News Feed
Jobs Feed
Sections

Recent Jobs

News Archive
John Cox's Blog:
vTiger multiple vulnerabilities
November 25, 2005 @ 06:50:46

John Cox has this new post today with an up-close look at one of the PHP application issues highlighted by the PHP Security Consortium - one dealing with vTiger.

Interesting security notice via PHPSec on vTiger (open source customer relationship management system). Beyond the normal XSS vulnerabilities that were reported was an interesting topic of an exploit that I had not given much thought to before.

The method he refers to here deals with vTigers ability to read in RSS blogs, but no checking is done. Thus, a malicious user could enter "crap" into the blog and trick someone using vTiger to read it in. This "RSS attack" isn't something new, but it doesn't get a lot of press. It should, however, be paid attention to, since the results could be quite detrimential to you and your site...

0 comments voice your opinion now!
php vtiger multiple vulnerabilities php vtiger multiple vulnerabilities



Similar Posts

Community News: The PHP Community Responds to the Framework

Justin Silverton\'s Blog: PHP vs Perl

Community News: Tentative Roadmap to PHP 5.1.2

Sephiroth.it: Debugging PHP with XDebug

PHP-it.net: Creating a chat script with PHP and Ajax (Part 2)


Community Events









Don't see your event here?
Let us know!


release application releases book database cakephp package PEAR framework code conference mysql job PHP5 example security zend developer zendframework ajax

All content copyright, 2009 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework