<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Yet More Security Vulnerabilities Found In Pligg V9.9.0</title>
	<atom:link href="http://socialcmsbuzz.com/yet-more-security-vulnerabilities-found-in-pligg-v990-31072008/feed/" rel="self" type="application/rss+xml" />
	<link>http://socialcmsbuzz.com/yet-more-security-vulnerabilities-found-in-pligg-v990-31072008/</link>
	<description>Latest News and Information for social CMS systems</description>
	<lastBuildDate>Wed, 16 Mar 2011 13:27:18 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Tiaranda</title>
		<link>http://socialcmsbuzz.com/yet-more-security-vulnerabilities-found-in-pligg-v990-31072008/comment-page-1/#comment-2677</link>
		<dc:creator>Tiaranda</dc:creator>
		<pubDate>Fri, 15 Aug 2008 16:02:31 +0000</pubDate>
		<guid isPermaLink="false">http://socialcmsbuzz.com/?p=493#comment-2677</guid>
		<description>&quot;Shame on GulfTech Security to post in the wild. Never EVER do business with them.&quot;

What an ignorant statement, have you ever even dealt with them? GulfTech do great work, and are simply amazing compared to the company that we had reviewing our products before. 

If anything, people should be cautious of a software vendor who does not care enough about their products (or their users)  to have them professionally secured. 

On another note, as a long time Pligg user I am definitely switching to YaDC since they are actually the project that secured Pligg when all these vulnerabilities were found. I still can&#039;t believe Yankidank and Co. ganked the fixes from YaDC without even giving due credit :-\ Maybe he should call himself Yankigank lol</description>
		<content:encoded><![CDATA[<p>&#8220;Shame on GulfTech Security to post in the wild. Never EVER do business with them.&#8221;</p>
<p>What an ignorant statement, have you ever even dealt with them? GulfTech do great work, and are simply amazing compared to the company that we had reviewing our products before. </p>
<p>If anything, people should be cautious of a software vendor who does not care enough about their products (or their users)  to have them professionally secured. </p>
<p>On another note, as a long time Pligg user I am definitely switching to YaDC since they are actually the project that secured Pligg when all these vulnerabilities were found. I still can&#8217;t believe Yankidank and Co. ganked the fixes from YaDC without even giving due credit :-\ Maybe he should call himself Yankigank lol</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: meneame.net</title>
		<link>http://socialcmsbuzz.com/yet-more-security-vulnerabilities-found-in-pligg-v990-31072008/comment-page-1/#comment-2542</link>
		<dc:creator>meneame.net</dc:creator>
		<pubDate>Fri, 01 Aug 2008 01:46:18 +0000</pubDate>
		<guid isPermaLink="false">http://socialcmsbuzz.com/?p=493#comment-2542</guid>
		<description>&lt;strong&gt;Encontrados dos agujeros de seguridad en pligg...&lt;/strong&gt;

Hace dos dÃ­as, se hicieron pÃºblicos un par de agujeros de seguridad en pligg, un fork de meneame, dichos agujeros permitirÃ­an ejecutar cÃ³digo sql arbitrario en la base de datos, cÃ³digo javascript arbitrario en el contexto de la web, y cÃ³digo php ...</description>
		<content:encoded><![CDATA[<p><strong>Encontrados dos agujeros de seguridad en pligg&#8230;</strong></p>
<p>Hace dos dÃ­as, se hicieron pÃºblicos un par de agujeros de seguridad en pligg, un fork de meneame, dichos agujeros permitirÃ­an ejecutar cÃ³digo sql arbitrario en la base de datos, cÃ³digo javascript arbitrario en el contexto de la web, y cÃ³digo php &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vulnerabilitate Pligg &#124; PCNews</title>
		<link>http://socialcmsbuzz.com/yet-more-security-vulnerabilities-found-in-pligg-v990-31072008/comment-page-1/#comment-2533</link>
		<dc:creator>Vulnerabilitate Pligg &#124; PCNews</dc:creator>
		<pubDate>Thu, 31 Jul 2008 20:56:51 +0000</pubDate>
		<guid isPermaLink="false">http://socialcmsbuzz.com/?p=493#comment-2533</guid>
		<description>[...] Toate site-urile care folosesc Pligg sunt in pericol deoarece o serie de vulnerabilitati au fost publicate pe Internet. [...]</description>
		<content:encoded><![CDATA[<p>[...] Toate site-urile care folosesc Pligg sunt in pericol deoarece o serie de vulnerabilitati au fost publicate pe Internet. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: stephan</title>
		<link>http://socialcmsbuzz.com/yet-more-security-vulnerabilities-found-in-pligg-v990-31072008/comment-page-1/#comment-2532</link>
		<dc:creator>stephan</dc:creator>
		<pubDate>Thu, 31 Jul 2008 20:39:42 +0000</pubDate>
		<guid isPermaLink="false">http://socialcmsbuzz.com/?p=493#comment-2532</guid>
		<description>&quot;Generally any serious or professional IT security team would never allow this information to be public.&quot;

Since when do IT Security teams not release their findings publicly? It is what they do! (everyone from symantec to secunia do this, duh) I think it is safe for you to take off your tin foil hat now. lol Also, I don&#039;t think he stole the information either as I found out about it here after I was hacked.

http://www.securityfocus.com/bid/30458/discuss

Since the Pligg developers seem to be a bunch of slackers I wanted details of the vulnerabilities so that I could fix them myself and get my site back up.

