TITLE: b2evolution Cross-Site Scripting and SQL Injection SECUNIA ADVISORY ID: SA9650 VERIFY ADVISORY: http://www.secunia.com/advisories/9650/ CRITICAL: Moderately critical IMPACT: Cross Site Scripting, Manipulation of data, Exposure of sensitive information WHERE: From remote SOFTWARE: b2evolution 0.x DESCRIPTION: Some vulnerabilities have been identified in b2evolution, which can be exploited by malicious people to conduct Cross-Site Scripting attacks and perform SQL injection. The vulnerabilities affect versions 0.8.2 and prior. SOLUTION: Update to version 0.8.2.2: http://prdownloads.sourceforge.net/evocms/b2evolution-0.8.2.2-2003-09-02.zip?download ORIGINAL ADVISORY: http://sourceforge.net/project/shownotes.php?release_id=181585 ---------------------------------------------------------------------- Secunia recommends that you verify all advisories you receive, by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. Contact details: Web : http://www.secunia.com/ E-mail : support@secunia.com Tel : +45 7020 5144 Fax : +45 7020 5145 ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://www.secunia.com/sec_adv_unsubscribe/?email=packet@packetstormsecurity.org ----------------------------------------------------------------------