<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
 <channel>
  <generator>NFE/1.0</generator>
	<title>Trustwave-SpiderLabs Security Advisories</title>
	<link>https://www.trustwave.com/spiderLabs-advisories.php</link>
	<language>en</language>
	<webMaster>marketing@trustwave.com</webMaster>
	<copyright>&amp;copy;2013 Trustwave</copyright>
	<pubDate>Sun, 19 May 2013 09:14:38 CDT</pubDate>
	<lastBuildDate>Sun, 19 May 2013 09:14:38 CDT</lastBuildDate>
	<image>
	 <title>SpiderLabs Security Advisories - Trustwave</title>
	 <url>https://www.trustwave.com/images/corpLogo.gif</url>
	 <link>https://www.trustwave.com/spiderLabs-advisories.php</link>
	</image>
			 <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/trustwave/spiderlabs-security-advisories" /><feedburner:info uri="trustwave/spiderlabs-security-advisories" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
      	  <title>TWSL2013-002.txt - Multiple XSS Vulnerabilities in The Bug Genie</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/efF9cGFo4VM/TWSL2013-002.txt</link>
      		<guid isPermaLink="false">TWSL2013-002.txt</guid>
      		<category>Advisory</category>
					<pubDate>Tue, 14 May 2013 13:00:00 UT</pubDate>
      		<description>CHICAGO (May 14, 2013) - Multiple XSS Vulnerabilities in The Bug Genie.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/efF9cGFo4VM" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2013-002.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2013-004.txt - Group Name Enumeration Vulnerability in Cisco IKE Implementation</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/Jw7JAjE6dSA/TWSL2013-004.txt</link>
      		<guid isPermaLink="false">TWSL2013-004.txt</guid>
      		<category>Advisory</category>
					<pubDate>Thu, 18 Apr 2013 13:00:00 UT</pubDate>
      		<description>CHICAGO (April 18, 2013) - Group Name Enumeration Vulnerability in Cisco IKE Implementation.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/Jw7JAjE6dSA" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2013-004.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2012-023.txt - Oracle Application Framework Diagnostic Mode Bypass Vulnerability</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/9t4uPo3Fizg/TWSL2012-023.txt</link>
      		<guid isPermaLink="false">TWSL2012-023.txt</guid>
      		<category>Advisory</category>
					<pubDate>Tue, 15 Jan 2013 13:00:00 UT</pubDate>
      		<description>CHICAGO (Jan 15, 2013) - Oracle Application Framework Diagnostic Mode Bypass Vulnerability.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/9t4uPo3Fizg" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2012-023.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2012-016.txt - Multiple Vulnerabilities in Bitweaver</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/NU_dfleyDCo/TWSL2012-016.txt</link>
      		<guid isPermaLink="false">TWSL2012-016.txt</guid>
      		<category>Advisory</category>
					<pubDate>Tue, 23 Oct 2012 13:00:00 UT</pubDate>
      		<description>CHICAGO (Oct 23, 2012) - Multiple Vulnerabilities in Bitweaver.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/NU_dfleyDCo" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2012-016.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2012-019 - Cross-Site Scripting Vulnerability in Support Incident Tracker</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/carMHyg2C3k/TWSL2012-019.txt</link>
      		<guid isPermaLink="false">TWSL2012-019</guid>
      		<category>Advisory</category>
					<pubDate>Wed, 29 Aug 2012 13:00:00 UT</pubDate>
      		<description>CHICAGO (Aug 29, 2012) - Cross-Site Scripting Vulnerability in Support Incident Tracker.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/carMHyg2C3k" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2012-019.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2012-014 - Multiple Vulnerabilities in Scrutinizer NetFlow and sFlow Analyzer</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/QDdPv4oFW4Q/TWSL2012-014.txt</link>
      		<guid isPermaLink="false">TWSL2012-014</guid>
      		<category>Advisory</category>
					<pubDate>Fri, 27 Jul 2012 17:00:00 UT</pubDate>
      		<description>CHICAGO (July 27, 2012) - Multiple Vulnerabilities in Scrutinizer NetFlow and sFlow Analyzer.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/QDdPv4oFW4Q" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2012-014.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2012-004 - Multiple Vulnerabilities in Zen Cart</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/Vcr17NkysU4/TWSL2012-004.txt</link>
      		<guid isPermaLink="false">TWSL2012-004</guid>
      		<category>Advisory</category>
					<pubDate>Thu, 3 May 2012 15:50:00 UT</pubDate>
      		<description>CHICAGO (May 3, 2012) - Multiple Vulnerabilities in Zen Cart. This advisory includes LFI vulnerabilities and XSS in the installation scripts.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/Vcr17NkysU4" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2012-004.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2012-012 - Cross-Site Scripting Vulnerability in Support Incident Tracker</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/4lEpXJQyXP8/TWSL2012-012.txt</link>
      		<guid isPermaLink="false">TWSL2012-012</guid>
      		<category>Advisory</category>