On  a more serious note I hope these issues are fixed soon. My webhost temporarily suspended my account cause my Pligg was used to send spam after it was hacked :(</description>
		<content:encoded><![CDATA[<p>&#8220;Generally any serious or professional IT security team would never allow this information to be public.&#8221;</p>
<p>Since when do IT Security teams not release their findings publicly? It is what they do! (everyone from symantec to secunia do this, duh) I think it is safe for you to take off your tin foil hat now. lol Also, I don&#8217;t think he stole the information either as I found out about it here after I was hacked.</p>
<p><a href="http://www.securityfocus.com/bid/30458/discuss" rel="nofollow">http://www.securityfocus.com/bid/30458/discuss</a></p>
<p>Since the Pligg developers seem to be a bunch of slackers I wanted details of the vulnerabilities so that I could fix them myself and get my site back up.</p>
<p>On  a more serious note I hope these issues are fixed soon. My webhost temporarily suspended my account cause my Pligg was used to send spam after it was hacked <img src='http://socialcmsbuzz.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: amuzihqzi</title>
		<link>http://socialcmsbuzz.com/yet-more-security-vulnerabilities-found-in-pligg-v990-31072008/comment-page-1/#comment-2531</link>
		<dc:creator>amuzihqzi</dc:creator>
		<pubDate>Thu, 31 Jul 2008 19:06:59 +0000</pubDate>
		<guid isPermaLink="false">http://socialcmsbuzz.com/?p=493#comment-2531</guid>
		<description>Shame on socialcmsbuzz telling people how to exploit a pliqq. Shame on GulfTech Security to post in the wild. Never EVER do business with them.</description>
		<content:encoded><![CDATA[<p>Shame on socialcmsbuzz telling people how to exploit a pliqq. Shame on GulfTech Security to post in the wild. Never EVER do business with them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pete</title>
		<link>http://socialcmsbuzz.com/yet-more-security-vulnerabilities-found-in-pligg-v990-31072008/comment-page-1/#comment-2530</link>
		<dc:creator>pete</dc:creator>
		<pubDate>Thu, 31 Jul 2008 18:24:54 +0000</pubDate>
		<guid isPermaLink="false">http://socialcmsbuzz.com/?p=493#comment-2530</guid>
		<description>You released a version of Pligg. Where are your security fixes? I guess you are just waiting until Pligg release theirs so you can add them to your version and take all the credit?

I&#039;m also surprised that James Bercegay of GulfTech Security Research Team would allow you to publicly post post his findings..  I guess that&#039;s how they do business.  Generally any serious or professional IT security team would never allow this information to be public.  So only 2 conclusions can be drawn. You illegally published his findings, or GulfTech is a scam looking to exploit money from Pligg.  Either way it&#039;s bad news all around.</description>
		<content:encoded><![CDATA[<p>You released a version of Pligg. Where are your security fixes? I guess you are just waiting until Pligg release theirs so you can add them to your version and take all the credit?</p>
<p>I&#8217;m also surprised that James Bercegay of GulfTech Security Research Team would allow you to publicly post post his findings..  I guess that&#8217;s how they do business.  Generally any serious or professional IT security team would never allow this information to be public.  So only 2 conclusions can be drawn. You illegally published his findings, or GulfTech is a scam looking to exploit money from Pligg.  Either way it&#8217;s bad news all around.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vote for this article at blogengage.com</title>
		<link>http://socialcmsbuzz.com/yet-more-security-vulnerabilities-found-in-pligg-v990-31072008/comment-page-1/#comment-2529</link>
		<dc:creator>Vote for this article at blogengage.com</dc:creator>
		<pubDate>Thu, 31 Jul 2008 15:58:01 +0000</pubDate>
		<guid isPermaLink="false">http://socialcmsbuzz.com/?p=493#comment-2529</guid>
		<description>&lt;strong&gt;Yet More Security Vulnerabilities Found In Pligg V9.9.0...&lt;/strong&gt;

On Tuesday of this week we alerted Pligg based CMS users to a Remote SQL Injection Vulnerability that was present within the story.php. This issue is caused by an input validation error in the &quot;story.php&quot; script when processing the &quot;id&quot; parameter. ...</description>
		<content:encoded><![CDATA[<p><strong>Yet More Security Vulnerabilities Found In Pligg V9.9.0&#8230;</strong></p>
<p>On Tuesday of this week we alerted Pligg based CMS users to a Remote SQL Injection Vulnerability that was present within the story.php. This issue is caused by an input validation error in the &#8220;story.php&#8221; script when processing the &#8220;id&#8221; parameter. &#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/


Served from: socialcmsbuzz.com @ 2012-02-09 09:01:59 -->
