue have been released. Contact the vendor for additional information. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/30130"&gt;http://www.securityfocus.com/bid/30130&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;2) Xerox CentreWare Web Multiple SQL Injection and Cross-Site Scripting Vulnerabilities&lt;/p&gt;
&lt;p&gt;Xerox CentreWare Web is susceptible to multiple SQL Injection and Cross-Site Scripting vulnerabilities. If exploited, these vulnerabilities could lead to compromise of the application, the theft of confidential information and authentication credentials, or be utilized in conducting additional database attacks. A fix has been released. Contact the vendor for further details.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/30151"&gt;http://www.securityfocus.com/bid/30151&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;3) Sun Java Web Start Multiple Vulnerabilities&lt;/p&gt;
&lt;p&gt;Sun Java Web Start is susceptible to multiple vulnerabilities including&amp;nbsp;buffer overflows, privilege escalation and information disclosure issues.&amp;nbsp; The user must first visit a malicious page before these vulnerabilities can be exploited. An attacker who leverages these issues could execute arbitrary code, or read, write, and execute arbitrary local files in the context of the user running a malicious Web Start application. This could result in a compromise of the underlying system.&amp;nbsp; Information obtained from the information disclosure vulnerabilities would also likely be utilized in orchestrating further attacks. Fixes which address this issue have been released. Contact the vendor for additional information. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/30148"&gt;http://www.securityfocus.com/bid/30148&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;4) IBM Maximo &amp;#39;debug.jsp&amp;#39; HTML Injection And Information Disclosure Vulnerabilities&lt;/p&gt;
&lt;p&gt;IBM Maximo is susceptible to an HTML Injection and information disclosure vulnerabilities. HTML Injection is used to add content into a web server’s response, which can then be used to steal cookie-based authentication credentials, execute arbitrary code in context of the site, or simply alter how the site appears.&amp;nbsp; Information obtained from the information disclosure vulnerabilities may aid in further attacks. A fix has not yet been released. Contact the vendor for additional information.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/30180"&gt;http://www.securityfocus.com/bid/30180&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;5) Adobe RoboHelp Server Help Errors Log SQL-Injection Vulnerability &lt;/p&gt;
&lt;p&gt;Adobe RoboHelp Server is susceptible to a SQL Injection vulnerability. SQL Injection can allow an attacker full access to a backend database, and in certain circumstances can be utilized to take complete control of a system. A fix which addresses this issue has been released. Contact the vendor for additional details. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/30137"&gt;http://www.securityfocus.com/bid/30137&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=83940" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/TopWebVulnerabilities/~4/341869574" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/ibm/default.aspx">ibm</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/xss/default.aspx">xss</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/sun/default.aspx">sun</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/xerox/default.aspx">xerox</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/web+application+vulnerabilities/default.aspx">web application vulnerabilities</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/html+injection/default.aspx">html injection</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/cross-site+scripting/default.aspx">cross-site scripting</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/SQL+Injection/default.aspx">SQL Injection</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/Top+Five+Web+Application+Vulnerabilities/default.aspx">Top Five Web Application Vulnerabilities</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/IBM+Maximo/default.aspx">IBM Maximo</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/Microsoft+Outlook+Web+Access+for+Exchange+Server/default.aspx">Microsoft Outlook Web Access for Exchange Server</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/Sun+Java+Web+Start/default.aspx">Sun Java Web Start</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/Xerox+CentreWare+Web/default.aspx">Xerox CentreWare Web</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/RoboHelp/default.aspx">RoboHelp</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/privilege+escalation/default.aspx">privilege escalation</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/information+disclosure/default.aspx">information disclosure</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/07/21/top-five-web-application-vulnerabilities-7-7-08-7-20-08.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities 6/23/08 - 7/06/08</title><link>http://feeds.feedburner.com/~r/TopWebVulnerabilities/~3/329185759/top-five-web-application-vulnerabilities-6-23-08-7-06-08.aspx</link><pubDate>Mon, 07 Jul 2008 20:43:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:83624</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/top5/rsscomments.aspx?PostID=83624</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/07/07/top-five-web-application-vulnerabilities-6-23-08-7-06-08.aspx#comments</comments><description>&lt;font size="3"&gt;&lt;font face="Calibri"&gt;1) Novell Groupwise WebAccess Simple Interface Cross-Site Scripting&lt;/font&gt;&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Novell Groupwise WebAccess is susceptible to a Cross-Site Scripting vulnerability. An attacker can leverage this issue to execute script code in the browsers of unsuspecting users in context of the affected application, possibly leading to theft of authentication credentials and other attacks.&amp;nbsp;A patch which addresses this issue has been released. Contact the vendor for additional details.&lt;/font&gt;&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;span class="MsoHyperlink"&gt;&lt;a href="http://secunia.com/advisories/30839"&gt;&lt;font face="Calibri" color="#800080" size="3"&gt;http://secunia.com/advisories/30839&lt;/font&gt;&lt;/a&gt;&lt;/span&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;2)&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;HP System Management Homepage (SMH) for Linux and Windows Cross-Site Scripting Vulnerability&lt;/font&gt;&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;HP System Management Homepage (SMH) is susceptible to a Cross-Site Scripting vulnerability. An attacker can leverage this issue to execute script code in the browsers of unsuspecting users in context of the affected application, possibly leading to theft of authentication credentials and other attacks. Fixes which address this issue have been released. Contact the vendor for further details.&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;span class="MsoHyperlink"&gt;&lt;a href="http://www.securityfocus.com/bid/30029"&gt;&lt;font face="Calibri" color="#800080" size="3"&gt;http://www.securityfocus.com/bid/30029&lt;/font&gt;&lt;/a&gt;&lt;/span&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;3) phpMyAdmin Cross-Site Scripting Vulnerabilities&lt;/font&gt;&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;phpMyAdmin is susceptible to multiple Cross-Site Scripting vulnerabilities. If successfully exploited, these vulnerabilities could allow an attacker to steal confidential information and cookie-based authentication credentials, and possibly lead to execution of arbitrary code in the browser of an unsuspecting user. &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;A fix for these issues has been released. Contact the vendor for more information.&lt;/font&gt;&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;span class="MsoHyperlink"&gt;&lt;a href="http://secunia.com/advisories/30813"&gt;&lt;font face="Calibri" color="#800080" size="3"&gt;http://secunia.com/advisories/30813&lt;/font&gt;&lt;/a&gt;&lt;/span&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;4) Drupal Taxonomy Autotagger SQL Injection and Script Insertion&lt;/font&gt;&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;span style="FONT-SIZE:11pt;FONT-FAMILY:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;mso-ascii-theme-font:minor-latin;mso-hansi-theme-font:minor-latin;"&gt;The Taxonomy Autotagger module for Drupal is susceptible to SQL Injection and Cross-Site Scripting vulnerabilities. If exploited, these vulnerabilities could lead to compromise of the application, the theft of confidential information and authentication credentials, or be utilized in conducting additional database attacks. &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;A fix for these issues has been released. Contact the vendor for further details. &lt;/span&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;a href="http://secunia.com/advisories/30933"&gt;&lt;font face="Calibri" color="#800080" size="3"&gt;http://secunia.com/advisories/30933&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;5)&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;Academic Web Tools SQL Injection and Cross-Site Scripting&lt;/font&gt;&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;span style="FONT-SIZE:11pt;FONT-FAMILY:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;mso-ascii-theme-font:minor-latin;mso-hansi-theme-font:minor-latin;"&gt;Academic Web Tools is susceptible to SQL Injection and Cross-Site Scripting attacks. &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;SQL Injection can allow an attacker full access to a backend database, and in certain circumstances can be utilized to take complete control of a system. The Cross-Site Scripting vulnerability can be exploited to execute code in the browser of an unsuspecting user and steal cookie-based authentication credentials. Fixes which address these issues have not yet been released. Contact the vendor for more details. &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="FONT-SIZE:11pt;FONT-FAMILY:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;mso-ascii-theme-font:minor-latin;mso-hansi-theme-font:minor-latin;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="MsoHyperlink"&gt;&lt;span style="COLOR:windowtext;"&gt;&lt;a href="http://secunia.com/advisories/30763"&gt;&lt;font face="Calibri" color="#800080" size="3"&gt;http://secunia.com/advisories/30763&lt;/font&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=83624" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/TopWebVulnerabilities/~4/329185759" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/top+five/default.aspx">top five</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/xss/default.aspx">xss</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/web+application+vulnerabilities/default.aspx">web application vulnerabilities</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/cross-site+scripting/default.aspx">cross-site scripting</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/novell/default.aspx">novell</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/SQL+Injection/default.aspx">SQL Injection</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/Top+Five+Web+Application+Vulnerabilities/default.aspx">Top Five Web Application Vulnerabilities</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/drupal/default.aspx">drupal</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/07/07/top-five-web-application-vulnerabilities-6-23-08-7-06-08.