<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Powered By &#187; Patch</title>
	<atom:link href="http://www.powered-by.org/tag/patch/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.powered-by.org</link>
	<description>Content Management System News and Updates</description>
	<lastBuildDate>Fri, 23 Jul 2010 09:25:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>phpBB2</title>
		<link>http://www.powered-by.org/cms/forum/phpbb/phpbb2/</link>
		<comments>http://www.powered-by.org/cms/forum/phpbb/phpbb2/#comments</comments>
		<pubDate>Sun, 19 Apr 2009 09:50:06 +0000</pubDate>
		<dc:creator>powered-by.org</dc:creator>
				<category><![CDATA[PhpBB]]></category>
		<category><![CDATA[Forum]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://www.powered-by.org/cms/forum/phpbb/phpbb2/</guid>
		<description><![CDATA[phpBB2 was the predecessor of the present-day phpBB3. Developed during 2001-2002, the source code was written primarily to run on PHP 3.0 and 4.0 (version 2.0.13 upped the minimum requirement to PHP 4.0.3 due to a necessary security fix), and by the time that phpBB3 was released in late 2007, the developers and other team [...]]]></description>
			<content:encoded><![CDATA[<p>phpBB2 was the predecessor of the present-day phpBB3. Developed during 2001-2002, the source code was written primarily to run on PHP 3.0 and 4.0 (version 2.0.13 upped the minimum requirement to PHP 4.0.3 due to a necessary security fix), and by the time that phpBB3 was released in late 2007, the developers and other team members felt that it no longer met their quality coding standards, and announced plans for the retirement/end of support of 2.0.x within a few months of 3.0.0&#8242;s release. phpBB2 was never officially supported under PHP 5. Although many users had no problems running it after making a few changes to PHP 5&#8242;s default configuration settings, the teams chose not to offer support for this configuration.</p>
<p><span id="more-521"></span></p>
<p>Official support for phpBB2 ended on January 1, 2009, and the 2.0.x support forums have been locked. Furthermore all development for phpBB2, including security patches, has ceased as of February 1, 2009.[27] Other information pertaining to phpBB2 on the phpBB.com website will be removed over the coming months and phpBB2 will likely be fully phased out by the second half of 2009. However, a number of unofficial support sites for phpBB2 have formed to fill the void and will likely continue supporting phpBB2 indefinitely.</p>
<p>Many administrators still prefer to run phpBB2 because it provides a much simpler administration interface and has a thriving ecosystem of MODs (modifications) and styles that allow admins many options for customising the software to their liking. Others still run phpBB2 because they have installed many MODs, none of which can function in phpBB3.</p>
<p>The default theme in phpBB2 is named subSilver, and was designed by Tom &#8220;subBlue&#8221; Beddard. At the time that it premiered in 2001, it was a revolutionary new design for bulletin boards[citation needed], and many bulletin board themes since have borrowed many cues and design elements from subSilver.</p>
<p>Some of phpBB2&#8242;s major features included the following:</p>
<ul>
<li>A templated style system intended to allow easy customisation that keeps the PHP code separate from the HTML.</li>
<li>Support for internationalisation through a language pack system; 48 translations are available for phpBB2 as of 2007.</li>
<li>Compatibility with multiple database management systems including MySQL, PostgreSQL, Microsoft SQL Server, and Microsoft Access,</li>
<li>Easy customisations, including MODs and styles.</li>
</ul>
<p>The last official release of the 2.0.x line is 2.0.23, released on February 17, 2008. However, the code for phpBB 2.0.24 still remains, unreleased, in the SVN repository.</p>
<p>About PhpBB</p>
<p><a title="phpBB" href="http://www.powered-by.org/references/cms-index/phpbb/">phpBB</a> is a popular Internet forum package written in the PHP scripting language. The name &#8220;phpBB&#8221; is an abbreviation of PHP Bulletin Board. Available under the GNU General Public License, phpBB is a free software. phpBB was started by James Atkinson as a simple UBB-like forum for his own website &#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.powered-by.org/cms/forum/phpbb/phpbb2/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>New Security Updates for Drupal Web CMS</title>
		<link>http://www.powered-by.org/news/new-security-updates-for-drupal-web-cms/</link>
		<comments>http://www.powered-by.org/news/new-security-updates-for-drupal-web-cms/#comments</comments>
		<pubDate>Sun, 14 Dec 2008 12:50:08 +0000</pubDate>
		<dc:creator>powered-by.org</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[bug fixes]]></category>
		<category><![CDATA[DAM]]></category>
		<category><![CDATA[drupal]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[security issue]]></category>
		<category><![CDATA[security issues]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://www.powered-by.org/?p=87</guid>
		<description><![CDATA[Drupal is at it again with another round of updated releases. While not major releases, these new versions from Drupal do address a number of security fixes and bugs that were brought to their attention via Drupal’s bug tracking system. Drupal has announced that there will be no new features added to 6.x or 5.x. [...]]]></description>
			<content:encoded><![CDATA[<p>Drupal is at it again with another round of updated releases. While not major releases, these new versions from Drupal do address a number of security fixes and bugs that were brought to their attention via Drupal’s bug tracking system.</p>
