<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>CVE : Nchovy &#51064;&#53552;&#45367; &#49828;&#53680; &#49468;&#53552;</title>
  <link type="text/html" href="http://nchovy.kr/security/cve" rel="alternate"/>
  <author>
    <name>NCHOVY &#51064;&#53552;&#45367; &#49828;&#53680; &#49468;&#53552;</name>
    <email>xeraph@nchovy.kr</email>
  </author>
  <entry>
    <title>CVE-2009-4168</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2009-4168</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2009-4168" rel="alternate"/>
    <content>Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and earlier for Joomla!, allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter in a tags action. Cross-site scripting (XSS) vulnerability in tagcloud.swf in the WP-Cumulus Plug-in before 1.23 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter.</content>
    <published>2010-03-10T00:00:00+09:00</published>
    <updated>2010-03-10T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2009-3555</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2009-3555</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2009-3555" rel="alternate"/>
    <content>The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.</content>
    <published>2010-03-10T00:00:00+09:00</published>
    <updated>2010-03-10T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-0946</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-0946</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-0946" rel="alternate"/>
    <content>SQL injection vulnerability in the Keep It Simple Stupid (KISS) Software Advertiser (com_ksadvertiser) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showcats action to index.php.</content>
    <published>2010-03-09T00:00:00+09:00</published>
    <updated>2010-03-09T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-0945</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-0945</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-0945" rel="alternate"/>
    <content>SQL injection vulnerability in the HotBrackets Tournament Brackets (com_hotbrackets) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.</content>
    <published>2010-03-09T00:00:00+09:00</published>
    <updated>2010-03-09T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-0944</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-0944</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-0944" rel="alternate"/>
    <content>Directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</content>
    <published>2010-03-09T00:00:00+09:00</published>
    <updated>2010-03-09T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-0943</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-0943</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-0943" rel="alternate"/>
    <content>Directory traversal vulnerability in the JA Showcase (com_jashowcase) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a jashowcase action to index.php.</content>
    <published>2010-03-09T00:00:00+09:00</published>
    <updated>2010-03-09T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-0942</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-0942</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-0942" rel="alternate"/>
    <content>Directory traversal vulnerability in the jVideoDirect (com_jvideodirect) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</content>
    <published>2010-03-09T00:00:00+09:00</published>
    <updated>2010-03-09T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-0941</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-0941</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-0941" rel="alternate"/>
    <content>Multiple cross-site scripting (XSS) vulnerabilities in eTek Systems Hit Counter 2.0 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) inc/login.php, (3) admin/index.php, and (4) admin/forgot.php.</content>
    <published>2010-03-09T00:00:00+09:00</published>
    <updated>2010-03-09T00:00:00+09:00</updated>
  </entry>
</feed>