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities 6/09/08 - 6/22/08</title><link>http://feeds.feedburner.com/~r/TopWebVulnerabilities/~3/318350798/top-five-web-application-vulnerabilities-6-09-08-6-22-08.aspx</link><pubDate>Mon, 23 Jun 2008 20:15:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:83370</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/top5/rsscomments.aspx?PostID=83370</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/06/23/top-five-web-application-vulnerabilities-6-09-08-6-22-08.aspx#comments</comments><description>&lt;font size="3"&gt;&lt;font face="Calibri"&gt;1) IBM Workplace Unspecified Cross-Site Scripting Vulnerability&lt;/font&gt;&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;IBM Workplace for Business Controls and Reporting and IBM Workplace Web Content Management are susceptible to an unspecified instance of Cross-Site Scripting. An attacker can leverage this issue to execute script code in the browsers of unsuspecting users in context of the affected application, possibly leading to theft of authentication credentials and other attacks.&amp;nbsp;A fix has not yet been released. Contact the vendor for additional information.&lt;/font&gt;&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;a href="http://www.securityfocus.com/bid/29625"&gt;&lt;font face="Calibri" color="#800080" size="3"&gt;http://www.securityfocus.com/bid/29625&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&amp;nbsp; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;br /&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;2) PHP 5 &amp;#39;posix_access()&amp;#39; Function &amp;#39;safe_mode&amp;#39; Bypass Directory Traversal Vulnerability&lt;/font&gt;&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;PHP is susceptible to a directory traversal vulnerability. Attackers can leverage this vulnerability to bypass ‘safe mode’ security restrictions and access data outside of the web root, possibly gaining access to sensitive information which could lead to more dangerous attacks. A fix has not yet been released. Contact the vendor for further details.&lt;/font&gt;&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;a href="http://www.securityfocus.com/bid/29797"&gt;&lt;font face="Calibri" color="#800080" size="3"&gt;http://www.securityfocus.com/bid/29797&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&amp;nbsp;&amp;nbsp;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;3) Xerox WorkCentre Webserver Unspecified HTML Injection Vulnerability&lt;/font&gt;&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;span style="FONT-SIZE:11pt;FONT-FAMILY:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;mso-ascii-theme-font:minor-latin;mso-hansi-theme-font:minor-latin;"&gt;Xerox WorkCentre Webserver is susceptible to an unspecified HTML Injection vulnerability. HTML Injection is used to add content into a web server’s response, which can then be used to steal cookie-based authentication credentials, execute arbitrary code in context of the site, or simply alter how the site appears. &lt;/span&gt;&lt;span style="FONT-SIZE:11pt;FONT-FAMILY:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;mso-ascii-theme-font:minor-latin;mso-hansi-theme-font:minor-latin;mso-bidi-font-family:Arial;"&gt;U&lt;/span&gt;&lt;span style="FONT-SIZE:11pt;FONT-FAMILY:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;mso-ascii-theme-font:minor-latin;mso-hansi-theme-font:minor-latin;"&gt;pdates which address this issue have been released. Contact the vendor for more details.&lt;/span&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;a href="http://www.securityfocus.com/bid/29689"&gt;&lt;font face="Calibri" color="#800080" size="3"&gt;http://www.securityfocus.com/bid/29689&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&amp;nbsp; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;4) Novell eDirectory iMonitor Unspecified Cross-Site Scripting Vulnerability&lt;/font&gt;&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;The Novell eDirectory server iMonitor is susceptible to a instance of Cross-Site Scripting. If exploited, this vulnerability could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information. Updates which address this issue have been released. Contact the vendor for additional information. &lt;/font&gt;&lt;/font&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/b&gt;&lt;a href="http://www.securityfocus.com/bid/29782"&gt;&lt;font face="Calibri" color="#800080" size="3"&gt;http://www.securityfocus.com/bid/29782&lt;/font&gt;&lt;/a&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/b&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;/b&gt;&amp;nbsp; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;/b&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;5) DotNetNuke Prior to 4.8.4 Multiple HTML Injection and Cross-Site Scripting Vulnerabilities&lt;/font&gt;&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;DotNetNuke is susceptible to multiple vulnerabilities including HTML Injection and Cross-Site Scripting. &lt;span style="mso-bidi-font-family:Arial;mso-fareast-font-family:&amp;#39;Times New Roman&amp;#39;;"&gt;Successful exploitation of these vulnerabilities could be used to alter how the site appears, steal authentication credentials, or execute malicious scripts in the browsers of unsuspecting users.&amp;nbsp;Updates which resolve these issues have been released. Contact the vendor for further details.&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;a href="http://www.securityfocus.com/bid/29686"&gt;&lt;font face="Calibri" color="#800080" size="3"&gt;http://www.securityfocus.com/bid/29686&lt;/font&gt;&lt;/a&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=83370" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/TopWebVulnerabilities/~4/318350798" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/ibm/default.aspx">ibm</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/top+five/default.aspx">top five</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/xss/default.aspx">xss</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/xerox/default.aspx">xerox</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/web+application+vulnerabilities/default.aspx">web application vulnerabilities</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/php/default.aspx">php</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/html+injection/default.aspx">html injection</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/cross-site+scripting/default.aspx">cross-site scripting</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/novell/default.aspx">novell</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/06/23/top-five-web-application-vulnerabilities-6-09-08-6-22-08.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities 5/26/08 - 6/08/08</title><link>http://feeds.feedburner.com/~r/TopWebVulnerabilities/~3/308874089/top-five-web-application-vulnerabilities-5-26-08-6-08-08.aspx</link><pubDate>Tue, 10 Jun 2008 14:13:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:83195</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/top5/rsscomments.aspx?PostID=83195</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/06/10/top-five-web-application-vulnerabilities-5-26-08-6-08-08.aspx#comments</comments><description>&lt;p&gt;1) Apache Tomcat Host Manager Cross-Site Scripting Vulnerability&lt;/p&gt;
&lt;p&gt;Apache Tomcat Host Manager is susceptible to Cross-Site Scripting. If exploited, this vulnerability could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information. A fix is available in the SVN repository. Contact the vendor for more information.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/29502"&gt;http://www.securityfocus.com/bid/29502&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;2) Sun Java System Web Server Advanced Search Mechanism Cross-Site Scripting Vulnerability&lt;/p&gt;
&lt;p&gt;Sun Java System Web Server&amp;nbsp; is susceptible to Cross-Site Scripting. An attacker can leverage this issue to execute script code in the browsers of unsuspecting users in context of the affected application, possibly leading to theft of authentication credentials and other attacks. Fixes which resolve this issue have been released. Contact the vendor for additional information.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/29355"&gt;http://www.securityfocus.com/bid/29355&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;3) Xerox DocuShare Multiple Cross-Site Scripting Vulnerabilities&lt;/p&gt;
