<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Weblog Tools Collection &#187; wpfootnotes</title>
	<atom:link href="http://weblogtoolscollection.com/archives/tag/wpfootnotes/feed/" rel="self" type="application/rss+xml" />
	<link>http://weblogtoolscollection.com</link>
	<description>Weblog Tools Blogging Tools Blog</description>
	<lastBuildDate>Mon, 13 Feb 2012 13:00:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>2 Plugin Security Bulletins</title>
		<link>http://weblogtoolscollection.com/archives/2008/02/07/2-plugin-security-bulletins/</link>
		<comments>http://weblogtoolscollection.com/archives/2008/02/07/2-plugin-security-bulletins/#comments</comments>
		<pubDate>Thu, 07 Feb 2008 13:22:43 +0000</pubDate>
		<dc:creator>Jeff Chandler</dc:creator>
				<category><![CDATA[WordPress Plugins]]></category>
		<category><![CDATA[WordPress Security]]></category>
		<category><![CDATA[cross_site_scripting]]></category>
		<category><![CDATA[secunia]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[wpfootnotes]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/02/07/2-plugin-security-bulletins/</guid>
		<description><![CDATA[NBBN has discovered some cross site scripting vulnerabilities for the WP-Footnotes plugin version 2.2 for WordPress. Input passed to the &#8220;pre_footnotes&#8221;, &#8220;priority&#8221;, &#8220;post_footnotes&#8221;, and &#8220;style_rules&#8221; array elements in the &#8220;wp_footnotes_current_settings[]&#8221; array in the admin_panel.php script is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user&#8217;s browser session in context of an affected site. The good news this time around is that, &#8216;register_globals&#8216; must be turned on for exploitation to occur. If you are using this plugin on your site, it is advised that you disable the plugin until a security patch has been released. According to the security bulletin, the solution is to edit the plugin source code to ensure that input is properly sanitized. Again, if you know that your webserver has register_globals turned off, you are in the clear. S@BUN has reported an &#8220;id&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p>NBBN has discovered some cross site scripting vulnerabilities for the <a href="http://wordpress.org/extend/plugins/wp-footnotes/" title="http://wordpress.org/extend/plugins/wp-footnotes/" target="_blank">WP-Footnotes</a> plugin version 2.2 for WordPress.</p>
<blockquote><p>Input passed to the &#8220;pre_footnotes&#8221;, &#8220;priority&#8221;, &#8220;post_footnotes&#8221;, and &#8220;style_rules&#8221; array elements in the &#8220;wp_footnotes_current_settings[]&#8221; array in the admin_panel.php script is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user&#8217;s browser session in context of an affected site.</p></blockquote>
<p>The good news this time around is that, &#8216;<strong>register_globals</strong>&#8216; must be turned on for exploitation to occur. If you are using this plugin on your site, it is advised that you disable the plugin until a security patch has been released. According to the security bulletin, the solution is to edit the plugin source code to ensure that input is properly sanitized.</p>
<p>Again, if you know that your webserver has register_globals turned off, you are in the clear.</p>
<p>S@BUN has reported an &#8220;<strong>id</strong>&#8221; based SQL injection vulnerability within the <a href="http://pierre.sudarovich.free.fr/index.php/2006/02/28/ajax-shoutbox/" title="http://pierre.sudarovich.free.fr/index.php/2006/02/28/ajax-shoutbox/" target="_blank">WordsPew</a> plugin version 3.x for WordPress.</p>
<blockquote><p>Input passed to the parameter &#8220;id&#8221; in wordspew-rss.php is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.</p></blockquote>
<p>The solution again is to edit the source code of the plugin to make sure that input is sanitized.</p>
]]></content:encoded>
			<wfw:commentRss>http://weblogtoolscollection.com/archives/2008/02/07/2-plugin-security-bulletins/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
	</channel>
</rss>
<!-- This Quick Cache file was built for (  weblogtoolscollection.com/archives/tag/wpfootnotes/feed/ ) in 0.75773 seconds, on Feb 14th, 2012 at 9:05 am UTC. -->
<!-- This Quick Cache file will automatically expire ( and be re-built automatically ) on Feb 14th, 2012 at 10:05 am UTC -->
