<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!--Web 2.0 Content Powered by MyST Blogsite® (http://blogsite.com)-->
<!--A service of MyST Technology Partners, Inc. (http://myst-technology.com)-->
<?xml-stylesheet href="http://blog.cenzic.com/public/styles/etc/object.xsl" type="text/xsl"?>

<?myst-baseUrl http://blog.cenzic.com/public/?>

<MySmartChannels Public="true" UserID="202607" dT="1491" t0="1268711562714">
     <GetChannel_Result>
      <ChannelDomain>
       <Domain>
        <ObjectID>202612</ObjectID>
        <ObjectClass>Domain</ObjectClass>
        <OwnerID ObjectClass="Domain" Title="Security Blog Weblogs">202611</OwnerID>
        <CreatedByID ObjectClass="User" Title="$Cenzic">202604</CreatedByID>
        <ModifiedByID ObjectClass="User" Title="$Cenzic">202604</ModifiedByID>
        <CreateTime Title="2008-05-01 13:00:50 EDT">1209661250756</CreateTime>
        <ModifyTime Title="2009-09-29 17:09:56 EDT">1254258596732</ModifyTime>
        <SecurityModel>Controlled</SecurityModel>
        <Name>[Weblog] Cenzic SmartAttack Updates for Web Vulnerabilities</Name>
        <Summary>Latest web application vulnerabilities integrated into the Cenzic product suite.</Summary>
        <Description>
        &lt;p&gt;This blog features the latest vulnerabilities in web / website applications (custom, commercial, and open-source) 
        that have been integrated into the Cenzic's website security product suite on a weekly basis.  
        These web application vulnerabilities include cross site scripting, 
        buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;
    </Description>
       </Domain>
       <ObjectCounts OwnerID="202612">
        <Resource>98</Resource>
       </ObjectCounts>
       <UserPermissions>
        <CanCreateChannelItem>false</CanCreateChannelItem>
        <CanDelete>false</CanDelete>
        <CanDiscover>true</CanDiscover>
        <CanEdit>false</CanEdit>
        <CanEditPermissions>false</CanEditPermissions>
        <CanPublish>false</CanPublish>
        <CanRead>true</CanRead>
       </UserPermissions>
      </ChannelDomain>
      <ChannelProperties>
            <Copyright>2009 Cenzic, Inc--All Rights Reserved</Copyright>

            <Legal>This channel is part of the Cenzic Security Blog blogsite--Powered by MyST Blogsite®.</Legal>

            <Views>
             <View>
              <Name>blog</Name>

              <Model>blogsite/Cenzic/web</Model>

              <Style/>

              <Scheme/>

       </View>

             <View>
              <Name>edit-item</Name>

              <Model>blogsite/Cenzic/right-content</Model>

              <Style/>

              <Scheme/>

       </View>

             <View>
              <Name>left</Name>

              <Model>blogsite/Cenzic/left-content</Model>

              <Style/>

              <Scheme/>

       </View>

             <View>
              <Name>right</Name>

              <Model>blogsite/Cenzic/right-content</Model>

              <Style/>

              <Scheme/>

       </View>

             <View>
              <Name>wide</Name>

              <Model>blogsite/Cenzic/wide-content</Model>

              <Style/>

              <Scheme/>

       </View>

      </Views>

            <Keywords>
             <Keyword>Cross site request forgery</Keyword>

             <Keyword>CSRF</Keyword>

             <Keyword>Cross site Scripting</Keyword>

             <Keyword>XSS</Keyword>

             <Keyword>Buffer overflow</Keyword>

             <Keyword>Session management</Keyword>

             <Keyword>Session ID randomness</Keyword>

             <Keyword>Privilege escalation</Keyword>

             <Keyword>Session hijacking</Keyword>

             <Keyword>SQL Injection</Keyword>

             <Keyword>archive.blog:Monthly 0 1</Keyword>

             <Keyword>image.description:This blogsite contains information on all security topics ranging from web application security, security software, vulnerabilities, enterprise security, penetration testing and hacker news.</Keyword>

             <Keyword>image.height:31</Keyword>

             <Keyword>image.link.url:http://blog.cenzic.com</Keyword>

             <Keyword>image.title:Cenzic Security Blog</Keyword>

             <Keyword>image.url:http://blog.cenzic.com/styles/blogsite/Cenzic/images/rss.jpg</Keyword>

