<?xml version="1.0" encoding="UTF-8" standalone="yes"?><rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:atom="http://www.w3.org/2005/Atom" xml:base="http://blog.cenzic.com/public/" version="2.0"><!--

MyST Blogsite® RSS Web Feed | Powered by MySmartChannels™ Weblog Application Server

MyST Blogsite and MySmartChannels are services of MyST Technology Partners, Inc.
For more information, including standard terms of service, see:
http://myst-technology.com and http://blogsite.com

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Customize this feed by adding any of the following URL parameters:

  description=none|summary|full (default=full)
  channelDescription=none|summary|full (default=value of 'description' parameter)
  itemDescription=none|summary|full (default=value of 'description' parameter)
  enhanced=true|false (default=false)
  limit=n (default=15)
  score=none|emoticon|simple|stars|text (default=text)
  smartPoints=true|false (default=true)
  sortKey=CreateTime|ModifyTime|Name|...any MyST-ML child element... (default=CreateTime)
  sortOrder=ascending|descending (default=descending)
--><channel>
     <title>Cenzic SmartAttack Updates for Web Vulnerabilities | Cenzic Security Blog</title><link>http://blog.cenzic.com/public/blog/202612</link><description>Latest web application vulnerabilities integrated into the Cenzic product suite.
        &lt;p&gt;This blog features the latest vulnerabilities in web / website applications (custom, commercial, and open-source) 
        that have been integrated into the Cenzic's website security product suite on a weekly basis.  
        These web application vulnerabilities include cross site scripting, 
        buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;
    </description><atom:link type="application/rss+xml" rel="self" href="http://blog.cenzic.com/public/rss/202612?"/><language>en-us</language><copyright>Copyright (C) 2009 Cenzic, Inc--All Rights Reserved -- This channel is part of the Cenzic Security Blog blogsite--Powered by MyST Blogsite®.</copyright><pubDate>Thu, 01 May 2008 13:00:50 -0400</pubDate><lastBuildDate>Fri, 05 Mar 2010 14:18:32 -0500</lastBuildDate><generator>MySmartChannels V3.0 (MyST Web Service Platform V6.00.0828)</generator><image><url>http://blog.cenzic.com/styles/blogsite/Cenzic/images/rss.jpg</url><height>31</height><width>88</width><link>http://blog.cenzic.com/public/blog/202612</link><title>Cenzic SmartAttack Updates for Web Vulnerabilities | Cenzic Security Blog</title><description>This blogsite contains information on all security topics ranging from web application security, security software, vulnerabilities, enterprise security, penetration testing and hacker news.</description></image>
       <category>Cross site request forgery</category><category>CSRF</category><category>Cross site Scripting</category><category>XSS</category><category>Buffer overflow</category><category>Session management</category><category>Session ID randomness</category><category>Privilege escalation</category><category>Session hijacking</category><category>SQL Injection</category>
       
       
      