					<pubDate>Fri, 20 Apr 2012 15:50:00 UT</pubDate>
      		<description>CHICAGO (April 20, 2012) - Cross-Site Scripting Vulnerability in Support Incident Tracker.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/4lEpXJQyXP8" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2012-012.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2012-008 - Multiple Vulnerabilities in Scrutinizer NetFlow</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/7Np5nuQTFoA/TWSL2012-008.txt</link>
      		<guid isPermaLink="false">TWSL2012-008</guid>
      		<category>Advisory</category>
					<pubDate>Tue, 10 Apr 2012 15:50:00 UT</pubDate>
      		<description>CHICAGO (April 10, 2012) - Multiple Vulnerabilities in Scrutinizer NetFlow.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/7Np5nuQTFoA" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2012-008.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2012-005 - Cross-Site Scripting Vulnerability in osCommerce Platform</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/UziCaPeqeg8/TWSL2012-005.txt</link>
      		<guid isPermaLink="false">TWSL2012-005</guid>
      		<category>Advisory</category>
					<pubDate>Fri, 23 Mar 2012 15:50:00 UT</pubDate>
      		<description>CHICAGO (March 23, 2012) - Cross-Site Scripting Vulnerability in osCommerce Platform.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/UziCaPeqeg8" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2012-005.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2012-003 - Cross-Site Scripting Vulnerability in Movable Type Publishing Platform</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/JqSFDVHhIag/TWSL2012-003.txt</link>
      		<guid isPermaLink="false">TWSL2012-003</guid>
      		<category>Advisory</category>
					<pubDate>Fri, 24 Feb 2012 18:50:00 UT</pubDate>
      		<description>CHICAGO (February 24, 2012) - Cross-Site Scripting Vulnerability in Movable Type Publishing Platform.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/JqSFDVHhIag" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2012-003.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2012-002 - Multiple Vulnerabilities in WordPress</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/yomlLxzZFR0/TWSL2012-002.txt</link>
      		<guid isPermaLink="false">TWSL2012-002</guid>
      		<category>Advisory</category>
					<pubDate>Tue, 24 Jan 2012 18:50:00 UT</pubDate>
      		<description>CHICAGO (January 24, 2012) - After the successful installation of WordPress, a malicious user can inject malicious PHP code via the WordPress Themes editor.  In addition, with control of the database store, malicious Javascript can be injected into the content of WordPress yielding persistent Cross Site Scripting.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/yomlLxzZFR0" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2012-002.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2012-001 - Cross-Site Scripting Vulnerability in Textpattern Content Management System</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/OXhYClSE6FU/TWSL2012-001.txt</link>
      		<guid isPermaLink="false">TWSL2012-001</guid>
      		<category>Advisory</category>
					<pubDate>Tue, 3 Jan 2012 20:00:00 UT</pubDate>
      		<description>CHICAGO (January 3, 2012) - After extracting the Textpattern source files on to a web server, but before the application is fully installed, cross-site scripting vulnerabilities are present in the '/textpattern/setup/index.php'.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/OXhYClSE6FU" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2012-001.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2011-019 - Cross-Site Scripting Vulnerability in phpMyAdmin</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/4AjwiIqFPHI/TWSL2011-019.txt</link>
      		<guid isPermaLink="false">TWSL2011-019</guid>
      		<category>Advisory</category>
					<pubDate>Thu, 22 Dec 2011 18:00:00 UT</pubDate>
      		<description>CHICAGO (December 22, 2011) - Cross-Site Scripting Vulnerability in phpMyAdmin. Affected versions of phpMyAdmin do not sanitize user-supplied server names before displaying them in its Setup Overview. This allows remote attackers to execute arbitrary web scripts or HTML via a crafted request.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/4AjwiIqFPHI" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2011-019.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2011-018 - Authentication Bypass Vulnerability in IBM TS3100/TS3200 Web User Interface</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/i2V6bQ3V23c/TWSL2011-018.txt</link>
      		<guid isPermaLink="false">TWSL2011-018</guid>
      		<category>Advisory</category>
					<pubDate>Tue, 20 Dec 2011 19:00:00 UT</pubDate>
      		<description>CHICAGO (December 20, 2011) - Authentication Bypass Vulnerability in IBM TS3100/TS3200 Web User Interface&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/i2V6bQ3V23c" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2011-018.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2011-017 - Multiple Vulnerabilities in Merethis Centreon</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/pxtLEvFZro8/TWSL2011-017.txt</link>
      		<guid isPermaLink="false">TWSL2011-017</guid>
