<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.0" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>imei Addmimistrator's BugBlog</title>
	<link>http://myimei.com/security</link>
	<description>imei's security Advisories and researches</description>
	<pubDate>Thu, 06 Dec 2007 10:34:31 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0</generator>
	<language>en</language>
			<item>
		<title>SupportSuite 3.11.01~ Multiple file ~ PHP SELF XSS</title>
		<link>http://myimei.com/security/2007-12-06/supportsuite-31101-multiple-file-php-self-xss.html</link>
		<comments>http://myimei.com/security/2007-12-06/supportsuite-31101-multiple-file-php-self-xss.html#comments</comments>
		<pubDate>Thu, 06 Dec 2007 10:34:31 +0000</pubDate>
		<dc:creator>imei</dc:creator>
		
	<category>Support Softwares</category>
		<guid isPermaLink="false">http://myimei.com/security/2007-12-06/supportsuite-31101-multiple-file-php-self-xss.html</guid>
		<description><![CDATA[&#8212;&#8212;-Summary&#8212;&#8212;
Software: SupportSuite
Sowtware&#8217;s Web Site: http://www.kayako.com
Versions: 3.00.32
Class: Remote
Status: Unpatched
Exploit: Available
Solution: Not Available
Discovered by: imei Addmimistrator
Risk Level: Medium
&#8212;&#8212;Description&#8212;&#8211;
Supportsuite , a great product of kayako, Ideal for providing ticket based support, is prone to XSS attack in multiple internal files.{more than 300 files}
Use of unsafe variable PHP_SELF in so many files of supprtsuite, makes this program vulnerable against [...]]]></description>
		<wfw:commentRSS>http://myimei.com/security/2007-12-06/supportsuite-31101-multiple-file-php-self-xss.html/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Olate Download 3.4.2 ~ userupload.php ~ Upload Executable Files</title>
		<link>http://myimei.com/security/2007-09-01/olate-download-342-useruploadphp-upload-executable-files.html</link>
		<comments>http://myimei.com/security/2007-09-01/olate-download-342-useruploadphp-upload-executable-files.html#comments</comments>
		<pubDate>Fri, 31 Aug 2007 21:25:09 +0000</pubDate>
		<dc:creator>imei</dc:creator>
		
	<category>Olate</category>
		<guid isPermaLink="false">http://myimei.com/security/2007-09-01/olate-download-342-useruploadphp-upload-executable-files.html</guid>
		<description><![CDATA[&#8212;&#8212;-Summary&#8212;&#8212;
Software: Olate Download
Sowtware&#8217;s Web Site: http://www.olate.co.uk/
Versions: 3.4.2
Class: Remote
Status: Patched
Exploit: Available
Solution: Not Available
Discovered by: imei Addmimistrator
Risk Level: High
&#8212;&#8212;Description&#8212;&#8211;
Olate download is prone to Upload executable file in uploads folder, If admin specified users can upload files.
Olate does not check Extension of uploaded file, and store them with its original extension. So uploading .php and .cgi and etc. [...]]]></description>
		<wfw:commentRSS>http://myimei.com/security/2007-09-01/olate-download-342-useruploadphp-upload-executable-files.html/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Olate Download 3.4.2~uploads folder ~ directory traversal</title>
		<link>http://myimei.com/security/2007-09-01/olate-download-342uploads-folder-directory-traversal.html</link>
		<comments>http://myimei.com/security/2007-09-01/olate-download-342uploads-folder-directory-traversal.html#comments</comments>
		<pubDate>Fri, 31 Aug 2007 21:24:04 +0000</pubDate>
		<dc:creator>imei</dc:creator>
		
	<category>Olate</category>
		<guid isPermaLink="false">http://myimei.com/security/2007-09-01/olate-download-342uploads-folder-directory-traversal.html</guid>
		<description><![CDATA[&#8212;&#8212;-Summary&#8212;&#8212;
Software: Olate Download
Sowtware&#8217;s Web Site: http://www.olate.co.uk/
Versions: 3.4.2
Class: Remote
Status: Patched
Exploit: Available
Solution: Available
Discovered by: imei addmimistrator
Risk Level: Low
&#8212;&#8212;Description&#8212;&#8211;
Olate download is prone to directory traversal in Uploads folder.
Directory traversal is usually not such an important security bug to report; But not in a spacial folder like Uploads. DIR Traversal bugs are not important because web applications have almost [...]]]></description>
		<wfw:commentRSS>http://myimei.com/security/2007-09-01/olate-download-342uploads-folder-directory-traversal.html/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Olate Download 3.4.2~download.php ~ sql injection</title>
		<link>http://myimei.com/security/2007-08-22/olate-download-342downloadphp-sql-injection.html</link>
		<comments>http://myimei.com/security/2007-08-22/olate-download-342downloadphp-sql-injection.html#comments</comments>
		<pubDate>Wed, 22 Aug 2007 17:58:40 +0000</pubDate>
		<dc:creator>imei</dc:creator>
		
