<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title>Bug Fix - DataLife Engine Support</title>
<link>http://dleviet.com/</link>
<language>ru</language>
<description>Bug Fix - DataLife Engine Support</description>
<generator>DataLife Engine</generator><item>
<title>Insufficient filtering of incoming data for DLE 8.5</title>
<guid isPermaLink="true">http://dleviet.com/dle/bug-fix/480-Insufficient-filtering-of-incoming-data-for-DLE-85.html</guid>
<link>http://dleviet.com/dle/bug-fix/480-Insufficient-filtering-of-incoming-data-for-DLE-85.html</link>
<description><![CDATA[<b>Problem:</b> User is allowed to upload files to server (no pictures), may go beyond the permitted download folder, and if he has the administrator account, then interrogate the script.<br /><br /><b>Error in version:</b> All Versions<br /><br /><b>The degree of danger:</b> <!--colorstart:#FF0000--><span style="color:#FF0000"><!--/colorstart-->Medium (High if the administrator account are online)<!--colorend--></span><!--/colorend--><br /><br />Distribution version 8.5 has been updated.]]></description>
<category><![CDATA[Bug Fix]]></category>
<dc:creator>admin</dc:creator>
<pubDate>Wed, 09 Jun 2010 23:38:50 -0600</pubDate>
</item><item>
<title>Fix bug cross-site scripting (XSS) attacks</title>
<guid isPermaLink="true">http://dleviet.com/dle/bug-fix/475-Fix-bug-cross-site-scripting-XSS-attacks.html</guid>
<link>http://dleviet.com/dle/bug-fix/475-Fix-bug-cross-site-scripting-XSS-attacks.html</link>
<description><![CDATA[<b>Problem:</b> Under certain conditions, your site can be attacked XSS. Attacker can steal cookies; browser if administrator use outdated browser. So he can access to authorized area.<br />View more about XSS : <a href="http://en.wikipedia.org/wiki/Cross-site_scripting" target="_blank">http://en.wikipedia.org/wiki/Cross-site_scripting</a><br /><br /><b>Affected version:</b> <!--colorstart:#CC0000--><span style="color:#CC0000"><!--/colorstart-->7.x - 8.5<!--colorend--></span><!--/colorend--><br /><br /><b>The degree of danger:</b> <!--colorstart:#CC0000--><span style="color:#CC0000"><!--/colorstart-->Low<!--colorend--></span><!--/colorend--><br /><br /><b>Download the patch and copy to your own server patch:</b> <a href="http://dle-news.ru/files/dle7_85_path.zip" target="_blank">dle7_85_path.zip</a><br /><br />This patch applies to all versions: 7.x - 8.5]]></description>
<category><![CDATA[Bug Fix]]></category>
<dc:creator>admin</dc:creator>
<pubDate>Sun, 06 Jun 2010 03:33:19 -0600</pubDate>
</item><item>
<title>Fix lost Category of DLE after move hosting</title>
<guid isPermaLink="true">http://dleviet.com/dle/bug-fix/373-Fix-lost-Category-of-DLE-after-move-hosting.html</guid>
<link>http://dleviet.com/dle/bug-fix/373-Fix-lost-Category-of-DLE-after-move-hosting.html</link>
<description><![CDATA[<div align="center"><!--TBegin--><a href="http://dleviet.com/uploads/posts/2010-05/1273065260_LetsFixIt.jpg" onclick="return hs.expand(this)" ><img src="http://dleviet.com/uploads/posts/2010-05/thumbs/1273065260_LetsFixIt.jpg" alt='Fix lost Category of DLE after move hosting' title='Fix lost Category of DLE after move hosting'  /></a><!--TEnd--><br /><br /><b>Fix lost Category of DLE after move hosting</b><br /></div>]]></description>
<category><![CDATA[Bug Fix]]></category>
<dc:creator>admin</dc:creator>
<pubDate>Wed, 05 May 2010 22:23:06 -0600</pubDate>
</item><item>
<title>DLE 8.5 SQL (fixes User Groups,  Banners, Vote)</title>
<guid isPermaLink="true">http://dleviet.com/dle/bug-fix/309-DLE-85-SQL-fixes-User-Groups-Banners-Vote.html</guid>
<link>http://dleviet.com/dle/bug-fix/309-DLE-85-SQL-fixes-User-Groups-Banners-Vote.html</link>