             <Keyword>image.width:88</Keyword>

             <Keyword>lang:en-us</Keyword>

             <Keyword>rss.description:full</Keyword>

             <Keyword>rss.limit:15</Keyword>

             <Keyword>captyx-hook._top:weblog-top</Keyword>

             <Keyword>captyx-hook._bottom:weblog-bottom</Keyword>

      </Keywords>

            <Refresh>360</Refresh>

     </ChannelProperties>
      <Items>
       <Item>
        <Resource>
         <ObjectID>249608</ObjectID>
         <ObjectClass>Resource</ObjectClass>
         <OwnerID ObjectClass="Domain" Title="[Weblog] Cenzic SmartAttack Updates for Web Vulnerabilities">202612</OwnerID>
         <CreatedByID ObjectClass="User" Title="eswanson">202768</CreatedByID>
         <ModifiedByID ObjectClass="User" Title="eswanson">202768</ModifiedByID>
         <CreateTime Title="2010-02-05 15:49:36 EST">1265402976764</CreateTime>
         <ModifyTime Title="2010-02-05 19:04:29 EST">1265414669478</ModifyTime>
         <SecurityModel>Controlled</SecurityModel>
         <Name>Cenzic Detects an Apache Integer Overflow Vulnerability</Name>
         <Summary>Weekly product update – Cenzic detects an Apache Integer Overflow Vulnerability</Summary>
         <Description>&lt;p&gt;As of February 5, 2010 Cenzic now detects an &lt;a title="Apache Integer Overflow Vulnerability" href="http://www.securityfocus.com/bid/37966/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 37966&lt;/strong&gt;).&amp;nbsp; An attacker can exploit&amp;nbsp;the Apache remote integer overflow vulnerability&amp;nbsp;and execute arbitrary code.&amp;nbsp; Successful exploits will compromise affected computers.&amp;nbsp; Failed exploit attempts will result in a denial-of-service condition.&amp;nbsp; Note that this issue affects platforms on which 'sizeof(int)' is less than 'sizeof(long)'.&amp;nbsp; In particular, this occurs on some 64-bit architectures.&amp;nbsp; Versions prior to Apache 1.3.42 are vulnerable.&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;
  &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</Description>
         <ResourceTypeID ObjectClass="ResourceType" Title="Item:Link">9</ResourceTypeID>
         <ContentType>application/xml</ContentType>
         <ContentDocument>
          <ItemProperties>
                <CommonProperties>
                 <Hidden>false</Hidden>

                 <Keywords>
                  <Keyword>apache vulnerability</Keyword>

       </Keywords>

                 <Links>
                  <Link>
                   <Title>Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow Vulnerability</Title>

                   <Synopsis>Learn more about this vulnerability on Security Focus</Synopsis>

                   <URL>http://www.securityfocus.com/bid/37966/info</URL>

        </Link>

       </Links>

      </CommonProperties>

                <RemoteInfo>
                 <UserAgent>Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB6.3; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)</UserAgent>