&lt;p&gt;Xerox DocuShare is susceptible to multiple instances of Cross-Site Scripting. If successfully exploited, these vulnerabilities could allow an attacker to steal confidential information and cookie-based authentication credentials, and possibly lead to execution of arbitrary code in the browser of an unsuspecting user. A vendor-supplied patch has not yet been released. Contact the vendor for additional details. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/29430"&gt;http://www.securityfocus.com/bid/29430&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;4) Mambo Multiple Vulnerabilities&lt;/p&gt;
&lt;p&gt;Mambo (prior to 4.6.4) is susceptible to multiple vulnerabilities including SQL Injection and HTTP Response Splitting. SQL Injection can give an attacker full access to a backend database, and in certain circumstances can be utilized to take complete control of a system. HTTP Response splitting can be used to break responses into multiple parts and conduct other types of attacks including Cross-Site Scripting and web cache poisoning. These issues have been resolved in Mambo 4.6.4. Contact the vendor for more details. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;a href="http://www.securityfocus.com/bid/29373"&gt;http://www.securityfocus.com/bid/29373&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;5) Sun Java ASP Server Multiple Directory Traversal Vulnerabilities&lt;/p&gt;
&lt;p&gt;Sun Java ASP Server is susceptible to multiple directory traversal vulnerabilities. Successful exploitation would give an attacker the means to view or delete arbitrary files with the privileges of the web server process. Information gained through these methods would likely lead to more damaging attacks. Fixes which resolve these vulnerabilities have been released. Contact the vendor for more details. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/29538"&gt;http://www.securityfocus.com/bid/29538&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=83195" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/TopWebVulnerabilities/~4/308874089" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/top+five/default.aspx">top five</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/xss/default.aspx">xss</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/apache/default.aspx">apache</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/mambo/default.aspx">mambo</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/sun/default.aspx">sun</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/directory+traversal/default.aspx">directory traversal</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/xerox/default.aspx">xerox</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/web+application+vulnerabilities/default.aspx">web application vulnerabilities</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/cross-site+scripting/default.aspx">cross-site scripting</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/06/10/top-five-web-application-vulnerabilities-5-26-08-6-08-08.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities 5/12/08 - 5/25/08</title><link>http://feeds.feedburner.com/~r/TopWebVulnerabilities/~3/304835108/top-five-web-application-vulnerabilities-5-12-08-5-25-08.aspx</link><pubDate>Wed, 04 Jun 2008 21:29:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:83142</guid><dc:creator>mark.painter</dc:creator><slash:comments>1</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/top5/rsscomments.aspx?PostID=83142</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/06/04/top-five-web-application-vulnerabilities-5-12-08-5-25-08.aspx#comments</comments><description>&lt;p&gt;1) Cisco User-Changeable Password (UCP) &amp;#39;CSuserCGI.exe&amp;#39; Multiple Remote Vulnerabilities&lt;/p&gt;
&lt;p&gt;Cisco User-Changeable Password (UCP) is susceptible to multiple remote issues including Cross-Site Scripting and buffer-overflows vulnerabilities.&amp;nbsp; If successfully exploited, the buffer overflows can be utilized to execute&amp;nbsp; code in context of the affected application and possibly facilitate the compromise of the affected system.&amp;nbsp; The Cross-Site Scripting vulnerability can be exploited to execute code in the browser of an unsuspecting user and steal cookie-based authentication credentials. These issues have been addressed in UCP 4.2. Contact the vendor for further details. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28222/discuss"&gt;http://www.securityfocus.com/bid/28222/discuss&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;2) SAP Web Application Server &amp;#39;/sap/bc/gui/sap/its/webgui/&amp;#39; Cross-Site Scripting Vulnerability&lt;/p&gt;
&lt;p&gt;SAP Web Application Server is susceptible to a Cross-Site Scripting vulnerability. If exploited, this vulnerability could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information. This issue has reportedly been resolved. Contact the vendor for additional details. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/29317"&gt;http://www.securityfocus.com/bid/29317&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;3) IBM Lotus Domino Web Server Unspecified Cross-Site Scripting Vulnerability&lt;/p&gt;
&lt;p&gt;IBM Lotus Domino Web Server is susceptible to a Cross-Site Scripting vulnerability. If successfully exploited, this vulnerability could allow an attacker to steal confidential information and cookie-based authentication credentials, and possibly lead to execution of arbitrary code in the browser of an unsuspecting user. Fixes have been released. Contact the vendor for more details.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/29311"&gt;http://www.securityfocus.com/bid/29311&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;4) IBM Lotus Quickr WYSIWYG Editors Unspecified Cross-Site Scripting Vulnerability&lt;/p&gt;
&lt;p&gt;IBM Lotus Quickr is susceptible to an unspecified Cross-Site Scripting vulnerability. Cross-Site Scripting is caused by insufficient filtration of user supplied input, and can be used to steal cookie based authentication credentials and conduct other attacks. Fixes which address this issue have been released. Contact the vendor for additional information. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/29175"&gt;http://www.securityfocus.com/bid/29175&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;5) Cisco BBSM Captive Portal Cross-Site Scripting&lt;/p&gt;
&lt;p&gt;Cisco BBSM (Building Broadband Service Manager) Captive Portal is susceptible to a Cross-Site Scripting vulnerability.&amp;nbsp; An attacker can leverage this issue to execute script code in the browsers of unsuspecting users in context of the affected application, possibly leading to theft of authentication credentials and other attacks.&amp;nbsp; An update which addresses this issue has been released. Contact the vendor for more information. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/29191"&gt;http://www.securityfocus.com/bid/29191&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=83142" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/TopWebVulnerabilities/~4/304835108" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/cisco/default.aspx">cisco</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/ibm/default.aspx">ibm</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/top+five/default.aspx">top five</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/xss/default.aspx">xss</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/lotus/default.aspx">lotus</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/sap/default.aspx">sap</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/top5/archive/tags/web+application+vulnerabilities/default.aspx">web application vulnerabilities</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/06/04/top-five-web-application-vulnerabilities-5-12-08-5-25-08.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities 4/28/08 - 5/11/08</title><link>http://feeds.feedburner.com/~r/TopWebVulnerabilities/~3/304816987/Top-Five-Web-Application-Vulnerabilities-4_2F00_28_2F00_08-_2D00_-5_2F00_11_2F00_08.aspx</link><pubDate>Mon, 12 May 2008 14:28:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:77188</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/top5/rsscomments.aspx?PostID=77188</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/05/12/Top-Five-Web-Application-Vulnerabilities-4_2F00_28_2F00_08-_2D00_-5_2F00_11_2F00_08.aspx#comments</comments><description>&lt;p&gt;1) SAP Internet Transaction Server Multiple Cross-Site Scripting Vulnerabilities&lt;/p&gt;&lt;p&gt;SAP Internet Transaction Server is susceptible to multiple instances of Cross-Site Scripting.&amp;nbsp; If exploited, these vulnerabilities could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information. A solution is reported to be available in SAP note 1052053. Contact the vendor for further details.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/29103"&gt;http://www.securityfocus.com/bid/29103&lt;/a&gt;&lt;/p&gt;&lt;p&gt;2) Sun Java System Web Server Search Module Cross-Site Scripting Vulnerability&lt;/p&gt;&lt;p&gt;Sun Java System Web Server Search Module is susceptible to a Cross-Site Scripting vulnerability. If successfully exploited, this vulnerability could allow an attacker to steal confidential information and cookie-based authentication credentials, and possibly lead to execution of arbitrary code in the browser of an unsuspecting user.&amp;nbsp; A fix has been released. Contact the vendor for additional information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/29087"&gt;http://www.securityfocus.com/bid/29087&lt;/a&gt;&lt;/p&gt;&lt;p&gt;3) Sun Java System Directory Proxy Server Remote Unauthorized Access Vulnerability&lt;/p&gt;&lt;p&gt;Sun Java System Directory Proxy Server is susceptible to a remote unauthorized access vulnerability. An attacker can leverage this vulnerability to gain administrative access to the affected server. An advisory and fixes for this issue have been released. Contact the vendor for more details.