<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security</title>
	<atom:link href="http://security.hostservicenet.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://security.hostservicenet.com</link>
	<description>Tutto sulla sicurezza...</description>
	<lastBuildDate>Sun, 19 Feb 2012 07:01:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Joomla Component com_hdvideoshare Sql Injection</title>
		<link>http://security.hostservicenet.com/2012/02/19/joomla-component-com_hdvideoshare-sql-injection/</link>
		<comments>http://security.hostservicenet.com/2012/02/19/joomla-component-com_hdvideoshare-sql-injection/#comments</comments>
		<pubDate>Sun, 19 Feb 2012 07:01:36 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[Joomla]]></category>
		<category><![CDATA[Web Content Management System]]></category>
		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.hostservicenet.com/?p=363</guid>
		<description><![CDATA[Tipo Exploit: SQL Injection Livello di criticità:]]></description>
			<content:encoded><![CDATA[<p><strong>Tipo Exploit:</strong> SQL Injection<br />
<strong>Livello di criticità: <img title="03" src="/images/Crit_Lev_03.gif" alt="" width="41" height="6" align="absmiddle" border="0" hspace="5" /></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://security.hostservicenet.com/2012/02/19/joomla-component-com_hdvideoshare-sql-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tube Ace (Adult PHP Tube Script) SQL Injection</title>
		<link>http://security.hostservicenet.com/2012/02/08/tube-ace-adult-php-tube-script-sql-injection/</link>
		<comments>http://security.hostservicenet.com/2012/02/08/tube-ace-adult-php-tube-script-sql-injection/#comments</comments>
		<pubDate>Wed, 08 Feb 2012 16:38:31 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[Tube Script]]></category>
		<category><![CDATA[Web Content Management System]]></category>
		<category><![CDATA[Adult PHP Tube Script]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[Tube Ace]]></category>

		<guid isPermaLink="false">http://security.hostservicenet.com/?p=361</guid>
		<description><![CDATA[Tipo Exploit: SQL Injection Livello di criticità:]]></description>
			<content:encoded><![CDATA[<p><strong>Tipo Exploit:</strong> SQL Injection<br />
<strong>Livello di criticità: <img title="03" src="/images/Crit_Lev_03.gif" alt="" width="41" height="6" align="absmiddle" border="0" hspace="5" /></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://security.hostservicenet.com/2012/02/08/tube-ace-adult-php-tube-script-sql-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OSCommerce v3.0.2 &#8211; Cross site scripting persistente</title>
		<link>http://security.hostservicenet.com/2012/02/08/oscommerce-v3-0-2-cross-site-scripting-persistente/</link>
		<comments>http://security.hostservicenet.com/2012/02/08/oscommerce-v3-0-2-cross-site-scripting-persistente/#comments</comments>
		<pubDate>Wed, 08 Feb 2012 16:20:37 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[eCommerce Script]]></category>
		<category><![CDATA[Web Content Management System]]></category>
		<category><![CDATA[Cross site scripting]]></category>

		<guid isPermaLink="false">http://security.hostservicenet.com/?p=359</guid>
		<description><![CDATA[Tipo Exploit: Cross site scripting persistente. Livello di criticità: Versioni affette: 3.0.2.]]></description>
			<content:encoded><![CDATA[<p><strong>Tipo Exploit:</strong> Cross site scripting persistente.<br />
<strong>Livello di criticità: <img title="04" src="/images/Crit_Lev_04.gif" alt="" width="41" height="6" align="absmiddle" border="0" hspace="5" /></strong><br />
<strong>Versioni affette:</strong> 3.0.2.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.hostservicenet.com/2012/02/08/oscommerce-v3-0-2-cross-site-scripting-persistente/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mambo CMS 4.6.5 SQL Injection</title>
		<link>http://security.hostservicenet.com/2012/02/08/mambo-cms-4-6-5-sql-injection/</link>
		<comments>http://security.hostservicenet.com/2012/02/08/mambo-cms-4-6-5-sql-injection/#comments</comments>
		<pubDate>Wed, 08 Feb 2012 16:11:13 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[Mambo]]></category>
		<category><![CDATA[Web Content Management System]]></category>
		<category><![CDATA[mambo]]></category>
		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.hostservicenet.com/?p=357</guid>