                 <RemoteHost>127.0.0.1</RemoteHost>

                 <RemoteAddr>127.0.0.1</RemoteAddr>

                 <RemoteUser>eswanson</RemoteUser>

                 <ForwardedFor>64.60.123.45</ForwardedFor>

      </RemoteInfo>

     </ItemProperties>
         </ContentDocument>
        </Resource>
        <Shares/>
        <Subjects/>
        <UserPermissions>
         <CanDelete>false</CanDelete>
         <CanDiscover>true</CanDiscover>
         <CanEdit>false</CanEdit>
         <CanEditPermissions>false</CanEditPermissions>
         <CanRead>true</CanRead>
        </UserPermissions>
        <CommentInfo>
         <CommentChannelRef AllowAnonymous="true" Inherited="true">
          <ChannelID ObjectClass="Channel" Title="[Public] Public Comments">204329</ChannelID>
          <UserPermissions>
           <CanCreateChannelItem>false</CanCreateChannelItem>
           <CanDelete>false</CanDelete>
           <CanDiscover>true</CanDiscover>
           <CanEdit>false</CanEdit>
           <CanEditPermissions>false</CanEditPermissions>
           <CanPublish>false</CanPublish>
           <CanRead>true</CanRead>
          </UserPermissions>
         </CommentChannelRef>
         <CommentCount>0</CommentCount>
        </CommentInfo>
       </Item>
       <Item>
        <Resource>
         <ObjectID>250174</ObjectID>
         <ObjectClass>Resource</ObjectClass>
         <OwnerID ObjectClass="Domain" Title="[Weblog] Cenzic SmartAttack Updates for Web Vulnerabilities">202612</OwnerID>
         <CreatedByID ObjectClass="User" Title="eswanson">202768</CreatedByID>
         <ModifiedByID ObjectClass="User" Title="eswanson">202768</ModifiedByID>
         <CreateTime Title="2010-02-12 18:24:36 EST">1266017076917</CreateTime>
         <ModifyTime Title="2010-02-12 18:46:46 EST">1266018406522</ModifyTime>
         <SecurityModel>Controlled</SecurityModel>
         <Name>Cenzic Detects an IBM WAS Security Bypass Vulnerability</Name>
         <Summary>Weekly product update – Cenzic detects an IBM WAS Security Bypass Vulnerability</Summary>
         <Description>&lt;p&gt;As of February 12, 2010 Cenzic now detects an &lt;a title="IBM WAS Security Bypass Vulnerability" href="http://www.securityfocus.com/bid/38122/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;IBM WebSphere Application Server 'Requires SSL' Option Security Bypass Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 38122&lt;/strong&gt;).&amp;nbsp; IBM WebSphere Application Server (WAS) is prone to a security-bypass vulnerability.&amp;nbsp; Successful exploits allow attackers to bypass certain security restrictions, which may lead to other attacks.&amp;nbsp; This issue affects WAS 7.0 through 7.0.0.8.&lt;/p&gt;
  &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;
  &lt;p&gt;Have a great 3-day weekend everyone!&lt;/p&gt;
  &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</Description>
         <ResourceTypeID ObjectClass="ResourceType" Title="Item:Link">9</ResourceTypeID>
         <ContentType>application/xml</ContentType>
         <ContentDocument>
          <ItemProperties>
                <CommonProperties>
                 <Hidden>false</Hidden>

                 <Keywords>
                  <Keyword>IBM</Keyword>

       </Keywords>

                 <Links>
                  <Link>
                   <Title>IBM WebSphere Application Server 'Requires SSL' Option Security Bypass Vulnerability</Title>

                   <Synopsis>Learn more about this vulnerability on Security Focus</Synopsis>

                   <URL>http://www.securityfocus.com/bid/38122/info</URL>

        </Link>

       </Links>

      </CommonProperties>

                <RemoteInfo>
                 <UserAgent>Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB6.3; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)</UserAgent>

