<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Commenti a: e107 0.7.11 Preview Admin news Xss</title>
	<atom:link href="http://www.michelepapaleo.it/e107-0-7-11-preview-admin-news-xss/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.michelepapaleo.it/e107-0-7-11-preview-admin-news-xss/</link>
	<description></description>
	<lastBuildDate>Sat, 11 Feb 2012 19:07:00 +0100</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>Di: diggita.it</title>
		<link>http://www.michelepapaleo.it/e107-0-7-11-preview-admin-news-xss/#comment-220</link>
		<dc:creator>diggita.it</dc:creator>
		<pubDate>Wed, 03 Mar 2010 19:27:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.michelepapaleo.it/e107-0-7-11-preview-admin-news-xss/#comment-220</guid>
		<description>&lt;strong&gt;e107 0.7.11 Preview Admin news Xss...&lt;/strong&gt;

Questa vulnerabilità vale per la versione 0.7.11 del CMS e107 BUG: in submitnews.php le variabili $author_name, $itemtitle e $item non sono controllate, così vengono inviate all&#039; admin senza nessun filtro, che quindi può essere &quot;fregato&quot; da un event...</description>
		<content:encoded><![CDATA[<p><strong>e107 0.7.11 Preview Admin news Xss&#8230;</strong></p>
<p>Questa vulnerabilità vale per la versione 0.7.11 del CMS e107 BUG: in submitnews.php le variabili $author_name, $itemtitle e $item non sono controllate, così vengono inviate all&#8217; admin senza nessun filtro, che quindi può essere &#8220;fregato&#8221; da un event&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

