<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Fri, 24 May 2013 12:28:44 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[Secubos.com: Cross-Site Scripting Vulnerability in phpFaber]]></title>
      <guid>http://www.phpdeveloper.org/news/6611</guid>
      <link>http://www.phpdeveloper.org/news/6611</link>
      <description><![CDATA[<p>
A cross-site scripting bug has <a href="http://www.secuobs.com/secumail/snsecumail/msg03130.shtml">been announced</a> on the Secuobs.com website for the phpFaber content management system.
</p>
<blockquote>
<p>
Vigilon has reported a vulnerability in phpFaber CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.
</p>
<p>
Input passed via the URL in cms_images/js/htmlarea/htmlarea.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
</p>
</blockquote>
<p>
For complete information on the issue, check out <a href="http://www.secuobs.com/secumail/snsecumail/msg03130.shtml">this report</a>.
</p>]]></description>
      <pubDate>Tue, 31 Oct 2006 11:17:00 -0600</pubDate>
    </item>
  </channel>
</rss>