&amp;nbsp; &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28941/discuss"&gt;http://www.securityfocus.com/bid/28941/discuss&lt;/a&gt;&lt;/p&gt;&lt;p&gt;4) Sun Java System Application Server and Web Server JSP Information Disclosure Vulnerability&lt;/p&gt;&lt;p&gt;Sun Java System Application Server and Web Server are prone to an information-disclosure vulnerability. An attacker could leverage this issue to obtain sensitive information which could possibly be used to orchestrate more dangerous attacks. An advisory and updates which address this issue have been released. Contact the vendor for additional information. &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/29088"&gt;http://www.securityfocus.com/bid/29088&lt;/a&gt;&lt;/p&gt;&lt;p&gt;5) Zen Cart &amp;#39;keyword&amp;#39; parameter SQL Injection and Cross-Site Scripting Vulnerabilities&lt;/p&gt;&lt;p&gt;Zen Cart is susceptible to SQL Injection and Cross-Site Scripting vulnerabilities. If exploited, these vulnerabilities could lead to compromise of the application, the theft of confidential information and authentication credentials, or be utilized in conducting additional database attacks. A fix has not yet been released. Contact the vendor for more information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/29020"&gt;http://www.securityfocus.com/bid/29020&lt;/a&gt;&lt;/p&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=77188" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/TopWebVulnerabilities/~4/304816987" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/05/12/Top-Five-Web-Application-Vulnerabilities-4_2F00_28_2F00_08-_2D00_-5_2F00_11_2F00_08.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities 4/14/08 - 4/27/08</title><link>http://feeds.feedburner.com/~r/TopWebVulnerabilities/~3/304816988/Top-Five-Web-Application-Vulnerabilities-4_2F00_14_2F00_08-_2D00_-4_2F00_27_2F00_08.aspx</link><pubDate>Mon, 28 Apr 2008 16:08:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:76862</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/top5/rsscomments.aspx?PostID=76862</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/04/28/Top-Five-Web-Application-Vulnerabilities-4_2F00_14_2F00_08-_2D00_-4_2F00_27_2F00_08.aspx#comments</comments><description>&lt;p&gt;1) IBM Lotus Expeditor URI Handler Command Execution Vulnerability&lt;/p&gt;&lt;p&gt;IBM Lotus Expeditor is susceptible to a remote command-execution vulnerability because user-supplied input is not properly sanitized. Attackers who successfully exploit this issue can execute arbitrary commands in the context of victims who follow malicious URI&amp;#39;s.&amp;nbsp; A fix has not yet been released. Contact IBM for more information. &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28926"&gt;http://www.securityfocus.com/bid/28926&lt;/a&gt;&lt;/p&gt;&lt;p&gt;2) F5 Networks FirePass 4100 SSL VPN &amp;#39;installControl.php3&amp;#39; Cross-Site Scripting Vulnerability&lt;/p&gt;&lt;p&gt;F5 Networks FirePass 4100 SSL VPN is susceptible to a Cross-Site Scripting vulnerability. If exploited, this vulnerability could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information. An update which resolves this vulnerability has been released. Contact the vendor for additional details. &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28902"&gt;http://www.securityfocus.com/bid/28902&lt;/a&gt;&lt;/p&gt;&lt;p&gt;3) HP OpenView Network Node Manager Running Apache Multiple Vulnerabilities&lt;/p&gt;&lt;p&gt;HP OpenView Network Node Manager when running Apache is vulnerable to multiple vulnerabilities including Cross-Site Scripting and Denial-of Service attacks. If successfully exploited, these vulnerabilities could allow an attacker to steal confidential information and cookie-based authentication credentials,&amp;nbsp; possibly lead to execution of arbitrary code in the browser of an unsuspecting users, and be used to deny access to legitimate users. Patches which resolve these issues have been released. Contact the vendor for more details. &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/archive/1/491026"&gt;http://www.securityfocus.com/archive/1/491026&lt;/a&gt;&lt;/p&gt;&lt;p&gt;4) Novell GroupWise HTML Injection and Denial-of-Service Vulnerabilities&lt;/p&gt;&lt;p&gt;Novell GroupWise is susceptible to HTML Injection and Denial-of-Service vulnerabilities. HTML Injection can be leveraged to add content into a web server&amp;rsquo;s response, which can then be used to steal cookie-based authentication credentials, execute arbitrary code in context of the site, or simply alter how the site appears. Denial-of-Service attacks can be exploited to crash the application and deny access to legitimate users. A fix has not yet been released. Contact the vendor for additional information. &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28944"&gt;http://www.securityfocus.com/bid/28944&lt;/a&gt;&lt;/p&gt;&lt;p&gt;5) RSA Authentication Agent for Web URI Redirection Vulnerability&lt;/p&gt;&lt;p&gt;RSA Authentication Agent for Web is susceptible to a remote URI-redirection vulnerability because inadequate data sanitization is performed on user-supplied input. Exploitation of this vulnerability could aid in phishing-style attacks. RSA Authentication Agent for Web 5.3.3.378 resolves this issue. Contact the vendor for specific upgrade information. &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28907"&gt;http://www.securityfocus.com/bid/28907&lt;/a&gt;&lt;/p&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=76862" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/TopWebVulnerabilities/~4/304816988" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/04/28/Top-Five-Web-Application-Vulnerabilities-4_2F00_14_2F00_08-_2D00_-4_2F00_27_2F00_08.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities  3/31/08 - 4/13/08</title><link>http://feeds.feedburner.com/~r/TopWebVulnerabilities/~3/304816989/Top-Five-Web-Application-Vulnerabilities--3_2F00_31_2F00_08-_2D00_-4_2F00_13_2F00_08.aspx</link><pubDate>Mon, 14 Apr 2008 17:16:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:76514</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/top5/rsscomments.aspx?PostID=76514</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/04/14/Top-Five-Web-Application-Vulnerabilities--3_2F00_31_2F00_08-_2D00_-4_2F00_13_2F00_08.aspx#comments</comments><description>&lt;p&gt;1) F5 BIG-IP Web Management Interface &amp;#39;NEW_VALUE&amp;#39; Parameter Remote Code Injection Vulnerability&lt;/p&gt;&lt;p&gt;F5 BIG-IP Web Management Interface is susceptible to a remote code injection vulnerability. Attackers who successfully exploit this vulnerability could execute arbitrary code with the privileges of the user of the affected application. A fix has not yet been released. Contact the vendor for additional information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28639/"&gt;http://www.securityfocus.com/bid/28639/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;2) Cisco Unified Communication Manager Multiple Vulnerabilities&lt;/p&gt;&lt;p&gt;Cisco Unified Communication Manager is susceptible to multiple remote vulnerabilities including instances of SQL Injection, information disclosure, and unauthorized access. If exploited, these vulnerabilities could lead to compromise of the application, leveraged to gain unauthorized application access, or utilized to obtain sensitive information. A fix has not yet been released. Contact Cisco for further details.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28690"&gt;http://www.securityfocus.com/bid/28690&lt;/a&gt;&lt;/p&gt;&lt;p&gt;3) Drupal Menu System Security Bypass Vulnerabilities&lt;/p&gt;&lt;p&gt;Drupal is susceptible to multiple security-bypass vulnerabilities via the menu system because the application fails to properly control access to certain pages. Successful exploitation would give an attacker access to sensitive information which could likely be utilized in orchestrating more damaging attacks. Updates which resolve these issues have been released. Contact the vendor for more information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28714"&gt;http://www.securityfocus.com/bid/28714&lt;/a&gt;&lt;/p&gt;&lt;p&gt;4) Microsoft SharePoint Server Picture Source HTML Injection Vulnerability&lt;/p&gt;&lt;p&gt;Microsoft SharePoint Server is susceptible to an HTML Injection vulnerability. HTML Injection is used to add content into a web server&amp;rsquo;s response, which can then be used to steal cookie-based authentication credentials, execute arbitrary code in context of the site, or simply alter how the site appears. An attacker needs to utilize a user account with page editing privileges to successfully exploit this vulnerability. A fix has not yet been released. Contact Microsoft for additional details.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28706"&gt;http://www.securityfocus.com/bid/28706&lt;/a&gt;&lt;/p&gt;&lt;p&gt;5) SAP NetWeaver Filesystem Feedbacks Cross-Site Scripting Vulnerability&lt;/p&gt;&lt;p&gt;SAP NetWeaver is susceptible to a Cross-Site Scripting vulnerability. If exploited, this vulnerability could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information.&amp;nbsp; Note that this issue can be resolved by activating &amp;#39;Secure Editing&amp;#39; in the Portal. Contact the vendor for more information.&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28699"&gt;http://www.securityfocus.com/bid/28699&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=76514" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/TopWebVulnerabilities/~4/304816989" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/04/14/Top-Five-Web-Application-Vulnerabilities--3_2F00_31_2F00_08-_2D00_-4_2F00_13_2F00_08.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities 3/17/08 - 3/30/08</title><link>http://feeds.feedburner.com/~r/TopWebVulnerabilities/~3/304816990/Top-Five-Web-Application-Vulnerabilities-3_2F00_17_2F00_08-_2D00_-3_2F00_30_2F00_08.aspx</link><pubDate>Tue, 01 Apr 2008 17:03:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:75810</guid><dc:creator>mark.painter</dc:creator><slash:comments>1</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/top5/rsscomments.aspx?PostID=75810</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/04/01/Top-Five-Web-Application-Vulnerabilities-3_2F00_17_2F00_08-_2D00_-3_2F00_30_2F00_08.aspx#comments</comments><description>&lt;p&gt;1) Webutil &amp;#39;webutil.pl&amp;#39; Multiple Remote Command Execution Vulnerabilities&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Webutil is susceptible to multiple command execution vulnerabilities which remote attackers can leverage to execute arbitrary commands. Successful exploitation can lead to a complete compromise of the affected application and underlying system. A fix has not yet been released. Contact the vendor for additional details.