                 <RemoteHost>127.0.0.1</RemoteHost>

                 <RemoteAddr>127.0.0.1</RemoteAddr>

                 <RemoteUser>eswanson</RemoteUser>

                 <ForwardedFor>64.60.123.45</ForwardedFor>

      </RemoteInfo>

     </ItemProperties>
         </ContentDocument>
        </Resource>
        <Shares/>
        <Subjects/>
        <UserPermissions>
         <CanDelete>false</CanDelete>
         <CanDiscover>true</CanDiscover>
         <CanEdit>false</CanEdit>
         <CanEditPermissions>false</CanEditPermissions>
         <CanRead>true</CanRead>
        </UserPermissions>
        <CommentInfo>
         <CommentChannelRef AllowAnonymous="true" Inherited="true">
          <ChannelID ObjectClass="Channel" Title="[Public] Public Comments">204329</ChannelID>
          <UserPermissions>
           <CanCreateChannelItem>false</CanCreateChannelItem>
           <CanDelete>false</CanDelete>
           <CanDiscover>true</CanDiscover>
           <CanEdit>false</CanEdit>
           <CanEditPermissions>false</CanEditPermissions>
           <CanPublish>false</CanPublish>
           <CanRead>true</CanRead>
          </UserPermissions>
         </CommentChannelRef>
         <CommentCount>0</CommentCount>
        </CommentInfo>
       </Item>
       <Item>
        <Resource>
         <ObjectID>251422</ObjectID>
         <ObjectClass>Resource</ObjectClass>
         <OwnerID ObjectClass="Domain" Title="[Weblog] Cenzic SmartAttack Updates for Web Vulnerabilities">202612</OwnerID>
         <CreatedByID ObjectClass="User" Title="eswanson">202768</CreatedByID>
         <ModifiedByID ObjectClass="User" Title="eswanson">202768</ModifiedByID>
         <CreateTime Title="2010-02-19 21:13:41 EST">1266632021579</CreateTime>
         <ModifyTime Title="2010-02-19 21:20:59 EST">1266632459506</ModifyTime>
         <SecurityModel>Controlled</SecurityModel>
         <Name>Cenzic Detects a Sun Java System Web Server Denial Of Service Vulnerability</Name>
         <Summary>Weekly product update – Cenzic detects a Sun Java System Web Server Denial Of Service Vulnerability</Summary>
         <Description>&lt;p&gt;As of February 19, 2010 Cenzic now detects a &lt;a title="Suna Java DOS Vulnerability" href="http://www.securityfocus.com/bid/37909/info" target="_blank"&gt;&lt;u&gt;&lt;strong&gt;Sun Java System Web Server 'admin' Server Denial of Service Vulnerability&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt;&amp;nbsp;(&lt;strong&gt;BugtraqID 37909&lt;/strong&gt;).&amp;nbsp; An attacker can exploit this issue to crash the effected application, denying service to legitimate users.&amp;nbsp; Sun Java System Web Server 7.0 Update 6 is affected; other versions may also be vulnerable.&lt;/p&gt;
  &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;
  &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</Description>
         <ResourceTypeID ObjectClass="ResourceType" Title="Item:Link">9</ResourceTypeID>
         <ContentType>application/xml</ContentType>
         <ContentDocument>
          <ItemProperties>
                <CommonProperties>
                 <Hidden>false</Hidden>

                 <Keywords>
                  <Keyword>denial of service vulnerability</Keyword>

                  <Keyword>Sun</Keyword>

       </Keywords>

                 <Links>
                  <Link>
                   <Title>Sun Java System Web Server 'admin' Server Denial of Service Vulnerability</Title>

                   <Synopsis>Learn more about this vulnerability on Security Focus</Synopsis>

                   <URL>http://www.securityfocus.com/bid/37909/info</URL>

        </Link>

       </Links>

      </CommonProperties>

                <RemoteInfo>
                 <UserAgent>Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB6.4; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)</UserAgent>

                 <RemoteHost>127.0.0.1</RemoteHost>

                 <RemoteAddr>127.0.0.1</RemoteAddr>

                 <RemoteUser>eswanson</RemoteUser>

                 <ForwardedFor>64.60.123.45</ForwardedFor>

      </RemoteInfo>

     </ItemProperties>
         </ContentDocument>
        </Resource>
        <Shares/>
        <Subjects/>
        <UserPermissions>
         <CanDelete>false</CanDelete>
         <CanDiscover>true</CanDiscover>
         <CanEdit>false</CanEdit>
         <CanEditPermissions>false</CanEditPermissions>
         <CanRead>true</CanRead>
        </UserPermissions>
        <CommentInfo>
         <CommentChannelRef AllowAnonymous="true" Inherited="true">
          <ChannelID ObjectClass="Channel" Title="[Public] Public Comments">204329</ChannelID>
          <UserPermissions>
           <CanCreateChannelItem>false</CanCreateChannelItem>
           <CanDelete>false</CanDelete>
           <CanDiscover>true</CanDiscover>
           <CanEdit>false</CanEdit>
           <CanEditPermissions>false</CanEditPermissions>
           <CanPublish>false</CanPublish>
           <CanRead>true</CanRead>
          </UserPermissions>
         </CommentChannelRef>
         <CommentCount>0</CommentCount>
        </CommentInfo>
       </Item>
       <Item>
        <Resource>
         <ObjectID>251823</ObjectID>
         <ObjectClass>Resource</ObjectClass>
         <OwnerID ObjectClass="Domain" Title="[Weblog] Cenzic SmartAttack Updates for Web Vulnerabilities">202612</OwnerID>
         <CreatedByID ObjectClass="User" Title="eswanson">202768</CreatedByID>
         <ModifiedByID ObjectClass="User" Title="eswanson">202768</ModifiedByID>
         <CreateTime Title="2010-02-26 12:55:14 EST">1267206914253</CreateTime>
         <ModifyTime Title="2010-02-26 12:56:41 EST">1267207001629</ModifyTime>
         <SecurityModel>Controlled</SecurityModel>
         <Name>Cenzic Detects a Sun Java System App Server HTTP TRACE Information Disclosure Vulnerability </Name>
         <Summary>Weekly product update – Cenzic detects a Sun Java System App Server HTTP TRACE Information Disclosure Vulnerability </Summary>
         <Description>&lt;p&gt;As of February 26, 2010 Cenzic now detects a &lt;a title="Sun Java System App Server HTTP TRACE Information Disclosure Vulnerability" href="http://www.securityfocus.com/bid/37995/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Sun Java System App Server HTTP TRACE Information Disclosure Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 37995&lt;/strong&gt;).&amp;nbsp; The Sun Java System Application Server is prone to a remote information-disclosure vulnerability.&amp;nbsp; Attackers can exploit this issue to obtain potentially sensitive information that can aid in further attacks.&lt;/p&gt;
  &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;
  &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</Description>
         <ResourceTypeID ObjectClass="ResourceType" Title="Item:Link">9</ResourceTypeID>
         <ContentType>application/xml</ContentType>
         <ContentDocument>
          <ItemProperties>
                <CommonProperties>
                 <Hidden>false</Hidden>