      		<category>Advisory</category>
					<pubDate>Fri, 4 Nov 2011 16:00:00 UT</pubDate>
      		<description>CHICAGO (November 04, 2011) - Multiple Vulnerabilities in Merethis Centreon&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/pxtLEvFZro8" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2011-017.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2011-014 - Vulnerability in Pantech Web Browser SSL Implementation</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/BVDy_OKzWF0/TWSL2011-014.txt</link>
      		<guid isPermaLink="false">TWSL2011-014</guid>
      		<category>Advisory</category>
					<pubDate>Fri, 23 Sep 2011 16:00:00 UT</pubDate>
      		<description>CHICAGO (September 23, 2011) - Vulnerability in Pantech Web Browser SSL Implementation.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/BVDy_OKzWF0" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2011-014.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2011-013 - Multiple Vulnerabilities in IceWarp Mail Server</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/OGVaw8ik8vs/TWSL2011-013.txt</link>
      		<guid isPermaLink="false">TWSL2011-013</guid>
      		<category>Advisory</category>
					<pubDate>Fri, 23 Sep 2011 16:00:00 UT</pubDate>
      		<description>CHICAGO (September 23, 2011) - Multiple Vulnerabilities in IceWarp Mail Server&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/OGVaw8ik8vs" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2011-013.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2011-008 - Focus Stealing Vulnerability in Android</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/qkjN-haLwr4/TWSL2011-008.txt</link>
      		<guid isPermaLink="false">TWSL2011-008</guid>
      		<category>Advisory</category>
					<pubDate>Sun, 7 Aug 2011 03:00:00 UT</pubDate>
      		<description>CHICAGO (August 6, 2011) - Android has vulnerabilities that allow a malicious developer to run a service that looks for apps it knows how to attack, and display a login screen to the user when those apps run.  Android gives no indication that the login screen actually belongs to a different app.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/qkjN-haLwr4" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2011-008.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2011-007 - iOS SSL Implementation Does Not Validate Certificate Chain</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/mlAZusnDp9k/TWSL2011-007.txt</link>
      		<guid isPermaLink="false">TWSL2011-007</guid>
      		<category>Advisory</category>
					<pubDate>Mon, 25 Jul 2011 19:45:00 UT</pubDate>
      		<description>CHICAGO (July 25, 2011) - iOS's SSL certificate parsing contains a flaw where it fails to check the basicConstraints parameter of certificates in the chain. By signing a new certificate using a legitimate end entity certificate, an attacker can obtain a "valid" certificate for any domain.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/mlAZusnDp9k" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2011-007.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2011-006 - IBM Web Application Firewall Bypass</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/I738FprgGHI/TWSL2011-006.txt</link>
      		<guid isPermaLink="false">TWSL2011-006</guid>
      		<category>Advisory</category>
					<pubDate>Tue, 21 Jun 2011 17:15:00 UT</pubDate>
      		<description>CHICAGO (June 21, 2011) - The IBM Web Application Firewall can be evaded, allowing an attacker to exploit web vulnerabilities that the product intends to protect.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/I738FprgGHI" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2011-006.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2011-005 - Directory Traversal in Trustwave WebDefend Enterprise</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/R4ydJhpVdvI/TWSL2011-005.txt</link>
      		<guid isPermaLink="false">TWSL2011-005</guid>
      		<category>Advisory</category>
					<pubDate>Fri, 17 Jun 2011 17:15:00 UT</pubDate>
      		<description>CHICAGO (June 17, 2011) - In WebDefend, users with administrative access to the local system in which the client software is executed can modify 'download file' function calls in order to obtain arbitrary files from the management server. These files may contain sensitive data that are above the privilege level of the current user.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/R4ydJhpVdvI" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2011-005.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2011-004 - Cross-Site Scripting Vulnerability in ZyXEL ZyWALL 70 Firewall</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/QRKay508ivk/TWSL2011-004.txt</link>
      		<guid isPermaLink="false">TWSL2011-004</guid>
      		<category>Advisory</category>
					<pubDate>Fri, 10 Jun 2011 17:15:00 UT</pubDate>
      		<description>CHICAGO (June 10, 2011) - A cross-site scripting (XSS) vulnerability was discovered in the ZyWALL 70 firewall login process that can be used to inject malicious scripts into a browser, which appear to be genuine content from the original site.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/QRKay508ivk" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2011-004.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2011-003 - Vulnerabilities discovered in Avocent Cyclades ACS Web Manager</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/D94YqQAokxQ/TWSL2011-003.txt</link>