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28393"&gt;http://www.securityfocus.com/bid/28393&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;2) IBM Rational ClearQuest Multiple Parameters Multiple Cross-Site Scripting Vulnerabilities&lt;br /&gt;&amp;nbsp;&lt;br /&gt;IBM Rational ClearQuest is susceptible to multiple instances of Cross-Site Scripting. If successfully exploited, these vulnerabilities could allow an attacker to steal confidential information and cookie-based authentication credentials, and possibly lead to execution of arbitrary code in the browser of an unsuspecting user. Patches which resolve these issues have been released. Contact IBM for further information.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28296"&gt;http://www.securityfocus.com/bid/28296&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;3) Imperva SecureSphere Cross-Site Scripting Vulnerability&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Imperva SecureSphere is susceptible to a Cross-Site Scripting vulnerability. If exploited, this vulnerability could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information. An update which addresses this issue has been released. Contact the vendor for additional details. &lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28279"&gt;http://www.securityfocus.com/bid/28279&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;4) Joomla! and Mambo Components Multiple SQL Injection Vulnerabilities&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Multiple Joomla! and Mambo components are susceptible to SQL Injection vulnerabilities. SQL Injection can give an attacker full access to a backend database, and in certain circumstances can be utilized to take complete control of a system. No fixes have yet been released. Contact the vendor for more information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28271"&gt;http://www.securityfocus.com/bid/28271&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28305"&gt;http://www.securityfocus.com/bid/28305&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28331"&gt;http://www.securityfocus.com/bid/28331&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28325"&gt;http://www.securityfocus.com/bid/28325&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28324"&gt;http://www.securityfocus.com/bid/28324&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28361"&gt;http://www.securityfocus.com/bid/28361&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28427"&gt;http://www.securityfocus.com/bid/28427&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28422"&gt;http://www.securityfocus.com/bid/28422&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28428"&gt;http://www.securityfocus.com/bid/28428&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28409"&gt;http://www.securityfocus.com/bid/28409&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28443"&gt;http://www.securityfocus.com/bid/28443&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28496"&gt;http://www.securityfocus.com/bid/28496&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;5) PHP-Nuke Platinum &amp;#39;dynamic_titles.php&amp;#39; SQL Injection Vulnerability&lt;br /&gt;&amp;nbsp;&lt;br /&gt;PHP-Nuke Platinum is susceptible to a SQL Injection vulnerability. Successful exploitation could give an attacker the means to access or modify backend database contents, or in some circumstances be utilized to take control of the server hosting the database. A fix has not yet been released. Contact the vendor for further details. &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28410"&gt;http://www.securityfocus.com/bid/28410&lt;/a&gt;&lt;/p&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=75810" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/TopWebVulnerabilities/~4/304816990" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/04/01/Top-Five-Web-Application-Vulnerabilities-3_2F00_17_2F00_08-_2D00_-3_2F00_30_2F00_08.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities 3/3/08 - 3/16/08</title><link>http://feeds.feedburner.com/~r/TopWebVulnerabilities/~3/304816991/Top-Five-Web-Application-Vulnerabilities-3_2F00_3_2F00_08-_2D00_-3_2F00_16_2F00_08.aspx</link><pubDate>Mon, 17 Mar 2008 16:52:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:75328</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/top5/rsscomments.aspx?PostID=75328</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/03/17/Top-Five-Web-Application-Vulnerabilities-3_2F00_3_2F00_08-_2D00_-3_2F00_16_2F00_08.aspx#comments</comments><description>&lt;span class="433285215-17032008"&gt;&lt;p&gt;1) Dokeos Multiple Remote Code Execution and Cross-Site Scripting Vulnerabilities&lt;/p&gt;&lt;p&gt;Dokeos is susceptible to multiple remote code execution and Cross-Site Scripting vulnerabilities. Exploitation of these vulnerabilities could lead to a complete compromise of the affected application and underlying system, and also be used to steal cookie based authentication credentials. Dokeos 1.8.4 SP3 has been released to address these issues. Contact the vendor for further information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28121"&gt;http://www.securityfocus.com/bid/28121&lt;/a&gt;&lt;/p&gt;&lt;p&gt;2) Adobe ColdFusion Multiple Cross-Site Scripting Vulnerabilities&lt;/p&gt;&lt;p&gt;Adobe ColdFusion is susceptible to multiple instances of Cross-Site Scripting. If successfully exploited, these vulnerabilities could allow an attacker to steal confidential information and cookie-based authentication credentials, and possibly lead to execution of arbitrary code in the browser of an unsuspecting user. Adobe has released advisory APSB08-06 and APSB08-07 to address these issues. Contact the vendor for additional details. &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28205"&gt;http://www.securityfocus.com/bid/28205&lt;/a&gt;&lt;/p&gt;&lt;p&gt;3) F5 BIG-IP Web Management Interface Console HTML Injection Vulnerability&lt;/p&gt;&lt;p&gt;F5 BIG-IP is susceptible to an HTML Injection vulnerability. When exploited, this vulnerability will allow an attacker to execute arbitrary script code in the browser of an unsuspecting victim in context of the affected device. This could possibly lead to theft of cookie-based authentication credentials or be utilized to launch other attacks. A fix has not yet been released. Contact the vendor for more information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28151"&gt;http://www.securityfocus.com/bid/28151&lt;/a&gt;&lt;/p&gt;&lt;p&gt;4) Adobe LiveCycle Workflow Management Login Page Cross-Site Scripting Vulnerability&lt;/p&gt;&lt;p&gt;Adobe LiveCycle Workflow is susceptible to a Cross-Site Scripting vulnerability. If exploited, this vulnerability could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information. Adobe has released advisory APSB0-10 to address this issue. Contact the vendor for further details.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28209/"&gt;http://www.securityfocus.com/bid/28209/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;5) Ruby WEBrick Remote Directory Traversal and Information Disclosure Vulnerabilities&lt;/p&gt;&lt;p&gt;Ruby WEBrick is susceptible to directory traversal and information disclosure vulnerabilities. Remote attackers can leverage these vulnerabilities to access the contents of arbitrary files, gathering information which will likely be utilized in orchestrating more dangerous attacks. Fixes which resolve these issues have been released. Contact the vendor for additional details.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28123/"&gt;http://www.securityfocus.com/bid/28123/&lt;/a&gt;&lt;/p&gt;&lt;/span&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=75328" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/TopWebVulnerabilities/~4/304816991" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/03/17/Top-Five-Web-Application-Vulnerabilities-3_2F00_3_2F00_08-_2D00_-3_2F00_16_2F00_08.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities 2/18/2008 - 3/02/2008</title><link>http://feeds.feedburner.com/~r/TopWebVulnerabilities/~3/304816992/Top-Five-Web-Application-Vulnerabilities-2_2F00_18_2F00_2008-_2D00_-3_2F00_02_2F00_2008.aspx</link><pubDate>Mon, 03 Mar 2008 17:21:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:74845</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/top5/rsscomments.aspx?PostID=74845</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/03/03/Top-Five-Web-Application-Vulnerabilities-2_2F00_18_2F00_2008-_2D00_-3_2F00_02_2F00_2008.aspx#comments</comments><description>&lt;p&gt;1) IBM Lotus QuickPlace &amp;#39;Main.nsf&amp;#39; Cross-Site Scripting Vulnerability&lt;br /&gt;&amp;nbsp;&lt;br /&gt;IBM Lotus QuickPlace is susceptible to a Cross-Site Scripting vulnerability.&amp;nbsp; If exploited, this vulnerability could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information. A fix has not yet been released. Contact IBM for additional details. &lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27871"&gt;http://www.securityfocus.com/bid/27871&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;2) PHP Nuke Multiple Modules SQL Injection&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Multiple PHP Nuke modules contain SQL Injection vulnerabilities. Successful exploitation could give an attacker the means to access or modify backend database contents, or in some circumstances be utilized to take control of the server hosting the database. No fixes have yet to be released. Contact the vendor for further information.