                 <Keywords>
                  <Keyword>information disclosure vulnerability</Keyword>

       </Keywords>

                 <Links>
                  <Link>
                   <Title>Sun Java System App Server HTTP TRACE Information Disclosure Vulnerability</Title>

                   <Synopsis>Learn more about this vulnerability on Security Focus</Synopsis>

                   <URL>http://www.securityfocus.com/bid/37995/info</URL>

        </Link>

       </Links>

      </CommonProperties>

                <RemoteInfo>
                 <UserAgent>Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB6.4; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)</UserAgent>

                 <RemoteHost>127.0.0.1</RemoteHost>

                 <RemoteAddr>127.0.0.1</RemoteAddr>

                 <RemoteUser>eswanson</RemoteUser>

                 <ForwardedFor>64.60.123.45</ForwardedFor>

      </RemoteInfo>

     </ItemProperties>
         </ContentDocument>
        </Resource>
        <Shares/>
        <Subjects/>
        <UserPermissions>
         <CanDelete>false</CanDelete>
         <CanDiscover>true</CanDiscover>
         <CanEdit>false</CanEdit>
         <CanEditPermissions>false</CanEditPermissions>
         <CanRead>true</CanRead>
        </UserPermissions>
        <CommentInfo>
         <CommentChannelRef AllowAnonymous="true" Inherited="true">
          <ChannelID ObjectClass="Channel" Title="[Public] Public Comments">204329</ChannelID>
          <UserPermissions>
           <CanCreateChannelItem>false</CanCreateChannelItem>
           <CanDelete>false</CanDelete>
           <CanDiscover>true</CanDiscover>
           <CanEdit>false</CanEdit>
           <CanEditPermissions>false</CanEditPermissions>
           <CanPublish>false</CanPublish>
           <CanRead>true</CanRead>
          </UserPermissions>
         </CommentChannelRef>
         <CommentCount>0</CommentCount>
        </CommentInfo>
       </Item>
       <Item>
        <Resource>
         <ObjectID>252094</ObjectID>
         <ObjectClass>Resource</ObjectClass>
         <OwnerID ObjectClass="Domain" Title="[Weblog] Cenzic SmartAttack Updates for Web Vulnerabilities">202612</OwnerID>
         <CreatedByID ObjectClass="User" Title="eswanson">202768</CreatedByID>
         <ModifiedByID ObjectClass="User" Title="eswanson">202768</ModifiedByID>
         <CreateTime Title="2010-03-05 12:21:58 EST">1267809718391</CreateTime>
         <ModifyTime Title="2010-03-05 14:18:32 EST">1267816712988</ModifyTime>
         <SecurityModel>Controlled</SecurityModel>
         <Name>Cenzic Detects a PHP Validation Restriction-Bypass Vulnerability </Name>
         <Summary>Weekly product update – Cenzic detects a PHP Validation Restriction-Bypass Vulnerability </Summary>
         <Description>&lt;p&gt;As of March 5, 2010 Cenzic now detects a &lt;a title="PHP Validation Restriction-Bypass Vulnerability" href="http://www.securityfocus.com/bid/38431/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;PHP 'tempnam()' 'safe_mode' Validation Restriction-Bypass Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 38431&lt;/strong&gt;).&amp;nbsp; Successful exploits allow attackers to access files in unauthorized locations or create files in any writable directory. This vulnerability is an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code; the 'safe_mode' restrictions are assumed to isolate users from each other.&amp;nbsp; PHP 5.2.12 and prior versions are affected.&lt;/p&gt;
  &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;
  &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</Description>
         <ResourceTypeID ObjectClass="ResourceType" Title="Item:Link">9</ResourceTypeID>
         <ContentType>application/xml</ContentType>
         <ContentDocument>
          <ItemProperties>
                <CommonProperties>
                 <Hidden>false</Hidden>

