<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Fri, 09 Jan 2009 06:28:16 -0600</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[Secunia.com: TCExam PHP Code Execution and Cross-Site Scripting]]></title>
      <guid>http://www.phpdeveloper.org/news/7749</guid>
      <link>http://www.phpdeveloper.org/news/7749</link>
      <description><![CDATA[<p>
TCExam users will definitely want to pay attention to <a href="http://secunia.com/advisories/25008/">this latest advisory</a> posted by Secunia detailing a PHP code execution and cross-site scripting issue that's been found:
</p>
<blockquote>
rgod has discovered two vulnerabilities in TCExam, which can be exploited by malicious people to conduct cross-site scripting attacks or to compromise a vulnerable system.
</blockquote>
<p>
The two issues is related to two different inpus not being handled properly - the mishandling of the SessionUserLang cookie and the _SERVER[SCRIPT_NAME] value. Neither of these are being sanitized.
</p>
<p>
<a href="http://secunia.com/advisories/25008/">This issue</a> effects users of the TCExam 4.x series but a new version, 4.1.000, has already been released and made available for download.
</p>]]></description>
      <pubDate>Tue, 01 May 2007 14:18:00 -0500</pubDate>
    </item>
  </channel>
</rss>
