<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Tue, 21 May 2013 07:41:07 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[SecWatch.org: CJ Tag Board Multiple Parameter Handling PHP Code Injection Vulnerabilities]]></title>
      <guid>http://www.phpdeveloper.org/news/6177</guid>
      <link>http://www.phpdeveloper.org/news/6177</link>
      <description><![CDATA[<p>
According to <a href="http://secwatch.org/advisories/1015231/">this posting</a> on the SecWatch board today, there are some issues with the CJ Tag Board software that allow for code injection issues.
</p>
<blockquote>
Multiple input validation vulnerabilities in CJ Tag Board have been reported, which can be exploited by remote users to compromise a vulnerable system.
</blockquote>
<p>
The <a href="http://secwatch.org/advisories/1015231/">issue</a> comes from improperly filtered user input for the "User-Agent" HTTP header and the "banned" parameter for the admin side. This issue effects CJ Tag Board version 3.0. No update or patch has been posted as of yet to correct this issue.
</p>]]></description>
      <pubDate>Wed, 30 Aug 2006 08:18:29 -0500</pubDate>
    </item>
  </channel>
</rss>