                 <Keywords>
                  <Keyword>PHP vulnerability</Keyword>

       </Keywords>

                 <Links>
                  <Link>
                   <Title>PHP Validation Restriction-Bypass Vulnerability</Title>

                   <Synopsis>Learn more about this vulnerability on Security Focus</Synopsis>

                   <URL>http://www.securityfocus.com/bid/38431/info</URL>

        </Link>

       </Links>

      </CommonProperties>

                <RemoteInfo>
                 <UserAgent>Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB6.4; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)</UserAgent>

                 <RemoteHost>127.0.0.1</RemoteHost>

                 <RemoteAddr>127.0.0.1</RemoteAddr>

                 <RemoteUser>eswanson</RemoteUser>

                 <ForwardedFor>64.60.123.45</ForwardedFor>

      </RemoteInfo>

     </ItemProperties>
         </ContentDocument>
        </Resource>
        <Shares/>
        <Subjects/>
        <UserPermissions>
         <CanDelete>false</CanDelete>
         <CanDiscover>true</CanDiscover>
         <CanEdit>false</CanEdit>
         <CanEditPermissions>false</CanEditPermissions>
         <CanRead>true</CanRead>
        </UserPermissions>
        <CommentInfo>
         <CommentChannelRef AllowAnonymous="true" Inherited="true">
          <ChannelID ObjectClass="Channel" Title="[Public] Public Comments">204329</ChannelID>
          <UserPermissions>
           <CanCreateChannelItem>false</CanCreateChannelItem>
           <CanDelete>false</CanDelete>
           <CanDiscover>true</CanDiscover>
           <CanEdit>false</CanEdit>
           <CanEditPermissions>false</CanEditPermissions>
           <CanPublish>false</CanPublish>
           <CanRead>true</CanRead>
          </UserPermissions>
         </CommentChannelRef>
         <CommentCount>0</CommentCount>
        </CommentInfo>
       </Item>
       <Item>
        <Resource>
         <ObjectID>252347</ObjectID>
         <ObjectClass>Resource</ObjectClass>
         <OwnerID ObjectClass="Domain" Title="[Weblog] Cenzic SmartAttack Updates for Web Vulnerabilities">202612</OwnerID>
         <CreatedByID ObjectClass="User" Title="eswanson">202768</CreatedByID>
         <ModifiedByID ObjectClass="User" Title="eswanson">202768</ModifiedByID>
         <CreateTime Title="2010-03-12 14:29:47 EST">1268422187558</CreateTime>
         <ModifyTime Title="2010-03-12 14:31:06 EST">1268422266118</ModifyTime>
         <SecurityModel>Controlled</SecurityModel>
         <Name>Cenzic Detects an Apache Denial of Service Vulnerability </Name>
         <Summary>Weekly product update – Cenzic detects an Apache Denial of Service Vulnerability </Summary>
         <Description>&lt;p&gt;As of March 12, 2010 Cenzic now detects an &lt;a title="Apache DOS Vulnerability" href="http://www.securityfocus.com/bid/38491/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Apache mod_proxy_ajp Module Incoming Request Body Denial Of Service Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 38491&lt;/strong&gt;).&amp;nbsp; Successful exploits may allow remote attackers to cause denial-of-service conditions.&lt;/p&gt;
  &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;
  &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</Description>
         <ResourceTypeID ObjectClass="ResourceType" Title="Item:Link">9</ResourceTypeID>
         <ContentType>application/xml</ContentType>
         <ContentDocument>
          <ItemProperties>
                <CommonProperties>
                 <Hidden>false</Hidden>

