<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Vulnerable InforMation And IT News &#187; vul news</title>
	<atom:link href="http://www.vul.kr/category/vulnerable-information/vul-news/feed" rel="self" type="application/rss+xml" />
	<link>http://www.vul.kr</link>
	<description>vulnerable security xss sql injection exploit bugs 0day zero-day paper news code</description>
	<lastBuildDate>Wed, 08 Sep 2010 06:06:07 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Microsoft Office Excel SxView Record Parsing Remote Code Execution Vulnerability</title>
		<link>http://www.vul.kr/microsoft-office-excel-sxview-record-parsing-remote-code-execution-vulnerability</link>
		<comments>http://www.vul.kr/microsoft-office-excel-sxview-record-parsing-remote-code-execution-vulnerability#comments</comments>
		<pubDate>Wed, 09 Jun 2010 08:39:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[0day]]></category>
		<category><![CDATA[Vulnerable InforMation]]></category>
		<category><![CDATA[vul news]]></category>
		<category><![CDATA[Microsoft Office Excel]]></category>
		<category><![CDATA[Remote Code Execution]]></category>

		<guid isPermaLink="false">http://www.vul.kr/?p=1371</guid>
		<description><![CDATA[<p>CVE ID<br />
CVE-2010-0821<br />
Affected Vendors<br />
Microsoft</p>
<p>Affected Products<br />
Office Excel</p>
<p>TippingPoint™ IPS Customer Protection<br />
TippingPoint IPS customers are protected against this vulnerability by Digital Vaccine protection filter ID 9244. For further product information on the TippingPoint IPS:<br />
http://www.tippingpoint.com<br />
Vulnerability Details<br />
This vulnerability allows remote attackers to execute arbitrary code on vulnerable <a href='http://www.vul.kr/microsoft-office-excel-sxview-record-parsing-remote-code-execution-vulnerability' rel="nofollow"><br> <br>[Read All About This Article]</a></p>]]></description>
			<content:encoded><![CDATA[<p>CVE ID<br />
CVE-2010-0821<br />
Affected Vendors<br />
Microsoft</p>
<p>Affected Products<br />
Office Excel</p>
<p>TippingPoint™ IPS Customer Protection<br />
TippingPoint IPS customers are protected against this vulnerability by Digital Vaccine protection filter ID 9244. For further product information on the TippingPoint IPS:<br />
http://www.tippingpoint.com<br />
Vulnerability Details<br />
This vulnerability allows remote attackers to execute arbitrary code on vulnerable <a href='http://www.vul.kr/microsoft-office-excel-sxview-record-parsing-remote-code-execution-vulnerability' rel="nofollow"><br> <br>[Read All About This Article]</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.vul.kr/microsoft-office-excel-sxview-record-parsing-remote-code-execution-vulnerability/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft IIS FTP Service Code Execution and DoS Vulnerability</title>
		<link>http://www.vul.kr/microsoft-iis-ftp-service-code-execution-and-dos-vulnerability</link>
		<comments>http://www.vul.kr/microsoft-iis-ftp-service-code-execution-and-dos-vulnerability#comments</comments>
		<pubDate>Sat, 31 Oct 2009 05:47:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Vulnerable InforMation]]></category>
		<category><![CDATA[vul news]]></category>
		<category><![CDATA[Code Execution]]></category>
		<category><![CDATA[Microsoft IIS FTP Service]]></category>

		<guid isPermaLink="false">http://www.vul.kr/?p=1280</guid>
		<description><![CDATA[<p>The vulnerabilities could allow remote code execution (RCE) on systems running FTP Service on IIS 5.0, or denial of service (DoS) on systems running FTP Service on IIS 5.0, IIS 5.1, IIS 6.0 or IIS 7.0. </p>
<p>Credit:<br />
The information has been provided by Kingcope and Microsoft.<br />
The original article can be found at: http://www.microsoft.com/technet/security/bulletin/MS09-053.mspx  </p>
<p>Vulnerable Systems:<br />
 * IIS 5.0 (FTP Service 5.0)<br />
 * IIS 5.1 (FTP Service 5.1)<br <a href='http://www.vul.kr/microsoft-iis-ftp-service-code-execution-and-dos-vulnerability' rel="nofollow"><br> <br>[Read All About This Article]</a></p>]]></description>
			<content:encoded><![CDATA[<p>The vulnerabilities could allow remote code execution (RCE) on systems running FTP Service on IIS 5.0, or denial of service (DoS) on systems running FTP Service on IIS 5.0, IIS 5.1, IIS 6.0 or IIS 7.0. </p>