		<description><![CDATA[Tipo Exploit: SQL Injection Livello di criticità: Versioni affette: 4.6.5 e tutte le precedenti versioni. Soluzione: aggiornare all&#8217;ultima versione disponibile.]]></description>
			<content:encoded><![CDATA[<p><strong>Tipo Exploit:</strong> SQL Injection<br />
<strong>Livello di criticità: <img title="03" src="/images/Crit_Lev_03.gif" alt="" width="41" height="6" align="absmiddle" border="0" hspace="5" /></strong><br />
<strong>Versioni affette:</strong> 4.6.5 e tutte le precedenti versioni.<br />
<strong>Soluzione:</strong> aggiornare all&#8217;ultima versione disponibile.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.hostservicenet.com/2012/02/08/mambo-cms-4-6-5-sql-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Joomla Discussions Component (com_discussions) SQL Injection</title>
		<link>http://security.hostservicenet.com/2012/02/08/joomla-discussions-component-com_discussions-sql-injection/</link>
		<comments>http://security.hostservicenet.com/2012/02/08/joomla-discussions-component-com_discussions-sql-injection/#comments</comments>
		<pubDate>Wed, 08 Feb 2012 16:02:55 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[Joomla]]></category>
		<category><![CDATA[Web Content Management System]]></category>
		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.hostservicenet.com/?p=355</guid>
		<description><![CDATA[Tipo Exploit: SQL Injection Livello di criticità:]]></description>
			<content:encoded><![CDATA[<p><strong>Tipo Exploit:</strong> SQL Injection<br />
<strong>Livello di criticità: <img title="04" src="/images/Crit_Lev_04.gif" alt="" width="41" height="6" align="absmiddle" border="0" hspace="5" /></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://security.hostservicenet.com/2012/02/08/joomla-discussions-component-com_discussions-sql-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress wp-autoyoutube plugin Blind SQL Injection</title>
		<link>http://security.hostservicenet.com/2012/02/08/wordpress-wp-autoyoutube-plugin-blind-sql-injection/</link>
		<comments>http://security.hostservicenet.com/2012/02/08/wordpress-wp-autoyoutube-plugin-blind-sql-injection/#comments</comments>
		<pubDate>Wed, 08 Feb 2012 15:49:26 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[Web Content Management System]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.hostservicenet.com/?p=353</guid>
		<description><![CDATA[Tipo Exploit: Blind SQL Injection Livello di criticità:]]></description>
			<content:encoded><![CDATA[<p><strong>Tipo Exploit:</strong> Blind SQL Injection<br />
<strong>Livello di criticità: <img title="04" src="/images/Crit_Lev_04.gif" alt="" width="41" height="6" align="absmiddle" border="0" hspace="5" /></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://security.hostservicenet.com/2012/02/08/wordpress-wp-autoyoutube-plugin-blind-sql-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress Easy Contact Form Lite plugin </title>
		<link>http://security.hostservicenet.com/2012/02/08/wordpress-easy-contact-form-lite-plugin/</link>
		<comments>http://security.hostservicenet.com/2012/02/08/wordpress-easy-contact-form-lite-plugin/#comments</comments>
		<pubDate>Wed, 08 Feb 2012 15:41:29 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[Web Content Management System]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.hostservicenet.com/?p=351</guid>
		<description><![CDATA[Tipo Exploit: SQL Injection Livello di criticità: Versioni affette: 1.0.7 e tutte le precedenti versioni.]]></description>
			<content:encoded><![CDATA[<p><strong>Tipo Exploit:</strong> SQL Injection<br />
<strong>Livello di criticità: <img title="04" src="/images/Crit_Lev_04.gif" alt="" width="41" height="6" align="absmiddle" border="0" hspace="5" /></strong><br />
<strong>Versioni affette:</strong> 1.0.7 e tutte le precedenti versioni.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.hostservicenet.com/2012/02/08/wordpress-easy-contact-form-lite-plugin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress Contact Form plugin </title>
		<link>http://security.hostservicenet.com/2012/02/08/wordpress-contact-form-plugin/</link>
		<comments>http://security.hostservicenet.com/2012/02/08/wordpress-contact-form-plugin/#comments</comments>
		<pubDate>Wed, 08 Feb 2012 15:35:16 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[Web Content Management System]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://security.hostservicenet.com/?p=348</guid>
		<description><![CDATA[Tipo Exploit: SQL Injection Livello di criticità: Versioni affette: 2.7.5 e tutte le precedenti versioni.]]></description>