                 <Keywords>
                  <Keyword>apache vulnerability</Keyword>

       </Keywords>

                 <Links>
                  <Link>
                   <Title>Apache mod_proxy_ajp Module Incoming Request Body Denial Of Service Vulnerability</Title>

                   <Synopsis>Learn more about this vulnerability on Security Focus</Synopsis>

                   <URL>http://www.securityfocus.com/bid/38491/info</URL>

        </Link>

       </Links>

      </CommonProperties>

                <RemoteInfo>
                 <UserAgent>Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB6.4; (R1 1.6); .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)</UserAgent>

                 <RemoteHost>127.0.0.1</RemoteHost>

                 <RemoteAddr>127.0.0.1</RemoteAddr>

                 <RemoteUser>eswanson</RemoteUser>

                 <ForwardedFor>64.60.123.45</ForwardedFor>

      </RemoteInfo>

     </ItemProperties>
         </ContentDocument>
        </Resource>
        <Shares/>
        <Subjects/>
        <UserPermissions>
         <CanDelete>false</CanDelete>
         <CanDiscover>true</CanDiscover>
         <CanEdit>false</CanEdit>
         <CanEditPermissions>false</CanEditPermissions>
         <CanRead>true</CanRead>
        </UserPermissions>
        <CommentInfo>
         <CommentChannelRef AllowAnonymous="true" Inherited="true">
          <ChannelID ObjectClass="Channel" Title="[Public] Public Comments">204329</ChannelID>
          <UserPermissions>
           <CanCreateChannelItem>false</CanCreateChannelItem>
           <CanDelete>false</CanDelete>
           <CanDiscover>true</CanDiscover>
           <CanEdit>false</CanEdit>
           <CanEditPermissions>false</CanEditPermissions>
           <CanPublish>false</CanPublish>
           <CanRead>true</CanRead>
          </UserPermissions>
         </CommentChannelRef>
         <CommentCount>0</CommentCount>
        </CommentInfo>
       </Item>
      </Items>
      <Filter>
       <ns3:Archive xmlns:ns3="urn:MyST-Technology.NodeFilter">
        <ns3:ConfigSpec>Monthly 0 1</ns3:ConfigSpec>
       </ns3:Archive>
      </Filter>
      <Archive>
       <ConfigSpec>Monthly 0 1</ConfigSpec>
       <ConfigSpecBase>Monthly</ConfigSpecBase>
       <Name>Monthly</Name>
       <Threshold>0</Threshold>
       <Count>98</Count>
       <Periods>
        <Period Selected="true">
         <Timestamp Title="2010-03-01 00:00:00 EST">1267419600814</Timestamp>
         <PeriodID>2010-03</PeriodID>
         <Label>March, 2010</Label>
         <Count>2</Count>
        </Period>
        <Period Selected="true">
         <Timestamp Title="2010-02-01 00:00:00 EST">1265000400814</Timestamp>
         <PeriodID>2010-02</PeriodID>
         <Label>February, 2010</Label>
         <Count>4</Count>
        </Period>
        <Period>
         <Timestamp Title="2010-01-01 00:00:00 EST">1262322000814</Timestamp>
         <PeriodID>2010-01</PeriodID>
         <Label>January, 2010</Label>
         <Count>4</Count>
        </Period>
        <Period>
         <Timestamp Title="2009-12-01 00:00:00 EST">1259643600814</Timestamp>
         <PeriodID>2009-12</PeriodID>
         <Label>December, 2009</Label>
         <Count>5</Count>
        </Period>
        <Period>
         <Timestamp Title="2009-11-01 00:00:00 EST">1257051600814</Timestamp>
         <PeriodID>2009-11</PeriodID>
         <Label>November, 2009</Label>
         <Count>4</Count>
        </Period>
        <Period>
         <Timestamp Title="2009-10-01 00:00:00 EDT">1254369600814</Timestamp>
         <PeriodID>2009-10</PeriodID>
         <Label>October, 2009</Label>
         <Count>5</Count>
        </Period>
        <Period>