<p>Credit:<br />
The information has been provided by Kingcope and Microsoft.<br />
The original article can be found at: http://www.microsoft.com/technet/security/bulletin/MS09-053.mspx  </p>
<p>Vulnerable Systems:<br />
 * IIS 5.0 (FTP Service 5.0)<br />
 * IIS 5.1 (FTP Service 5.1)<br <a href='http://www.vul.kr/microsoft-iis-ftp-service-code-execution-and-dos-vulnerability' rel="nofollow"><br> <br>[Read All About This Article]</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.vul.kr/microsoft-iis-ftp-service-code-execution-and-dos-vulnerability/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Kernel Multiple Vulnerabilities</title>
		<link>http://www.vul.kr/windows-kernel-multiple-vulnerabilities</link>
		<comments>http://www.vul.kr/windows-kernel-multiple-vulnerabilities#comments</comments>
		<pubDate>Sat, 31 Oct 2009 05:19:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Vulnerable InforMation]]></category>
		<category><![CDATA[vul news]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.vul.kr/?p=1278</guid>
		<description><![CDATA[<p>The most severe of the vulnerabilities could allow elevation of privilege if an attacker logged on to the system and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit any of these vulnerabilities. The vulnerabilities could not be exploited remotely or by anonymous users. </p>
<p>Credit:<br />
The information has been provided by Tavis Ormandy, Neel Mehta and Microsoft.<br />
The original article can be found at: <a href='http://www.vul.kr/windows-kernel-multiple-vulnerabilities' rel="nofollow"><br> <br>[Read All About This Article]</a></p>]]></description>
			<content:encoded><![CDATA[<p>The most severe of the vulnerabilities could allow elevation of privilege if an attacker logged on to the system and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit any of these vulnerabilities. The vulnerabilities could not be exploited remotely or by anonymous users. </p>
<p>Credit:<br />
The information has been provided by Tavis Ormandy, Neel Mehta and Microsoft.<br />
The original article can be found at: <a href='http://www.vul.kr/windows-kernel-multiple-vulnerabilities' rel="nofollow"><br> <br>[Read All About This Article]</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.vul.kr/windows-kernel-multiple-vulnerabilities/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>vBulletin Cross Site Scripting Vulnerability</title>
		<link>http://www.vul.kr/vbulletin-cross-site-scripting-vulnerability</link>
		<comments>http://www.vul.kr/vbulletin-cross-site-scripting-vulnerability#comments</comments>
		<pubDate>Sat, 31 Oct 2009 05:15:18 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Vulnerable InforMation]]></category>
		<category><![CDATA[vul news]]></category>
		<category><![CDATA[css]]></category>
		<category><![CDATA[vBulletin]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.vul.kr/?p=1276</guid>
		<description><![CDATA[<p>An XSS flaw within the user profile page has recently been discovered. This could allow an attacker to carry out an action as a user or obtain access to a user&#8217;s account. To resolve this issue, it has been necessary to release a patch level version of the active versions of vBulletin. </p>
<p>Credit:</p>
<p>The information has been provided by MaXe.<br />
The original article can be found at: http://www.vbulletin.com/forum/showthread.php?t=319572   <a href='http://www.vul.kr/vbulletin-cross-site-scripting-vulnerability' rel="nofollow"><br> <br>[Read All About This Article]</a></p>]]></description>
			<content:encoded><![CDATA[<p>An XSS flaw within the user profile page has recently been discovered. This could allow an attacker to carry out an action as a user or obtain access to a user&#8217;s account. To resolve this issue, it has been necessary to release a patch level version of the active versions of vBulletin. </p>
<p>Credit:</p>
<p>The information has been provided by MaXe.<br />
