<?xml version="1.0" encoding="US-ASCII"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<atom:link href="http://www.phpcmsreviews.com/rss" rel="self" type="application/rss+xml" /><title>PHP CMS Reviews</title>
<link>http://www.phpcmsreviews.com</link>
<description>PHP CMS Reviews - http://www.phpcmsreviews.com/</description>
<webMaster>webmaster@phpcmsreviews.com (Webmaster)</webMaster>

<item>
<title>PHP CMS Reviews - News: AdaptCMS 1.3 Security Fix Released</title>
<guid isPermaLink='true'>http://www.phpcmsreviews.com/article/63/News/AdaptCMS-13-Security-Fix-Released/</guid>
<link>http://www.phpcmsreviews.com/article/63/News/AdaptCMS-13-Security-Fix-Released/</link>
<description>&lt;p&gt;The Insane Visions team has issued an urgent security fix for AdaptCMS Pro/Lite 1.3. The security issue was a matter of SQL Injection vulnerability and they say that hashes were possible to get, but not passwords themselves. They recommend downloading and applying this patch immediately.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&quot;&lt;/em&gt;&lt;em&gt;For the first time with AdaptCMS, Insane Visions has issued an urgent security fix. This recent security hole was discovered by the group at &lt;strong&gt;Milw0rm&lt;/strong&gt;. Upon hearing about this security hole we immediately fixed the problem in a matter of minutes and are now issuing this fix.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The Security Hole was related to the new &quot;Check User&quot; feature in AdaptCMS Lite 1.3 and AdaptCMS Pro 1.3. When &lt;a id=&quot;AdBriteInlineAd_signing&quot; style=&quot;background: transparent url(http://files.adbrite.com/mb/images/green-double-underline-006600.gif) repeat-x scroll center bottom; cursor: pointer; color: #006600; text-decoration: none; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; margin-bottom: -2px; padding-bottom: 2px;&quot; name=&quot;AdBriteInlineAd_signing&quot; target=&quot;_top&quot;&gt;signing&lt;/a&gt; up you would enter the username desired, once moving to the password field a box would appear saying whether the username was taken or not. The issue was the PHP that checks to see if the username is taken did not use any safe guards incase of SQL injection. The worst consequence is the stealing of the MD5 hash of a users password but NO passwords themselves were vulnerable to this problem.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;This fix is simply one &lt;a id=&quot;AdBriteInlineAd_file&quot; style=&quot;background: transparent url(http://files.adbrite.com/mb/images/green-double-underline-006600.gif) repeat-x scroll center bottom; cursor: pointer; color: #006600; text-decoration: none; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; margin-bottom: -2px; padding-bottom: 2px;&quot; name=&quot;AdBriteInlineAd_file&quot; target=&quot;_top&quot;&gt;file&lt;/a&gt; which goes into the &quot;includes/&quot; folder. We recommend that all AdaptCMS Lite users upload this fixed file immediately. Thank you.&quot;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Links&lt;/strong&gt;: &lt;a href=&quot;http://www.adaptcms.com/article/51/News/URGENT-AdaptCMS-13-Security-Fix-Released/&quot;&gt;AdaptCMS 1.3 Security Fix Released&lt;/a&gt; - &lt;strong&gt;&lt;a href=&quot;http://downloads.sourceforge.net/adaptcms/AdaptCMS_1.3_Fix.zip&quot;&gt;&lt;strong&gt;Download &lt;/strong&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;</description>
<pubDate>Wed, 08 Oct 2008 05:03:05 CDT</pubDate>
</item>

<item>
<title>PHP CMS Reviews - News: Drupal 6.5 and 5.11 released</title>
<guid isPermaLink='true'>http://www.phpcmsreviews.com/article/62/News/Drupal-65-and-511-released/</guid>
<link>http://www.phpcmsreviews.com/article/62/News/Drupal-65-and-511-released/</link>
<description>&lt;p&gt;The Drupal team has announced the release of Drupal 6.5 and 5.11. Both releases fix &quot;critical security vulnerabilities&quot; and it is &quot;strongly recommended&quot; to upgrade Drupal 5 and 6 sites. Here's the announcement:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p style=&quot;position: inherit;&quot;&gt;&lt;em&gt;&quot;Drupal 6.5 and Drupal 5.11, maintenance releases fixing problems reported using the bug tracking system, as well as &lt;strong&gt;critical security vulnerabilities&lt;/strong&gt;, are now available for download.&lt;/em&gt;&lt;/p&gt;
&lt;p style=&quot;position: inherit;&quot;&gt;&lt;em&gt;&lt;strong&gt;&lt;a href=&quot;http://drupal.org/upgrade/&quot;&gt;Upgrading&lt;/a&gt; your existing Drupal 5 and 6 sites is strongly recommended.&lt;/strong&gt; There are no new features in these releases. For more information about the Drupal 6.x release series, consult the &lt;a href=&quot;http://drupal.org/drupal-6.0&quot;&gt;Drupal 6.0 release announcement&lt;/a&gt;, more information on the 5.x releases can be found in &lt;a href=&quot;http://drupal.org/drupal-5.0&quot;&gt;Drupal 5.0 release announcement&lt;/a&gt;.&quot;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Link&lt;/strong&gt;: &lt;a href=&quot;http://drupal.org/drupal-6.5&quot;&gt;Drupal 6.5 and 5.11 released&lt;/a&gt;&lt;/p&gt;</description>
<pubDate>Wed, 08 Oct 2008 04:47:03 CDT</pubDate>
</item>