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27863"&gt;http://www.securityfocus.com/bid/27863&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27879"&gt;http://www.securityfocus.com/bid/27879&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27894"&gt;http://www.securityfocus.com/bid/27894&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27897"&gt;http://www.securityfocus.com/bid/27897&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27909"&gt;http://www.securityfocus.com/bid/27909&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27912"&gt;http://www.securityfocus.com/bid/27912&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27886"&gt;http://www.securityfocus.com/bid/27886&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27932"&gt;http://www.securityfocus.com/bid/27932&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27930"&gt;http://www.securityfocus.com/bid/27930&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27930"&gt;http://www.securityfocus.com/bid/27930&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27930"&gt;http://www.securityfocus.com/bid/27930&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27952"&gt;http://www.securityfocus.com/bid/27952&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27958"&gt;http://www.securityfocus.com/bid/27958&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27955"&gt;http://www.securityfocus.com/bid/27955&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27957"&gt;http://www.securityfocus.com/bid/27957&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27980"&gt;http://www.securityfocus.com/bid/27980&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27991"&gt;http://www.securityfocus.com/bid/27991&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28030"&gt;http://www.securityfocus.com/bid/28030&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28063"&gt;http://www.securityfocus.com/bid/28063&lt;/a&gt;&lt;/p&gt;&lt;p&gt;3) Joomla! and Mambo Components Multiple SQL Injection Vulnerabilities&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Multiple Joomla! and Mambo components are susceptible to SQL Injection vulnerabilities. SQL Injection can give an attacker full access to a backend database, and in certain circumstances can be utilized to take complete control of a system. No fixes have yet been released. Contact the vendor for more information.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27849"&gt;http://www.securityfocus.com/bid/27849&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27860"&gt;http://www.securityfocus.com/bid/27860&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27864"&gt;http://www.securityfocus.com/bid/27864&lt;/a&gt; &lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27883"&gt;http://www.securityfocus.com/bid/27883&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27884"&gt;http://www.securityfocus.com/bid/27884&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27887"&gt;http://www.securityfocus.com/bid/27887&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27888"&gt;http://www.securityfocus.com/bid/27888&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27898"&gt;http://www.securityfocus.com/bid/27898&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27921"&gt;http://www.securityfocus.com/bid/27921&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27922"&gt;http://www.securityfocus.com/bid/27922&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27923"&gt;http://www.securityfocus.com/bid/27923&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27926"&gt;http://www.securityfocus.com/bid/27926&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27956"&gt;http://www.securityfocus.com/bid/27956&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27970"&gt;http://www.securityfocus.com/bid/27970&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27975"&gt;http://www.securityfocus.com/bid/27975&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27971"&gt;http://www.securityfocus.com/bid/27971&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27994"&gt;http://www.securityfocus.com/bid/27994&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28018"&gt;http://www.securityfocus.com/bid/28018&lt;/a&gt;&lt;/p&gt;&lt;p&gt;4) Spyce Sample Scripts Multiple Input Validation Vulnerabilities&lt;/p&gt;&lt;p&gt;Spyce Sample Scripts are susceptible to multiple input validation vulnerabilities including Cross-Site Scripting and Path Disclosure. An attacker could possibly execute arbitrary script code in the browser of an unsuspecting user in context of the affected site, and could also retrieve the server&amp;#39;s web root path. A fix has not yet been released. Contact the vendor for more details. &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/27898"&gt;http://www.securityfocus.com/bid/27898&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;5) Drupal Multiple HTML Injection Vulnerabilities&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Drupal is susceptible to multiple HTML Injection vulnerabilities. HTML Injection can be leveraged to add content into a web server&amp;rsquo;s response, which can then be used to steal cookie-based authentication credentials, execute arbitrary code in context of the site, or simply alter how the site appears. An update that addresses these issues has been released. Contact the vendor further details.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28026"&gt;http://www.securityfocus.com/bid/28026&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=74845" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/TopWebVulnerabilities/~4/304816992" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/03/03/Top-Five-Web-Application-Vulnerabilities-2_2F00_18_2F00_2008-_2D00_-3_2F00_02_2F00_2008.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities 2/4/2008 - 2/17/2008</title><link>http://feeds.feedburner.com/~r/TopWebVulnerabilities/~3/304816993/Top-Five-Web-Application-Vulnerabilities-2_2F00_4_2F00_2008-_2D00_-2_2F00_17_2F00_2008.aspx</link><pubDate>Tue, 19 Feb 2008 16:43:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:74312</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/top5/rsscomments.aspx?PostID=74312</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/02/19/Top-Five-Web-Application-Vulnerabilities-2_2F00_4_2F00_2008-_2D00_-2_2F00_17_2F00_2008.aspx#comments</comments><description>&lt;font size="2"&gt;&lt;p&gt;1) Microsoft Internet Information Services ASP Remote Code-Execution Vulnerability&lt;/p&gt;&lt;p&gt;IIS is susceptible to a remote code-execution vulnerability that can be exploited via malicious input to vulnerable ASP pages. Attackers who successfully exploit this vulnerability could execute arbitrary code in context of the Worker Process Identity, which has Network Services privileges by default. Security bulletins which resolve this issue have been released for both IIS 5.1 and 6.0. Contact Microsoft for additional details.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/27676/"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27676/&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;&lt;/font&gt;&lt;font size="2"&gt;&lt;p&gt;2) WordPress &amp;#39;wp-admin/options.php&amp;#39; Remote Code-Execution Vulnerability&lt;/p&gt;&lt;p&gt;WordPress is susceptible to a remote code-execution vulnerability due to a failure of the application to properly sanitize data. A remote attacker can leverage this vulnerability to execute arbitrary PHP code in context of the application, possibly leading to a complete compromise of the affected system. WordPress MU 1.3.2 has been released to correct this issue. Contact WordPress for further information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/27633/"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27633/&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;&lt;/font&gt;&lt;font size="2"&gt;&lt;p&gt;3) Cisco Unified Communications Manager &amp;#39;key&amp;#39; Parameter SQL Injection Vulnerability&lt;/p&gt;&lt;p&gt;Cisco Unified Communications Manager is susceptible to a SQL Injection vulnerability. Successful exploitation could give an attacker the means to access or modify backend database contents, or in some circumstances be utilized to take control of the server hosting the database. An advisory which addresses this issue has been released. Contact Cisco for more information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/27775"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27775&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;&lt;/font&gt;&lt;font size="2"&gt;&lt;p&gt;4) IBM Lotus Quickr Unspecified Cross-Site Scripting Vulnerability&lt;/p&gt;&lt;p&gt;IBM Lotus Quickr is susceptible to a Cross-Site Scripting vulnerability. Successful exploitation of Cross-Site Scripting could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information. Fixes which address this issue have been released. Contact IBM for additional details.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27840"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27840&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;5) Joomla! and Mambo Components Multiple SQL Injection Vulnerabilities &lt;/font&gt;&lt;/p&gt;&lt;p&gt;Multiple Joomla! and Mambo components are susceptible to SQL Injection vulnerabilities. SQL Injection can give an attacker full access to a backend database, and in certain circumstances can be utilized to take complete control of a system. No fixes have yet been released. Contact the vendor for more information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/27609"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27609&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27617"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27617&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27648"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27648&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27649"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27649&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27673"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27673&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27679"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27679&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27691"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27691&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27692"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27692&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27695"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27695&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27731"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27731&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27748"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27748&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27783"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27783&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27780"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27780&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;font