The original article can be found at: http://www.vbulletin.com/forum/showthread.php?t=319572   <a href='http://www.vul.kr/vbulletin-cross-site-scripting-vulnerability' rel="nofollow"><br> <br>[Read All About This Article]</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.vul.kr/vbulletin-cross-site-scripting-vulnerability/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Joomla Component com_gameserver 1.0 (id) SQL Injection Vulnerability</title>
		<link>http://www.vul.kr/joomla-component-com_gameserver-1-0-id-sql-injection-vulnerability</link>
		<comments>http://www.vul.kr/joomla-component-com_gameserver-1-0-id-sql-injection-vulnerability#comments</comments>
		<pubDate>Thu, 03 Sep 2009 10:58:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Vulnerable InforMation]]></category>
		<category><![CDATA[vul news]]></category>
		<category><![CDATA[com_gameserver]]></category>
		<category><![CDATA[Joomla]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://www.vul.kr/?p=1233</guid>
		<description><![CDATA[<p>[o] Joomla Component com_gameserver 1.0 (id) SQL Injection Vulnerability</p>
<p>			&#8211;==[ Author ]==&#8211;<br />
[+] Author	: v3n0m<br />
[+] Contact	: v3n0m666[at]live[dot]com<br />
[+] Blog	: http://0wnage.wordpress.com/<br />
[+] Group	: YOGYACARDERLINK<br />
[+] Site	: http://yogyacarderlink.web.id/<br />
[+] Date	: September, 03rd 2009 [INDONESIA]<br />
*************************************************************************<br />
			&#8211;==[ Details ]==&#8211;<br />
[+] <a href='http://www.vul.kr/joomla-component-com_gameserver-1-0-id-sql-injection-vulnerability' rel="nofollow"><br> <br>[Read All About This Article]</a></p>]]></description>
			<content:encoded><![CDATA[<p>[o] Joomla Component com_gameserver 1.0 (id) SQL Injection Vulnerability</p>
<p>			&#8211;==[ Author ]==&#8211;<br />
[+] Author	: v3n0m<br />
[+] Contact	: v3n0m666[at]live[dot]com<br />
[+] Blog	: http://0wnage.wordpress.com/<br />
[+] Group	: YOGYACARDERLINK<br />
[+] Site	: http://yogyacarderlink.web.id/<br />
[+] Date	: September, 03rd 2009 [INDONESIA]<br />
*************************************************************************<br />
			&#8211;==[ Details ]==&#8211;<br />
[+] <a href='http://www.vul.kr/joomla-component-com_gameserver-1-0-id-sql-injection-vulnerability' rel="nofollow"><br> <br>[Read All About This Article]</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.vul.kr/joomla-component-com_gameserver-1-0-id-sql-injection-vulnerability/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A killer Windows 7 bug?</title>
		<link>http://www.vul.kr/a-killer-windows-7-bug</link>
		<comments>http://www.vul.kr/a-killer-windows-7-bug#comments</comments>
		<pubDate>Thu, 06 Aug 2009 01:38:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[IT News]]></category>
		<category><![CDATA[Vulnerable InforMation]]></category>
		<category><![CDATA[vul news]]></category>
		<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[Windows 7 bug]]></category>

		<guid isPermaLink="false">http://www.vul.kr/?p=986</guid>
		<description><![CDATA[<p>The blogosphere is abuzz over a newly publicized bug in Windows 7. I read about it yesterday on Chris123NT’s blog, where it was described as a “critical bug in Windows 7 RTM.” The story picked up momentum today when InfoWorld’s Randall Kennedy (the man behind the “Save XP” Astroturf campaign) published a sensational polemic: “Critical Windows 7 bug risks derailing product launch.” Tom Warren at Neowin called it “rather nasty” but sensibly concluded that it’s far from a <a href='http://www.vul.kr/a-killer-windows-7-bug' rel="nofollow"><br> <br>[Read All About This Article]</a></p>]]></description>
			<content:encoded><![CDATA[<p>The blogosphere is abuzz over a newly publicized bug in Windows 7. I read about it yesterday on Chris123NT’s blog, where it was described as a “critical bug in Windows 7 RTM.” The story picked up momentum today when InfoWorld’s Randall Kennedy (the man behind the “Save XP” Astroturf campaign) published a sensational polemic: “Critical Windows 7 bug risks derailing product launch.” Tom Warren at Neowin called it “rather nasty” but sensibly concluded that it’s far from a <a href='http://www.vul.kr/a-killer-windows-7-bug' rel="nofollow"><br> <br>[Read All About This Article]</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.vul.kr/a-killer-windows-7-bug/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Not only the iPhone: there are serious loopholes in mobile phone SMS</title>
