<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ajay - On the Road called Life &#187; cross-site-scripting</title>
	<atom:link href="http://ajaydsouza.com/archives/tag/cross-site-scripting/feed/" rel="self" type="application/rss+xml" />
	<link>http://ajaydsouza.com</link>
	<description>Blogging, WordPress, Work and Life</description>
	<lastBuildDate>Sun, 13 May 2012 14:37:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Security Patch Released for Simple Machines</title>
		<link>http://ajaydsouza.com/archives/2006/10/30/security-patch-released-for-simple-machines/</link>
		<comments>http://ajaydsouza.com/archives/2006/10/30/security-patch-released-for-simple-machines/#comments</comments>
		<pubDate>Mon, 30 Oct 2006 11:22:46 +0000</pubDate>
		<dc:creator>Ajay</dc:creator>
				<category><![CDATA[Computers & Technology]]></category>
		<category><![CDATA[cross-site-scripting]]></category>
		<category><![CDATA[forums]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[simple-machines]]></category>
		<category><![CDATA[smf]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://ajaydsouza.com/archives/2006/10/30/security-patch-released-for-simple-machines/</guid>
		<description><![CDATA[Simple Machines has just released a security patch for SMF. This release addresses a cross-site scripting vulnerability in the search function. The fix for the 1.0.x has been released as 1.0.9. The version number of 1.1RC3 has remained as is, but you need to download and update your SMF installation ASAP! Just last week my [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fajaydsouza.com%2Farchives%2F2006%2F10%2F30%2Fsecurity-patch-released-for-simple-machines%2F' data-shr_title='Security+Patch+Released+for+Simple+Machines'></a><a class='shareaholic-fbsend' data-shr_href='http%3A%2F%2Fajaydsouza.com%2Farchives%2F2006%2F10%2F30%2Fsecurity-patch-released-for-simple-machines%2F'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fajaydsouza.com%2Farchives%2F2006%2F10%2F30%2Fsecurity-patch-released-for-simple-machines%2F' data-shr_title='Security+Patch+Released+for+Simple+Machines'></a><a class='shareaholic-tweetbutton' data-shr_count='horizontal' data-shr_href='http%3A%2F%2Fajaydsouza.com%2Farchives%2F2006%2F10%2F30%2Fsecurity-patch-released-for-simple-machines%2F' data-shr_title='Security+Patch+Released+for+Simple+Machines'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetTop Automatic --><p><a href="http://www.simplemachines.org/">Simple Machines</a> has just released a security patch for SMF.</p>
<p>This release addresses a cross-site scripting vulnerability in the search function.</p>
<p>The fix for the 1.0.x has been released as 1.0.9. The version number of 1.1RC3 has remained as is, but you need to download and update your SMF installation ASAP!</p>
<p>Just last week <a href="http://ajaydsouza.com/archives/2006/10/29/ajaydsouzaorg-hacked/">my forum was hacked</a>. I&#8217;m not sure if this is the reason, but having your software vulnerable XSS is a sure shot way to getting hacked.</p>
<p>Read the <a href="http://www.simplemachines.org/community/index.php?topic=123285.0">complete release notification</a> or <a href="http://www.simplemachines.org/download/">download the latest version</a>.</p>
<h3>Direct Download:</h3>
<p>Download the files below (you may need to be registered to the forum) and replace the files in your installation with the php files in the package.</p>
<p><a href="http://www.simplemachines.org/community/index.php?action=dlattach;topic=123285.0;attach=20404">updated_files_SMF_1-0-9.zip</a> (102.59 KB)<br />
<a href="http://www.simplemachines.org/community/index.php?action=dlattach;topic=123285.0;attach=20420">smf_patch_1-0-9_1-1-rc3-1.tar.gz</a> (1.99 KB)<br />
<a href="http://www.simplemachines.org/community/index.php?action=dlattach;topic=123285.0;attach=20422">updated_files_SMF_1-1-rc3-1.zip</a> (179.11 KB)</p>
<div id="crp_related"><h4>Related Posts:</h4><ul><li><a href="http://ajaydsouza.com/archives/2006/10/29/ajaydsouzaorg-hacked/" rel="bookmark" class="crp_title">AjayDSouza.org Hacked!</a></li><li><a href="http://ajaydsouza.com/archives/2009/06/10/better-search-bug-fix-release/" rel="bookmark" class="crp_title">Better Search bug-fix release</a></li><li><a href="http://ajaydsouza.com/archives/2006/01/04/structural-changes/" rel="bookmark" class="crp_title">Structural Changes</a></li><li><a href="http://ajaydsouza.com/archives/2007/02/21/wordpress-211-and-209-update-files/" rel="bookmark" class="crp_title">WordPress 2.1.1 and 2.0.9 Update Files</a></li><li><a href="http://ajaydsouza.com/archives/2005/03/18/top100bloggerscom/" rel="bookmark" class="crp_title">Top100Bloggers.com</a></li><li>Powered by <a href="http://ajaydsouza.com/wordpress/plugins/contextual-related-posts/">Contextual Related Posts</a></li></ul></div><div class="shr-publisher-904"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic --><hr style="border-top:black solid 1px" /><a href="http://ajaydsouza.com/archives/2006/10/30/security-patch-released-for-simple-machines/">Security Patch Released for Simple Machines</a> was first posted on October 30, 2006 at 4:52 pm.<br />© 2003-2009 "<a href="http://ajaydsouza.com">Ajay - On the Road called Life</a>". Use of this feed is for personal non-commercial use only. If you are not reading this article in your feed reader, then the site is guilty of copyright infringement. Please <a href="http://ajaydsouza.com/contact/">contact me</a>.<br /><br /><span style="font-size: 0.8em">Feed enhanced by the <a href="http://ajaydsouza.com/wordpress/plugins/add-to-feed/">Add To Feed Plugin</a> by <a href="http://ajaydsouza.com/">Ajay D'Souza</a></span><br />]]></content:encoded>
			<wfw:commentRss>http://ajaydsouza.com/archives/2006/10/30/security-patch-released-for-simple-machines/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