	<category>Olate</category>
		<guid isPermaLink="false">http://myimei.com/security/2007-08-22/olate-download-342downloadphp-sql-injection.html</guid>
		<description><![CDATA[——————-Summary—————-
Software: Olate Download
Sowtware’s Web Site: http://www.olate.co.uk/
Versions: 3.4.2
Class: Remote
Status: Patched
Exploit: Available
Solution: Not Available
Discovered by: imei addmimistrator
Risk Level: Middel
—————–Description—————
Olate download is prone to SQL injection in download.php file.
Lack of programmer&#8217;s knowledge about HTTP headers and process of assigning value to predefined global arrays, resulted to this bug.With a shallow look, on line app. 118-127 you&#8217;ll understand that [...]]]></description>
		<wfw:commentRSS>http://myimei.com/security/2007-08-22/olate-download-342downloadphp-sql-injection.html/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Olate Download 3.4.2~modules/core/fldm.php~comments tag [url] XSS</title>
		<link>http://myimei.com/security/2007-08-22/olate-download-342modulescorefldmphpcomments-tag-url-xss.html</link>
		<comments>http://myimei.com/security/2007-08-22/olate-download-342modulescorefldmphpcomments-tag-url-xss.html#comments</comments>
		<pubDate>Wed, 22 Aug 2007 17:47:32 +0000</pubDate>
		<dc:creator>imei</dc:creator>
		
	<category>Olate</category>
		<guid isPermaLink="false">http://myimei.com/security/2007-08-22/olate-download-342modulescorefldmphpcomments-tag-url-xss.html</guid>
		<description><![CDATA[——————-Summary—————-
Software: Olate Download
Sowtware’s Web Site: http://www.olate.co.uk/
Versions: 3.4.2
Class: Remote
Status: Patched
Exploit: Available
Solution: Not Available
Discovered by: imei addmimistrator
Risk Level: Middel
—————–Description—————
Olate download is prone to Cross site scripting, cause of simple code replacing for comments in mentioned file
 bug is in line about 231, that programmers simply replaced some patterns with some equivalents.
Usually, phrasing codes are a complicated process [...]]]></description>
		<wfw:commentRSS>http://myimei.com/security/2007-08-22/olate-download-342modulescorefldmphpcomments-tag-url-xss.html/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Olate Download 3.4.2~modules/core/uim.php~XSS</title>
		<link>http://myimei.com/security/2007-08-22/olate-download-342modulescoreuimphpxss.html</link>
		<comments>http://myimei.com/security/2007-08-22/olate-download-342modulescoreuimphpxss.html#comments</comments>
		<pubDate>Wed, 22 Aug 2007 17:47:23 +0000</pubDate>
		<dc:creator>imei</dc:creator>
		
	<category>Olate</category>
		<guid isPermaLink="false">http://myimei.com/security/2007-08-22/olate-download-342modulescoreuimphpxss.html</guid>
		<description><![CDATA[——————-Summary—————-
Software: Olate Download
Sowtware’s Web Site: http://www.olate.co.uk/
Versions: 3.4.2
Class: Remote
Status: Patched
Exploit: Available
Solution: Not Available
Discovered by: imei addmimistrator
Risk Level: Middel
—————–Description—————
Olate download is prone to Cross site scripting, cause of trusting to unsafe variable, $_SERVER[&#8217;PHP_SELF&#8217;].
 Programmers team, trusted that $_SERVER[&#8217;PHP_SELF&#8217;] contained executed php file. I was reading bug report of this issue in php support site. it was reported [...]]]></description>
		<wfw:commentRSS>http://myimei.com/security/2007-08-22/olate-download-342modulescoreuimphpxss.html/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Olate Download 3.4.1 ~ environment.php ~ Code Execution</title>
		<link>http://myimei.com/security/2007-08-17/olate-download-341-environmentphpphp-code-execution.html</link>
		<comments>http://myimei.com/security/2007-08-17/olate-download-341-environmentphpphp-code-execution.html#comments</comments>
		<pubDate>Fri, 17 Aug 2007 11:38:06 +0000</pubDate>
		<dc:creator>imei</dc:creator>
		
	<category>Olate</category>
		<guid isPermaLink="false">http://myimei.com/security/2007-08-17/olate-download-341-environmentphpphp-code-execution.html</guid>
		<description><![CDATA[——————-Summary—————-
Software: Olate Download
Sowtware’s Web Site: http://www.olate.co.uk/
Versions: 3.4.1
Class: Remote
Status: Patched
Exploit: Available
Solution: Available
Discovered by: imei addmimistrator
Risk Level: High
—————–Description—————
 Olate is prone to code execution vulnerability cause of trusting to user supplied inputs in environment.php file, that is a very unusable file in software.