		<link>http://www.vul.kr/not-only-the-iphone-there-are-serious-loopholes-in-mobile-phone-sms</link>
		<comments>http://www.vul.kr/not-only-the-iphone-there-are-serious-loopholes-in-mobile-phone-sms#comments</comments>
		<pubDate>Sun, 02 Aug 2009 09:10:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Hack News]]></category>
		<category><![CDATA[Vulnerable InforMation]]></category>
		<category><![CDATA[vul news]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[SMS]]></category>

		<guid isPermaLink="false">http://www.vul.kr/?p=911</guid>
		<description><![CDATA[<p>Recently held in Las Vegas Black Hat security conference (Black Hat security conference), there are researchers on how the model through a simple SMS, will be able to control the mobile phone they want to control from eavesdropping or theft of data. IPhone as a result mainly of a demonstration to the outside world that the iPhone will only affect users, but in fact quite a number of smartphone platforms, including Android and Windows Mobile, the SMS has the same flaw. The incident has aroused <a href='http://www.vul.kr/not-only-the-iphone-there-are-serious-loopholes-in-mobile-phone-sms' rel="nofollow"><br> <br>[Read All About This Article]</a></p>]]></description>
			<content:encoded><![CDATA[<p>Recently held in Las Vegas Black Hat security conference (Black Hat security conference), there are researchers on how the model through a simple SMS, will be able to control the mobile phone they want to control from eavesdropping or theft of data. IPhone as a result mainly of a demonstration to the outside world that the iPhone will only affect users, but in fact quite a number of smartphone platforms, including Android and Windows Mobile, the SMS has the same flaw. The incident has aroused <a href='http://www.vul.kr/not-only-the-iphone-there-are-serious-loopholes-in-mobile-phone-sms' rel="nofollow"><br> <br>[Read All About This Article]</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.vul.kr/not-only-the-iphone-there-are-serious-loopholes-in-mobile-phone-sms/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wordpress 0day Once More</title>
		<link>http://www.vul.kr/wordpress-0day-once-more</link>
		<comments>http://www.vul.kr/wordpress-0day-once-more#comments</comments>
		<pubDate>Fri, 31 Jul 2009 08:16:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[0day]]></category>
		<category><![CDATA[Vulnerable InforMation]]></category>
		<category><![CDATA[vul news]]></category>
		<category><![CDATA[0DAY]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.vul.kr/?p=870</guid>
		<description><![CDATA[<p>Today,i get a paper from milw0rm.com,which was written by ZFO team.I saw most contet of it and found wordpress was hacked of the lastest version. And also found that Securityfous own this wordpress 0day but not published.In my opinion , ZFO underground team also owns this 0day.<br />
We don&#8217;t know what is wordpress 0day is,sqlinjection?remote command execution?Remote file inclusion or Xss.<br />
But it seems to me that hackers can get webshell easily by this 0day.So please update your <a href='http://www.vul.kr/wordpress-0day-once-more' rel="nofollow"><br> <br>[Read All About This Article]</a></p>]]></description>
			<content:encoded><![CDATA[<p>Today,i get a paper from milw0rm.com,which was written by ZFO team.I saw most contet of it and found wordpress was hacked of the lastest version. And also found that Securityfous own this wordpress 0day but not published.In my opinion , ZFO underground team also owns this 0day.<br />
We don&#8217;t know what is wordpress 0day is,sqlinjection?remote command execution?Remote file inclusion or Xss.<br />
But it seems to me that hackers can get webshell easily by this 0day.So please update your <a href='http://www.vul.kr/wordpress-0day-once-more' rel="nofollow"><br> <br>[Read All About This Article]</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.vul.kr/wordpress-0day-once-more/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