			<content:encoded><![CDATA[<p><strong>Tipo Exploit:</strong> SQL Injection<br />
<strong>Livello di criticità: <img title="04" src="/images/Crit_Lev_04.gif" alt="" width="41" height="6" align="absmiddle" border="0" hspace="5" /></strong><br />
<strong>Versioni affette:</strong> 2.7.5 e tutte le precedenti versioni.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.hostservicenet.com/2012/02/08/wordpress-contact-form-plugin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress Kish Guest Posting Plugin 1.0 &#8211; Upload di files arbitrari</title>
		<link>http://security.hostservicenet.com/2012/02/08/wordpress-kish-guest-posting-plugin-1-0-upload-di-files-arbitrari/</link>
		<comments>http://security.hostservicenet.com/2012/02/08/wordpress-kish-guest-posting-plugin-1-0-upload-di-files-arbitrari/#comments</comments>
		<pubDate>Wed, 08 Feb 2012 14:21:21 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[Web Content Management System]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[Arbitrary File Upload]]></category>

		<guid isPermaLink="false">http://security.hostservicenet.com/?p=346</guid>
		<description><![CDATA[Tipo Exploit: Arbitrary File Upload Livello di criticità: Versioni affette: 1. Descrizione: uploadify.php permette l&#8217;upload di file senza limiti (restrizioni). Un aggressore potrebbe essere in grado di caricare file arbitrari contenenti codice PHP dannoso perchè il tipo di estensione del file caricato non è adeguatamente controllato.]]></description>
			<content:encoded><![CDATA[<p><strong>Tipo Exploit:</strong> Arbitrary File Upload<br />
<strong>Livello di criticità: <img title="03" src="/images/Crit_Lev_03.gif" alt="" width="41" height="6" align="absmiddle" border="0" hspace="5" /></strong><br />
<strong>Versioni affette:</strong> 1.<strong></strong><br />
<strong>Descrizione:</strong> uploadify.php permette l&#8217;upload di file senza limiti (restrizioni).<br />
Un aggressore potrebbe essere in grado di caricare file arbitrari contenenti codice PHP dannoso perchè il tipo di estensione del file caricato non è adeguatamente controllato.</p>
]]></content:encoded>
			<wfw:commentRss>http://security.hostservicenet.com/2012/02/08/wordpress-kish-guest-posting-plugin-1-0-upload-di-files-arbitrari/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress </title>
		<link>http://security.hostservicenet.com/2012/02/08/wordpress/</link>
		<comments>http://security.hostservicenet.com/2012/02/08/wordpress/#comments</comments>
		<pubDate>Wed, 08 Feb 2012 13:20:42 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://security.hostservicenet.com/?p=344</guid>
		<description><![CDATA[Tipo Exploit: Esecuzione di codice PHP e persistente Cross Site Scripting Vulnerabilità tramite la pagina di &#8216;setup-config.php&#8217; Livello di criticità: Versioni affette: 3.3.1 e tutte le precedenti versioni di WordPress. Descrizione: La pagina di installazione WordPress &#8216;setup-config.php&#8217; permette agli utenti di installare WordPress in un locale o remote database MySQL. Ciò richiede che un utente [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Tipo Exploit:</strong> Esecuzione di codice PHP e persistente Cross Site Scripting<br />
Vulnerabilità tramite la pagina di &#8216;setup-config.php&#8217;<br />
<strong>Livello di criticità: <img title="05" src="/images/Crit_Lev_05.gif" border="0" alt="" hspace="5" width="41" height="6" align="absmiddle" /></strong><br />
<strong>Versioni affette:</strong> 3.3.1 e tutte le precedenti versioni di WordPress.<strong></strong><br />
<strong>Descrizione:</strong> La pagina di installazione WordPress &#8216;setup-config.php&#8217; permette agli utenti di installare WordPress in un locale o remote database MySQL. Ciò richiede che un utente abbia valide credenziali per completare l&#8217;operazione. Tuttavia, un utente malintenzionato, può ospitare il proprio database MySQL e può completare con successo l&#8217;installazione di WordPress senza credenziali valide sul sistema di destinazione.<br />
Dopo la corretta installazione di WordPress, un utente malintenzionato può iniettare codice PHP maligno tramite l&#8217;editor di WordPress Themes. Inoltre, con il controllo del database, può essere iniettare Javascript dannoso nel contenuto di WordPress (persistente Cross Site Scripting).</p>
]]></content:encoded>
			<wfw:commentRss>http://security.hostservicenet.com/2012/02/08/wordpress/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