 Check out lines 86-87,
Client Version: < ?php eval("echo $pdo->getAttribute(PDO::ATTR_CLIENT_VERSION);&#8221;); ?>]]></description>
		<wfw:commentRSS>http://myimei.com/security/2007-08-17/olate-download-341-environmentphpphp-code-execution.html/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Olate Download 3.4.1 ~ admin.php ~ authentication bypassing</title>
		<link>http://myimei.com/security/2007-08-16/olate-download-341adminphpauthentication-bypassing.html</link>
		<comments>http://myimei.com/security/2007-08-16/olate-download-341adminphpauthentication-bypassing.html#comments</comments>
		<pubDate>Wed, 15 Aug 2007 21:25:38 +0000</pubDate>
		<dc:creator>imei</dc:creator>
		
	<category>Olate</category>
		<guid isPermaLink="false">http://myimei.com/security/2007-08-16/olate-download-341adminphpauthentication-bypassing.html</guid>
		<description><![CDATA[——————-Summary—————-
Software: Olate Download
Sowtware’s Web Site: http://www.olate.co.uk/
Versions: 3.4.1
Status: Patched
Exploit: Available
Solution: Not Available
Discovered by: imei addmimistrator
Risk Level: High
—————–Description—————
There is some flews in Olate Download software, one of the popular files&#8217; links list, Ideal for download sites, that results to bypassing authentication of site&#8217;s admin. An attacker can gain access to Admin area have full control permissions to [...]]]></description>
		<wfw:commentRSS>http://myimei.com/security/2007-08-16/olate-download-341adminphpauthentication-bypassing.html/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>MyBB 1.1.7 ~ admin/global.php ~ XSS Attack</title>
		<link>http://myimei.com/security/2006-08-17/mybb-117-adminglobalphp-xss-attack.html</link>
		<comments>http://myimei.com/security/2006-08-17/mybb-117-adminglobalphp-xss-attack.html#comments</comments>
		<pubDate>Thu, 17 Aug 2006 12:38:51 +0000</pubDate>
		<dc:creator>imei</dc:creator>
		
	<category>MyBB</category>
	<category>Forum Software</category>
		<guid isPermaLink="false">http://myimei.com/security/2006-08-17/mybb-117-adminglobalphp-xss-attack.html</guid>
		<description><![CDATA[——————-Summary—————-
Software: MyBB
Sowtware’s Web Site: http://www.mybboard.com
Versions: 1.1.7
Class: Remote
Status: Unpatched
Exploit: Available
Solution: Available
Discovered by: imei addmimistrator
Risk Level: Medium
—————–Description—————
There is some security bug in MyBB 1.1.7 software (latest version fully patched) file admin/global.php  that allows attacker performe an XSS attack.
Bug is in result of trust to variable $_SERVER[PHP_SELF] that may dont point to script that is executing and [...]]]></description>
		<wfw:commentRSS>http://myimei.com/security/2006-08-17/mybb-117-adminglobalphp-xss-attack.html/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>MyBB 1.1.7~ htmlspeacialchar_uni(), fixjavascript(), functions_post.php ~[url]XSS attack</title>
		<link>http://myimei.com/security/2006-08-15/mybb-117-htmlspeacialchar_uni-fixjavascript-functions_postphp-urlxss-attack.html</link>
		<comments>http://myimei.com/security/2006-08-15/mybb-117-htmlspeacialchar_uni-fixjavascript-functions_postphp-urlxss-attack.html#comments</comments>
		<pubDate>Tue, 15 Aug 2006 06:01:11 +0000</pubDate>
		<dc:creator>imei</dc:creator>
		
	<category>MyBB</category>
	<category>Forum Software</category>
		<guid isPermaLink="false">http://myimei.com/security/2006-08-15/mybb-117-htmlspeacialchar_uni-fixjavascript-functions_postphp-urlxss-attack.html</guid>
		<description><![CDATA[——————-Summary—————-
Software: MyBB
Sowtware’s Web Site: http://www.mybboard.com
Versions: 1.1.7
Class: Remote
Status: Unpatched
Exploit: Available
Solution: Available
Discovered by: imei addmimistrator
Risk Level: low
—————–Description—————
There is a security bug in MyBB 1.1.7 software (latest version fully patched) file functions_post.php  that allows attacker performe an XSS attack.
Bug is in result of poor regullar expression for url patterns, also allowing unicode entries to bypass fixjavascript()&#8217;s checks [...]]]></description>
		<wfw:commentRSS>http://myimei.com/security/2006-08-15/mybb-117-htmlspeacialchar_uni-fixjavascript-functions_postphp-urlxss-attack.html/feed/</wfw:commentRSS>
		</item>
	</channel>
</rss>