<item>
<title>PHP CMS Reviews - News: e107 0.7.13 Released</title>
<guid isPermaLink='true'>http://www.phpcmsreviews.com/article/61/News/e107-0713-Released/</guid>
<link>http://www.phpcmsreviews.com/article/61/News/e107-0713-Released/</link>
<description>&lt;p&gt;It has been anounced that a new release of e107, 0.7.13, has been released. This is seemingly another small bug-update that affects &quot;relatively few files&quot; and also fixes a security vulnerability. They recommend to apply the update as soon as possible.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&quot;A bit like buses, E107 releases sometimes come in pairs - usually because a bug which affects a fair number of people has crept in under the radar of those who regularly update from CVS. More to the point, on this occasion there's a fix for a security vulnerability which can potentially affect those with certain server configurations. Thanks to Fanat1k for finding this one.&lt;/p&gt;</description>
<pubDate>Sun, 28 Sep 2008 04:46:50 CDT</pubDate>
</item>

<item>
<title>PHP CMS Reviews - News: TYPOlight 2.6.1 Released</title>
<guid isPermaLink='true'>http://www.phpcmsreviews.com/article/60/News/TYPOlight-261-Released/</guid>
<link>http://www.phpcmsreviews.com/article/60/News/TYPOlight-261-Released/</link>
<description>&lt;p&gt;A new &quot;minor release&quot; of TYPOlight has been released and is availble, TYPOlight 2.6.1. Here's the story:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&quot;TYPOlight version 2.6.1 is available. The minor release introduces a new content element named &quot;article alias&quot;, which allows you to insert the content of an article into another one. In addition, the newsletter module has been overworked and now supports sending personalized e-mails to registered members. The new version also includes some important bug fixes (especially for the built-in search engine), so it is recommended to update.&quot;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Feel free to checkout the &lt;strong&gt;&lt;a href=&quot;http://www.phpcmsreviews.com/article/38/CMS/TYPOlight/&quot;&gt;TYPOlight CMS Page&lt;/a&gt;&lt;/strong&gt;&lt;a href=&quot;http://www.phpcmsreviews.com/article/15/CMS/CMS-Made-Simple/&quot;&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/a&gt; to see the new version in action.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Link&lt;/strong&gt;: &lt;a href=&quot;http://www.typolight.org/news/items/typolight-2_6_1.html&quot;&gt;TYPOlight 2.6.1 Released&lt;/a&gt;&lt;/p&gt;</description>
<pubDate>Sat, 20 Sep 2008 11:57:29 CDT</pubDate>
</item>

<item>
<title>PHP CMS Reviews - News: MiaCMS 4.6.5 Security Patch 1 Released</title>
<guid isPermaLink='true'>http://www.phpcmsreviews.com/article/59/News/MiaCMS-465-Security-Patch-1-Released/</guid>
<link>http://www.phpcmsreviews.com/article/59/News/MiaCMS-465-Security-Patch-1-Released/</link>
<description>&lt;p&gt;The MiaCMS team has released a very imporant security patch, MiaCMS 4.6.5 Security Patch 1. This Patch fixes serious SQL injection issues found in MiaCMS. They &quot;strongly recommend&quot; that all users update there copy of MiaCMS as soon as possible. Here's the scoop:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&quot;As you may or may not be aware, within the last day or two there has been a MiaCMS SQL injection security report making rounds on the web.&amp;nbsp; We have taken time to carefully review the report and wanted to make you aware of our findings.&amp;nbsp; The report can be found here for reference - &lt;a href=&quot;http://secunia.com/advisories/31584/&quot;&gt;http://secunia.com/advisories/31584/&lt;/a&gt;.&lt;/p&gt;</description>
<pubDate>Wed, 27 Aug 2008 10:42:52 CDT</pubDate>
</item>

</channel></rss>