      		<guid isPermaLink="false">TWSL2011-003</guid>
      		<category>Advisory</category>
					<pubDate>Fri, 11 Mar 2011 17:15:00 UT</pubDate>
      		<description>CHICAGO (March 11, 2011) - The session management and authentication framework on the application's web-based console contains a systemic flaw. Information is leaked concerning pages which should only be accessible subsequent to authentication within anonymously available content.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/D94YqQAokxQ" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2011-003.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2011-001 - Vulnerabilities in Trustwave WebDefend Enterprise. Read the latest news about this Trustwave WebDefend vulnerability on the SpiderLabs Blog </title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/6aPR2aA79do/TWSL2011-001.txt</link>
      		<guid isPermaLink="false">TWSL2011-001</guid>
      		<category>Advisory</category>
					<pubDate>Tue, 15 Feb 2011 22:15:00 UT</pubDate>
      		<description>CHICAGO (February 15, 2011) - A static username and password is present in versions of WebDefend Enterprise prior to 5.0. Customers should upgrade to version 5.0 version 7.01.903-1.4 in order to remediate both vulnerabilities.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/6aPR2aA79do" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2011-001.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2011-002 - Vulnerabilities in Comcast DOCSIS 3.0 Business Gateways (SMCD3G-CCR)</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/aNCctss8YdM/TWSL2011-002.txt</link>
      		<guid isPermaLink="false">TWSL2011-002</guid>
      		<category>Advisory</category>
					<pubDate>Fri, 4 Feb 2011 22:15:00 UT</pubDate>
      		<description>CHICAGO (February 4, 2011) - All SMCD3G-CCR gateways provided by Comcast have an administrative login of 'mso' with the password of 'D0nt4g3tme'.  These passwords are not provided as a part of the installation of the device and are not recommended to be changed, thus the majority of users are unaware of the default configuration.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/aNCctss8YdM" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2011-002.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2010-008 - Clear iSpot/Clearspot CSRF Vulnerabilities</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/FzfGSSv3n_g/TWSL2010-008.txt</link>
      		<guid isPermaLink="false">TWSL2010-008</guid>
      		<category>Advisory</category>
					<pubDate>Fri, 10 Dec 2010 22:15:00 UT</pubDate>
      		<description>CHICAGO (December 10, 2010) - Vulnerabilities will allow an attacker to enable remote access to the iSpot and ClearSpot 4G, and add their own account to the device. This level of access also provides a device's client-side SSL certificates, which are used to perform device authentication. This could lead to a compromise of ClearWire accounts as well as other personal information.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/FzfGSSv3n_g" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2010-008.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2010-007 - Passlogix v-GO Self-Service Password Reset Bypass via Invalid SSL Certificate</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/Is8cRtsVu1Q/TWSL2010-007.txt</link>
      		<guid isPermaLink="false">TWSL2010-007</guid>
      		<category>Advisory</category>
					<pubDate>Fri, 10 Dec 2010 22:15:00 UT</pubDate>
      		<description>CHICAGO (December 10, 2010) - Passlogix v-GO SSPR provides users with a fast, secure way to regain access to their computer by automating Windows password reset. Users can reset their password or unlock their Windows account directly from their locked out workstation, so that they can get to their applications within seconds - without having to pick up the telephone or go to another workstation.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/Is8cRtsVu1Q" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2010-007.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2010-006 - Multiple Vulnerabilities in Camtron CMNC-200 IP Camera</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/Y5abTlPo_hQ/TWSL2010-006.txt</link>
      		<guid isPermaLink="false">TWSL2010-006</guid>
      		<category>Advisory</category>
					<pubDate>Fri, 12 Nov 2010 22:15:00 UT</pubDate>
      		<description>CHICAGO (November 12, 2010) - The CMNC-200 IP Camera has a built-in web server that is enabled by default. The server is vulnerable to directory transversal attacks, allowing access to any file on the camera file system.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/Y5abTlPo_hQ" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2010-006.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2010-005 - FreePBX recordings interface allows remote code execution</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/TOf60IuGQII/TWSL2010-005.txt</link>
      		<guid isPermaLink="false">TWSL2010-005</guid>
      		<category>Advisory</category>
					<pubDate>Thu, 23 Sep 2010 22:15:00 UT</pubDate>