         <Timestamp Title="2009-09-01 00:00:00 EDT">1251777600814</Timestamp>
         <PeriodID>2009-09</PeriodID>
         <Label>September, 2009</Label>
         <Count>4</Count>
        </Period>
        <Period>
         <Timestamp Title="2009-08-01 00:00:00 EDT">1249099200814</Timestamp>
         <PeriodID>2009-08</PeriodID>
         <Label>August, 2009</Label>
         <Count>4</Count>
        </Period>
        <Period>
         <Timestamp Title="2009-07-01 00:00:00 EDT">1246420800814</Timestamp>
         <PeriodID>2009-07</PeriodID>
         <Label>July, 2009</Label>
         <Count>5</Count>
        </Period>
        <Period>
         <Timestamp Title="2009-06-01 00:00:00 EDT">1243828800814</Timestamp>
         <PeriodID>2009-06</PeriodID>
         <Label>June, 2009</Label>
         <Count>4</Count>
        </Period>
        <Period>
         <Timestamp Title="2009-05-01 00:00:00 EDT">1241150400814</Timestamp>
         <PeriodID>2009-05</PeriodID>
         <Label>May, 2009</Label>
         <Count>5</Count>
        </Period>
        <Period>
         <Timestamp Title="2009-04-01 00:00:00 EST">1238562000814</Timestamp>
         <PeriodID>2009-04</PeriodID>
         <Label>April, 2009</Label>
         <Count>4</Count>
        </Period>
        <Period>
         <Timestamp Title="2009-03-01 00:00:00 EST">1235883600814</Timestamp>
         <PeriodID>2009-03</PeriodID>
         <Label>March, 2009</Label>
         <Count>5</Count>
        </Period>
        <Period>
         <Timestamp Title="2009-02-01 00:00:00 EST">1233464400814</Timestamp>
         <PeriodID>2009-02</PeriodID>
         <Label>February, 2009</Label>
         <Count>3</Count>
        </Period>
        <Period>
         <Timestamp Title="2009-01-01 00:00:00 EST">1230786000814</Timestamp>
         <PeriodID>2009-01</PeriodID>
         <Label>January, 2009</Label>
         <Count>7</Count>
        </Period>
        <Period>
         <Timestamp Title="2008-12-01 00:00:00 EST">1228107600814</Timestamp>
         <PeriodID>2008-12</PeriodID>
         <Label>December, 2008</Label>
         <Count>5</Count>
        </Period>
        <Period>
         <Timestamp Title="2008-11-01 00:00:00 EST">1225515600814</Timestamp>
         <PeriodID>2008-11</PeriodID>
         <Label>November, 2008</Label>
         <Count>3</Count>
        </Period>
        <Period>
         <Timestamp Title="2008-10-01 00:00:00 EDT">1222833600814</Timestamp>
         <PeriodID>2008-10</PeriodID>
         <Label>October, 2008</Label>
         <Count>5</Count>
        </Period>
        <Period>
         <Timestamp Title="2008-09-01 00:00:00 EDT">1220241600814</Timestamp>
         <PeriodID>2008-09</PeriodID>
         <Label>September, 2008</Label>
         <Count>4</Count>
        </Period>
        <Period>
         <Timestamp Title="2008-08-01 00:00:00 EDT">1217563200814</Timestamp>
         <PeriodID>2008-08</PeriodID>
         <Label>August, 2008</Label>
         <Count>5</Count>
        </Period>
        <Period>
         <Timestamp Title="2008-07-01 00:00:00 EDT">1214884800814</Timestamp>
         <PeriodID>2008-07</PeriodID>
         <Label>July, 2008</Label>
         <Count>4</Count>
        </Period>
        <Period>
         <Timestamp Title="2008-06-01 00:00:00 EDT">1212292800814</Timestamp>
         <PeriodID>2008-06</PeriodID>
         <Label>June, 2008</Label>
         <Count>4</Count>
        </Period>
        <Period>
         <Timestamp Title="2008-05-01 00:00:00 EDT">1209614400814</Timestamp>
         <PeriodID>2008-05</PeriodID>
         <Label>May, 2008</Label>
         <Count>3</Count>
        </Period>
       </Periods>
      </Archive>
     </GetChannel_Result>
    </MySmartChannels>
