Gentoo Archives: gentoo-announce

From: aliz@gentoo.org (Daniel Ahlberg)
To: gentoo-announce@g.o, bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com
Subject: [gentoo-announce] GLSA: phpwebsite (200309-03)
Date: Tue, 02 Sep 2003 08:47:54
Message-Id: 20030902085431.2130F9FBB1@noc.internal.fairytale.se
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200309-03
6 - - - ---------------------------------------------------------------------
7
8           PACKAGE : phpwebsite
9           SUMMARY : SQL Injection, DoS and XSS Vulnerabilities
10              DATE : 2003-09-02 08:54 UTC
11           EXPLOIT : remote
12 VERSIONS AFFECTED : <phpwebsite-0.9.3_p1
13     FIXED VERSION : >=phpwebsite-0.9.3_p1
14               CVE :
15
16 - - - ---------------------------------------------------------------------
17
18 phpwebsite contains an sql injection vulnerability in the calendar
19 module which allows the attacker to execute sql queries.
20
21 In addition phpwebsite is also vulnerable to XSS, more information
22 can be found in the full advisory.
23
24 Read the full advisory at:
25 http://marc.theaimsgroup.com/?l=bugtraq&m=106062021711496&w=2
26
27 SOLUTION
28
29 It is recommended that all Gentoo Linux users who are running
30 net-www/phpwebsite upgrade to phpwebsite-0.9.3_p1 as follows:
31
32 emerge sync
33 emerge phpwebsite
34 emerge clean
35
36 - - - ---------------------------------------------------------------------
37 aliz@g.o - GnuPG key is available at http://dev.gentoo.org/~aliz
38 - - - ---------------------------------------------------------------------
39 -----BEGIN PGP SIGNATURE-----
40 Version: GnuPG v1.2.3 (GNU/Linux)
41
42 iD8DBQE/VFrGfT7nyhUpoZMRAoFSAKChf1ZjKu8R0JwnRbE3DEkFP4SJ5ACfQCnY
43 XXjTcnVEuUXTG4YTF8EGpJ4=
44 =JhXo
45 -----END PGP SIGNATURE-----