    
     <item><title>Cenzic Detects a PHP Validation Restriction-Bypass Vulnerability</title><link>http://blog.cenzic.com/public/item/252094</link><description>Weekly product update – Cenzic detects a PHP Validation Restriction-Bypass Vulnerability &lt;p&gt;As of March 5, 2010 Cenzic now detects a &lt;a title="PHP Validation Restriction-Bypass Vulnerability" href="http://www.securityfocus.com/bid/38431/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;PHP 'tempnam()' 'safe_mode' Validation Restriction-Bypass Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 38431&lt;/strong&gt;).&amp;nbsp; Successful exploits allow attackers to access files in unauthorized locations or create files in any writable directory. This vulnerability is an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code; the 'safe_mode' restrictions are assumed to isolate users from each other.&amp;nbsp; PHP 5.2.12 and prior versions are affected.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/38431/info" target=%quot;_blank%quot;&gt;PHP Validation Restriction-Bypass Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/252094</guid><pubDate>Fri, 05 Mar 2010 12:21:58 -0500</pubDate>
        <category>PHP vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects a Sun Java System App Server HTTP TRACE Information Disclosure Vulnerability</title><link>http://blog.cenzic.com/public/item/251823</link><description>Weekly product update – Cenzic detects a Sun Java System App Server HTTP TRACE Information Disclosure Vulnerability &lt;p&gt;As of February 26, 2010 Cenzic now detects a &lt;a title="Sun Java System App Server HTTP TRACE Information Disclosure Vulnerability" href="http://www.securityfocus.com/bid/37995/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Sun Java System App Server HTTP TRACE Information Disclosure Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 37995&lt;/strong&gt;).&amp;nbsp; The Sun Java System Application Server is prone to a remote information-disclosure vulnerability.&amp;nbsp; Attackers can exploit this issue to obtain potentially sensitive information that can aid in further attacks.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/37995/info" target=%quot;_blank%quot;&gt;Sun Java System App Server HTTP TRACE Information Disclosure Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/251823</guid><pubDate>Fri, 26 Feb 2010 12:55:14 -0500</pubDate>
        <category>information disclosure vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects a Sun Java System Web Server Denial Of Service Vulnerability</title><link>http://blog.cenzic.com/public/item/251422</link><description>Weekly product update – Cenzic detects a Sun Java System Web Server Denial Of Service Vulnerability&lt;p&gt;As of February 19, 2010 Cenzic now detects a &lt;a title="Suna Java DOS Vulnerability" href="http://www.securityfocus.com/bid/37909/info" target="_blank"&gt;&lt;u&gt;&lt;strong&gt;Sun Java System Web Server 'admin' Server Denial of Service Vulnerability&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt;&amp;nbsp;(&lt;strong&gt;BugtraqID 37909&lt;/strong&gt;).&amp;nbsp; An attacker can exploit this issue to crash the effected application, denying service to legitimate users.&amp;nbsp; Sun Java System Web Server 7.0 Update 6 is affected; other versions may also be vulnerable.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/37909/info" target=%quot;_blank%quot;&gt;Sun Java System Web Server 'admin' Server Denial of Service Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/251422</guid><pubDate>Fri, 19 Feb 2010 21:13:41 -0500</pubDate>
        <category>denial of service vulnerability</category><category>Sun</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects an IBM WAS Security Bypass Vulnerability</title><link>http://blog.cenzic.com/public/item/250174</link><description>Weekly product update – Cenzic detects an IBM WAS Security Bypass Vulnerability&lt;p&gt;As of February 12, 2010 Cenzic now detects an &lt;a title="IBM WAS Security Bypass Vulnerability" href="http://www.securityfocus.com/bid/38122/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;IBM WebSphere Application Server 'Requires SSL' Option Security Bypass Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 38122&lt;/strong&gt;).&amp;nbsp; IBM WebSphere Application Server (WAS) is prone to a security-bypass vulnerability.&amp;nbsp; Successful exploits allow attackers to bypass certain security restrictions, which may lead to other attacks.&amp;nbsp; This issue affects WAS 7.0 through 7.0.0.8.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;Have a great 3-day weekend everyone!&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/38122/info" target=%quot;_blank%quot;&gt;IBM WebSphere Application Server 'Requires SSL' Option Security Bypass Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/250174</guid><pubDate>Fri, 12 Feb 2010 18:24:36 -0500</pubDate>
        <category>IBM</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects an Apache Integer Overflow Vulnerability</title><link>http://blog.cenzic.com/public/item/249608</link><description>Weekly product update – Cenzic detects an Apache Integer Overflow Vulnerability&lt;p&gt;As of February 5, 2010 Cenzic now detects an &lt;a title="Apache Integer Overflow Vulnerability" href="http://www.securityfocus.com/bid/37966/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 37966&lt;/strong&gt;).&amp;nbsp; An attacker can exploit&amp;nbsp;the Apache remote integer overflow vulnerability&amp;nbsp;and execute arbitrary code.&amp;nbsp; Successful exploits will compromise affected computers.&amp;nbsp; Failed exploit attempts will result in a denial-of-service condition.&amp;nbsp; Note that this issue affects platforms on which 'sizeof(int)' is less than 'sizeof(long)'.&amp;nbsp; In particular, this occurs on some 64-bit architectures.&amp;nbsp; Versions prior to Apache 1.3.42 are vulnerable.&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/37966/info" target=%quot;_blank%quot;&gt;Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/249608</guid><pubDate>Fri, 05 Feb 2010 15:49:36 -0500</pubDate>
        <category>apache vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item>
    </channel></rss>