size="2"&gt; (Joomla! only)&lt;br /&gt;&lt;/font&gt;&lt;a href="http://www.securityfocus.com/bid/27781"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27781&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27784"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27784&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27842"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27842&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27808"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27808&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27805"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27805&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;font size="2"&gt; (Joomla! only)&lt;br /&gt;&lt;/font&gt;&lt;a href="http://www.securityfocus.com/bid/27818"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27818&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27820"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27820&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27822"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27822&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27821"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27821&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;&lt;/font&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=74312" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/TopWebVulnerabilities/~4/304816993" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/02/19/Top-Five-Web-Application-Vulnerabilities-2_2F00_4_2F00_2008-_2D00_-2_2F00_17_2F00_2008.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities 1/19/08 - 2/03/08</title><link>http://feeds.feedburner.com/~r/TopWebVulnerabilities/~3/304816994/Top-Five-Web-Application-Vulnerabilities-1_2F00_19_2F00_08-_2D00_-2_2F00_03_2F00_0.aspx</link><pubDate>Mon, 04 Feb 2008 17:18:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:73908</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/top5/rsscomments.aspx?PostID=73908</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/02/04/Top-Five-Web-Application-Vulnerabilities-1_2F00_19_2F00_08-_2D00_-2_2F00_03_2F00_0.aspx#comments</comments><description>&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;1) Coppermine Photo Gallery Multiple Remote Command Execution Vulnerabilities&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;br /&gt;Coppermine Photo Gallery&amp;nbsp;is susceptible to multiple remote command execution vulnerabilties. &lt;font size="2"&gt;Remote attackers can exploit this vulnerability to execute arbitrary commands with the privileges of the affected application, possibly leading to compromise of the application and the underlying web server.&amp;nbsp; Coppermine Photo Gallery 1.4.15 has been released to resolve these and other issues. Contact the vendor for additonal information.&amp;nbsp;&lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27512" title="http://www.securityfocus.com/bid/27512"&gt;http://www.securityfocus.com/bid/27512&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;2) PHP-Nuke Search Module &amp;#39;sid&amp;#39; Parameter SQL Injection Vulnerability&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;PHP-Nuke is susceptible to a SQL Injection vulnerability. S&lt;font size="2"&gt;QL Injection can allow an attacker full access to a backend database, and in certain circumstances can be utilized to take complete control of a system. A fix has not yet been released. Contact the vendor for further details.&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;font size="2"&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27408" title="http://www.securityfocus.com/bid/27408"&gt;http://www.securityfocus.com/bid/27408&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;3)&amp;nbsp;Novell GroupWise WebAccess Multiple Cross-Site Scripting Vulnerabilities&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;Novell GroupWise WebAccess is susceptible to multiple instances of Cross-Site Scripting. I&lt;font size="2"&gt;f successful, Cross-Site Scripting vulnerabilities can be exploited to manipulate or steal cookies, create requests that can be mistaken for those of a valid user, compromise confidential information, or execute malicious code on end user systems. Fixes which address these issues have been released. Contact the vendor for more details.&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;font size="2"&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27582" title="http://www.securityfocus.com/bid/27582"&gt;http://www.securityfocus.com/bid/27582&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;4) WordPress Plug-ins Multiple Vulnerabilities&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;Several WordPress plug-ins are susceptible to vulnerabilities including SQL Injection and Cross-Site Scripting. &lt;font size="2"&gt;If successfully exploited, these vulnerabilities could allow an attacker to steal confidential information and cookie-based authentication credentials, and possibly lead to execution of arbitrary code in the browser of an unsuspecting user. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;font size="2"&gt;No upgrade or patch has yet been released to resolve these issues. &lt;/font&gt;Contact the vendor for additional information. &lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;p&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27525" title="http://www.securityfocus.com/bid/27525"&gt;http://www.securityfocus.com/bid/27525&lt;br /&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27504" title="http://www.securityfocus.com/bid/27504"&gt;http://www.securityfocus.com/bid/27504&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;/a&gt;&lt;a href="http://www.securityfocus.com/bid/27504" title="http://www.securityfocus.com/bid/27504"&gt;http://www.securityfocus.com/bid/27504&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27504" title="http://www.securityfocus.com/bid/27504"&gt;http://www.securityfocus.com/bid/27504&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27504" title="http://www.securityfocus.com/bid/27504"&gt;http://www.securityfocus.com/bid/27504&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27504" title="http://www.securityfocus.com/bid/27504"&gt;http://www.securityfocus.com/bid/27504&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27504" title="http://www.securityfocus.com/bid/27504"&gt;http://www.securityfocus.com/bid/27504&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27504" title="http://www.securityfocus.com/bid/27504"&gt;http://www.securityfocus.com/bid/27504&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27504" title="http://www.securityfocus.com/bid/27504"&gt;http://www.securityfocus.com/bid/27504&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27464" title="http://www.securityfocus.com/bid/27464"&gt;http://www.securityfocus.com/bid/27464&lt;br /&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27362" title="http://www.securityfocus.com/bid/27362"&gt;http://www.securityfocus.com/bid/27362&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;/a&gt;&lt;a href="http://www.securityfocus.com/bid/27362" title="http://www.securityfocus.com/bid/27362"&gt;http://www.securityfocus.com/bid/27362&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27362" title="http://www.securityfocus.com/bid/27362"&gt;http://www.securityfocus.com/bid/27362&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27362" title="http://www.securityfocus.com/bid/27362"&gt;http://www.securityfocus.com/bid/27362&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27362" title="http://www.securityfocus.com/bid/27362"&gt;http://www.securityfocus.com/bid/27362&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27362" title="http://www.securityfocus.com/bid/27362"&gt;http://www.securityfocus.com/bid/27362&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27362" title="http://www.securityfocus.com/bid/27362"&gt;http://www.securityfocus.com/bid/27362&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27362" title="http://www.securityfocus.com/bid/27362"&gt;http://www.securityfocus.com/bid/27362&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;5) Drupal Modules Multiple Vulnerabilities&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;Several Drupal&amp;nbsp;modules are&amp;nbsp;susceptible to&amp;nbsp;vulnerabilities including Authentication Bypass, Cross-Site Scripting, and HTML Injection. Successful exploitation can lead to escalation of&amp;nbsp;privileges, alter how the site appears, steal authentication credentials, or execute malicious scripts in the browsers of unsuspecting users.&amp;nbsp;Upgrades which resolve these issues have been released. Contact the vendor for further information.&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27545" title="http://www.securityfocus.com/bid/27545"&gt;http://www.securityfocus.com/bid/27545&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27544" title="http://www.securityfocus.com/bid/27544"&gt;http://www.securityfocus.com/bid/27544&lt;/a&gt; &lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27543" title="http://www.securityfocus.com/bid/27543"&gt;http://www.securityfocus.com/bid/27543&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27444" title="http://www.securityfocus.com/bid/27444"&gt;http://www.securityfocus.com/bid/27444&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27436" title="http://www.securityfocus.com/bid/27436"&gt;http://www.securityfocus.com/bid/27436&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=73908" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/TopWebVulnerabilities/~4/304816994" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2008/02/04/Top-Five-Web-Application-Vulnerabilities-1_2F00_19_2F00_08-_2D00_-2_2F00_03_2F00_0.