      		<description>CHICAGO (September 23, 2010) - The configuration interface for FreePBX is prone to a remote arbitrary code execution on the system recordings menu. FreePBX doesn't handle file uploads in a secure manner, allowing an attacker to manipulate the file extension and the beginning of the uploaded file name.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/TOf60IuGQII" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2010-005.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2010-003 - Unauthorized access to root NFS export on EMC Celerra Network Attached Storage(NAS) appliance</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/gOBmcuMUVLQ/TWSL2010-003.txt</link>
      		<guid isPermaLink="false">TWSL2010-003</guid>
      		<category>Advisory</category>
					<pubDate>Thu, 29 Jul 2010 22:15:00 UT</pubDate>
      		<description>CHICAGO (July 29, 2010) - The Celerra appliance's NFS server freely exports its "/" file system and enforces access using a factory-defined list of authorized IP addresses.  The addresses found on a recent model are listed in the showmount example below,however this list may differ depending on product version. The IP addresses are intended for communication internal to the appliance, but are still accepted from external sources. An attacker can mount this file system by spoofing an authorized IP address.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/gOBmcuMUVLQ" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2010-003.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2010-002 - Web Service Hijacking in VMWare WebAccess</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/4vUCrbKk-LU/TWSL2010-002.txt</link>
      		<guid isPermaLink="false">TWSL2010-002</guid>
      		<category>Advisory</category>
					<pubDate>Tue, 30 Mar 2010 22:00:00 UT</pubDate>
      		<description>CHICAGO (March 30, 2010) - The Struts-based web application uses the server-side session attribute "context_vmdirect" to store various settings, including the URL to the XML web service backend. By default, the URL is http://localhost/sdk, but the web service URL can be manually set from a client browser in several locations. One location is /ui/vmDirect.do, by passing a base64-encoded value to in the "view" parameter.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/4vUCrbKk-LU" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2010-002.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2010-001 - View state tampering vulnerabilities in products from Microsoft, Apache, and Sun Microsystems</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/LwdNclYF6iI/TWSL2010-001.txt</link>
      		<guid isPermaLink="false">TWSL2010-001</guid>
      		<category>Advisory</category>
					<pubDate>Wed, 3 Feb 2010 22:00:00 UT</pubDate>
      		<description>CHICAGO (February 3, 2010) - SpiderLabs has documented view state tampering vulnerabilities in three products from separate vendors. View states are used by some web application frameworks to store the state of HTML GUI controls. View states are typically stored in hidden client-side input fields,although server-side storage is widely supported.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/LwdNclYF6iI" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2009-002 - Cisco's Adaptive Security Appliance (ASA) Web VPN Multiple Vulnerabilities</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/cHsODwxHGNA/TWSL2009-002.txt</link>
      		<guid isPermaLink="false">TWSL2009-002</guid>
      		<category>Advisory</category>
					<pubDate>Wed, 24 Jun 2009 22:00:00 UT</pubDate>
      		<description>CHICAGO (June 24, 2009) - Cisco's Adaptive Security Appliance (ASA) provides a number of security related features, including "Web VPN" functionality that allows authenticated users to access a variety of content through a web interface. This includes other web content, FTP servers, and CIFS file servers.&lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/cHsODwxHGNA" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2009-002.txt</feedburner:origLink></item>
		 
		 		 <item>
      	  <title>TWSL2009-001 - Profense Web Application Firewall and Load Balancer multiple vulnerabilities</title>
      		<link>http://feedproxy.google.com/~r/trustwave/spiderlabs-security-advisories/~3/_-muA6MCbqM/TWSL2009-001.txt</link>
      		<guid isPermaLink="false">TWSL2009-001</guid>
      		<category>Advisory</category>
					<pubDate>Tue, 19 May 2009 22:00:00 UT</pubDate>
      		<description>CHICAGO (May 19, 2009) - Profense is a web application firewall and load balancer designed to help organizations become compliant. it features scalability and acceleration of complex SSL-enabled web applications. A Cross-Site Scripting (XSS) vulnerability can be reproduced by injecting a common XSS attack in a vulnerable application protected by Profense Web Application Firewall. Inserting extra characters in the JavaScript close tag will bypass the XSS protection mechanisms. &lt;br&gt;&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/trustwave/spiderlabs-security-advisories/~4/_-muA6MCbqM" height="1" width="1"/&gt;</description>
	<feedburner:origLink>https://www.trustwave.com/spiderlabs/advisories/TWSL2009-001.txt</feedburner:origLink></item>
		 
		 
	<description>SpiderLabs Advisories</description>
 </channel>
</rss>