<p>Drupal has announced that there will be no new features added to 6.x or 5.x. They are holding the feature updates and implementation of new features until they are ready to release Drupal 7.x in the near future.</p>
<p><span id="more-87"></span></p>
<p>A 7th security update for version 6 and the 13th security update for version 5 may not mean a whole slew of new features, but they do address major security issues.</p>
<p>Security Issues</p>
<p>In both versions there are potential vulnerabilities to users for creating cross site request forgeries as well as cross site scripting. Both of these vulnerabilities could potentially result in database damage or unfiltered content being published inadvertently.</p>
<p>Whether you are using Drupal 6.x or Drupal 5.x, it is highly recommended by the community to update to the newest version to eliminate the potential for security infringements.</p>
<p>There are two options to upgrade:.<br />
Patching or Upgrading Current Drupal Versions</p>
<p>The first option for updating your Drupal version 5.x or 6.x is to simply patch your current core files with the updated ones. This is not the best option as the patch files do not contain certain bug fixes.</p>
<p>The second and best option is to do a full upgrade. This will ensure that all security fixes and bug fixes are addressed in your particular core code. You will also be better prepared for the Drupal 7 update which is expected to contain a number of new features.</p>
<p>It is also highly recommended that you run update.php to refresh the menu cache and other website caches. If you are using custom .htaccess or robot.txt files, you will want to make sure that any custom changes are retained since the updates modify both of these files.</p>
<p>Full upgrade files and patch files can be found here:</p>
<p>* Drupal 5.13 upgrade files<br />
* Drupal 6.7 upgrade files<br />
* Drupal 5.13 patch files<br />
* Drupal 6.7 patch files</p>
<p>If you are using PHP 5.1.x or lower there is a warning that comes up upon login. According to the Drupal Community, “That patch has been rolled back in CVS, and we will be doing a bug fix release on December 11th.”<br />
Get Ready for Drupal 7</p>
<p>Want new Drupal features? You’ll have to wait for Drupal 7 to be released. Until then get the upgrade files and ensure that your site is secure against the malicious threats described above.</p>
<p>If you are interested in learning more about Drupal, DrupalCon DC, the premier conference for Drupal developers, is right around the corner in March. While final submissions for sessions is over, tickets are still available. Get yours today and learn all the ins and outs of Drupal.</p>
<p><a href="http://www.cmswire.com/cms/web-cms/new-security-updates-for-drupal-web-cms-003664.php">CMSWire</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.powered-by.org/news/new-security-updates-for-drupal-web-cms/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress shuts door on new PHP attack vector</title>
		<link>http://www.powered-by.org/news/security/wordpress-shuts-door-on-new-php-attack-vector/</link>
		<comments>http://www.powered-by.org/news/security/wordpress-shuts-door-on-new-php-attack-vector/#comments</comments>
		<pubDate>Sat, 13 Sep 2008 17:53:25 +0000</pubDate>
		<dc:creator>powered-by.org</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[Blogs]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://www.powered-by.org/news/security/wordpress-shuts-door-on-new-php-attack-vector/</guid>
		<description><![CDATA[According to an advisory from maintainers of the open-source blog software, WordPress 2.6.2 was released on September 8 to mitigate a new attack vector discovered by PHP security guru Stefan Esser. From the announcement: Stefan Esser recently warned developers of the dangers of SQL Column Truncation and the weakness of mt_rand(). With his help we [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_6" class="wp-caption alignright" style="width: 288px"><a href="http://www.powered-by.org/wp-content/uploads/2008/09/wordpress-logo.png"><img class="size-medium wp-image-6" title="wordpress-logo" src="http://www.powered-by.org/wp-content/uploads/2008/09/wordpress-logo.png" alt="WordPress" width="278" height="117" /></a><p class="wp-caption-text">WordPress</p></div>
<p>According to an advisory from maintainers of the open-source blog software, WordPress 2.6.2 was released on September 8 to mitigate a new attack vector discovered by PHP security guru Stefan Esser.</p>
<p><span id="more-32"></span></p>
<p>From the announcement:</p>
<blockquote><p>Stefan Esser recently warned developers of the dangers of SQL Column Truncation and the weakness of mt_rand().  With his help we worked around these problems and are now releasing WordPress 2.6.2.  If you allow open registration on your blog, you should definitely upgrade.  With open registration enabled, it is possible in WordPress versions 2.6.1 and earlier to craft a username such that it will allow resetting another user’s password to a randomly generated password.  The randomly generated password is not disclosed to the attacker, so this problem by itself is annoying but not a security exploit.  However, this attack coupled with a weakness in the random number seeding in mt_rand() could be used to predict the randomly generated password.</p></blockquote>
<p>WordPress developers said the attack is difficult to accomplish but, because of the associated risk, the patch is being released.</p>
<p>It’s important to note that other PHP applications are vulnerable to this class of attack.</p>
<p><a href="http://blogs.zdnet.com/security/?p=1868">WordPress shuts door on new PHP attack vector | Zero Day | ZDNet.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.powered-by.org/news/security/wordpress-shuts-door-on-new-php-attack-vector/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