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities 7/30/07 - 8/12/07</title><link>http://feeds.feedburner.com/~r/TopWebVulnerabilities/~3/304816995/Top-Five-Web-Application-Vulnerabilities-7_2F00_30_2F00_07-_2D00_-8_2F00_12_2F00_07.aspx</link><pubDate>Wed, 15 Aug 2007 10:33:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:68561</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/top5/rsscomments.aspx?PostID=68561</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2007/08/15/Top-Five-Web-Application-Vulnerabilities-7_2F00_30_2F00_07-_2D00_-8_2F00_12_2F00_07.aspx#comments</comments><description>&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;1) Help Center Live Administration Multiple Security Bypass Vulnerabilities&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;br /&gt;Help Center Live is susceptible to multiple administration bypass security vulnerabilities. An attacker who leverages these vulnerabilities could gain unauthorized access to administrative pages and compromise the vulnerable application. A fix has not yet been released. Contact the vendor for additional information. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/25225"&gt;http://www.securityfocus.com/bid/25225&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;2)&lt;/span&gt;&lt;font face="Times New Roman" size="3"&gt; &lt;/font&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;FrontAccounting Config.PHP Remote File Include Vulnerability&lt;br /&gt;&lt;br /&gt;FrontAccounting is susceptible to a remote file-include vulnerability. An attacker could conceivably exploit this vulnerability to compromise the application and underlying system. Other attacks are likely possible. A fix has not yet been released. Contact the vendor for more information.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/25229"&gt;http://www.securityfocus.com/bid/25229&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;br /&gt;3)&lt;/span&gt;&lt;font face="Times New Roman" size="3"&gt; &lt;/font&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;Sun Java System Web Server Multiple HTTP Redirect Vulnerabilities&lt;br /&gt;&lt;br /&gt;Sun Java System Web Server is susceptible to multiple HTTP redirect vulnerabilities including HTTP-response splitting and HTTP-header injection. Exploitation could give an attacker the means to inject arbitrary cookie attributes into a session cookie and launch attacks on active web sessions, or to misrepresent how web content is served, cached, or interpreted. Service packs and updates have been released to address these issues. Contact the vendor for further details. &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/25190/"&gt;http://www.securityfocus.com/bid/25190/&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;br /&gt;4) Apache Tomcat Error Message Reporting Cross-Site Scripting Vulnerability&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;Apache Tomcat is susceptible to a Cross-Site Scripting vulnerability. If exploited, this vulnerability could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information. An update which addresses this issue has been released. Contact the vendor for additional details. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/25174"&gt;http://www.securityfocus.com/bid/25174&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;5) Novell GroupWise WebAccess User.Id Parameter Cross-Site Scripting Vulnerability&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 12pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;br /&gt;Novell GroupWise WebAccess is susceptible to a Cross-Site Scripting vulnerability. If successful, Cross-Site Scripting vulnerabilities can be exploited to manipulate or steal cookies, create requests that can be mistaken for those of a valid user, compromise confidential information, or execute malicious code on end user systems. A fix has not yet been released. Contact the vendor for additional information.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-size:10pt;color:navy;font-family:Arial;"&gt;&lt;a href="http://www.securityfocus.com/bid/25126"&gt;http://www.securityfocus.com/bid/25126&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=68561" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/TopWebVulnerabilities/~4/304816995" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2007/08/15/Top-Five-Web-Application-Vulnerabilities-7_2F00_30_2F00_07-_2D00_-8_2F00_12_2F00_07.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities 7/14/07 - 7/29/07</title><link>http://feeds.feedburner.com/~r/TopWebVulnerabilities/~3/304816996/Top-Five-Web-Application-Vulnerabilities-7_2F00_14_2F00_07-_2D00_-7_2F00_29_2F00_07.aspx</link><pubDate>Tue, 31 Jul 2007 10:34:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:68143</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/top5/rsscomments.aspx?PostID=68143</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2007/07/31/Top-Five-Web-Application-Vulnerabilities-7_2F00_14_2F00_07-_2D00_-7_2F00_29_2F00_07.aspx#comments</comments><description>&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;a href="http://www.securityfocus.com/bid/24999/"&gt;&lt;/a&gt;&lt;div class="Section1"&gt;&lt;p class="MsoNormal" style="margin-left:0.25in;"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;1) Joomla! Search Component Remote Command Execution Vulnerability&lt;br /&gt;&lt;br /&gt;Joomla is susceptible to a remote command execution vulnerability. Remote attackers can exploit this vulnerability to execute arbitrary commands with the privileges of the affected application, possibly leading to compromise of the application and the underlying web server. Other attacks are also likely. A fix has been released. Contact the vendor for further details.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/24997" title="http://www.securityfocus.com/bid/24997"&gt;http://www.securityfocus.com/bid/24997&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:0.25in;"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;br /&gt;2) Sun Java System Application Server JSP Source Code Disclosure Vulnerability&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:0.25in;"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:0.25in;"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;Sun Java System Application Server on Microsoft Windows is susceptible to a remote vulnerability that could allow attackers to obtain sensitive JSP source code, which would likely aid in conducting more dangerous attacks. An alert and fixes which address this issue have been released. Contact the vendor for additional information.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/25058" title="http://www.securityfocus.com/bid/25058"&gt;http://www.securityfocus.com/bid/25058&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;3)&lt;/span&gt;&lt;/font&gt; &lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;Trend Micro OfficeScan Management Console Authentication Bypass Vulnerability&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:0.25in;"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:0.25in;"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;Trend Micro OfficeScan is susceptible to an authentication bypass vulnerability. An attacker could exploit this vulnerability to gain unauthorized access to the web-based management console. Successful exploitation will compromise the application. Fixes which address this issue have been released. Contact the vendor for further information.&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:0.25in;"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:0.25in;"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;a href="http://www.securityfocus.com/bid/24935/" title="http://www.securityfocus.com/bid/24935/"&gt;http://www.securityfocus.com/bid/24935/&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:0.25in;"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:0.25in;"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;4) Apache Tomcat SendMailServlet Cross-Site Scripting Vulnerability&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:0.25in;"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:0.25in;"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;Apache Tomcat is susceptible to a Cross-Site Scripting vulnerability. If exploited, this vulnerability could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information. Note that this is an example application, and not intended for production environments. This issue has been resolved in Apache Tomcat 4.1.HEAD. Contact the vendor for more information.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/24999/" title="http://www.securityfocus.com/bid/24999/"&gt;http://www.securityfocus.com/bid/24999/&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:0.25in;"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:0.25in;"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;5)&lt;/span&gt;&lt;/font&gt; &lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;PhpHostBot Authorize.PHP Remote File Include Vulnerability&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:0.25in;"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:0.25in;"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;PhpHostBot is susceptible to a remote file include vulnerability. An attacker could conceivably exploit this vulnerability to compromise the application and underlying system. Other attacks are likely possible. A fix has not yet been released. Contact the vendor for additional details. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/25073/" title="http://www.securityfocus.com/bid/25073/"&gt;http://www.securityfocus.com/bid/25073/&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:0.25in;"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/div&gt;&lt;/span&gt;&lt;/font&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=68143" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/TopWebVulnerabilities/~4/304816996" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/top5/archive/2007/07/31/Top-Five-Web-Application-Vulnerabilities-7_2F00_14_2F00_07-_2D00_-7_2F00_29_2F00_07.aspx</feedburner:origLink></item></channel></rss>