<description><![CDATA[<!--sizestart:3--><span style="font-size:12pt;line-height:100%"><!--/sizestart-->You might face Unknown Column "Start" & "End" problem after Restoring DLE 8.3 SQL<br /><br />Its because there are two new columns in DLE 8.5 to start a Banner , Vote Transitions.<br />Also and other col "Image_size" in user groups<br /><br /><!--colorstart:#6600CC--><span style="color:#6600CC"><!--/colorstart--><b>Here is the solution</b><!--colorend--></span><!--/colorend--><!--sizeend--></span><!--/sizeend-->]]></description>
<category><![CDATA[Bug Fix]]></category>
<dc:creator>Pakistan</dc:creator>
<pubDate>Thu, 11 Mar 2010 20:09:49 -0700</pubDate>
</item><item>
<title>Lack of filtering incoming data in the module reset your password in DataLife Engine 8.2</title>
<guid isPermaLink="true">http://dleviet.com/dle/bug-fix/287-Lack-of-filtering-incoming-data-in-the-module-reset-your-password-in-DataLife-Engine-82.html</guid>
<link>http://dleviet.com/dle/bug-fix/287-Lack-of-filtering-incoming-data-in-the-module-reset-your-password-in-DataLife-Engine-82.html</link>
<description><![CDATA[<b>Problem:</b> Lack of filtering incoming data in the module reset your password.<br /><br /><b>Error in version:</b> only <!--colorstart:#CC0000--><span style="color:#CC0000"><!--/colorstart-->8.2<!--colorend--></span><!--/colorend-->, the versions below 8.2, as well as the current version 8.3 is not affected<br /><br /><b>The degree of danger:</b> Very high<br /><br />Distribution version 8.2 has been updated.]]></description>
<category><![CDATA[Bug Fix]]></category>
<dc:creator>admin</dc:creator>
<pubDate>Thu, 25 Feb 2010 22:14:34 -0700</pubDate>
</item><item>
<title>Lack of filtering incoming data in the processing of news</title>
<guid isPermaLink="true">http://dleviet.com/dle/bug-fix/286-Lack-of-filtering-incoming-data-in-the-processing-of-news.html</guid>
<link>http://dleviet.com/dle/bug-fix/286-Lack-of-filtering-incoming-data-in-the-processing-of-news.html</link>
<description><![CDATA[<b>Problem:</b> Lack of filtering incoming data in the processing of news.<br /><br /><b>Error in version:</b> <!--colorstart:#CC0000--><span style="color:#CC0000"><!--/colorstart-->All Versions before DLE 8.0<!--colorend--></span><!--/colorend--><br /><br /><b>The degree of danger:</b> <!--colorstart:#CC0000--><span style="color:#CC0000"><!--/colorstart-->Low<!--colorend--></span><!--/colorend-->]]></description>
<category><![CDATA[Bug Fix]]></category>
<dc:creator>admin</dc:creator>
<pubDate>Thu, 25 Feb 2010 21:56:42 -0700</pubDate>
</item><item>
<title>Insufficient filtering of incoming data for DLE</title>
<guid isPermaLink="true">http://dleviet.com/dle/bug-fix/185-Insufficient-filtering-of-incoming-data-for-DLE.html</guid>
<link>http://dleviet.com/dle/bug-fix/185-Insufficient-filtering-of-incoming-data-for-DLE.html</link>
<description><![CDATA[<b>Problem:</b> Lack of filtering incoming data in the processing of news.<br /><br /><b>Error in version:</b> All Versions (except DLE 8.2)<br /><br /><b>The degree of danger:</b> <!--colorstart:#FF0000--><span style="color:#FF0000"><!--/colorstart-->Low<!--colorend--></span><!--/colorend--><br /><br />Source : <!--code1--><div class="scriptcode"><!--ecode1-->http&#58;//dle-news.ru/bags/665-nedostatochnaya-filtraciya-vxodyashhix-dannyx.html<!--code2--></div><!--ecode2-->]]></description>
<category><![CDATA[Bug Fix]]></category>
<dc:creator>admin</dc:creator>
<pubDate>Sat, 17 Oct 2009 09:41:21 -0600</pubDate>
</item><item>
<title>Insufficient filtering of incoming data in DaraLife Engine 7.5</title>
<guid isPermaLink="true">http://dleviet.com/dle/bug-fix/15-Insufficient-filtering-of-incoming-data-in-DaraLife-Engine-7.5.html</guid>
<link>http://dleviet.com/dle/bug-fix/15-Insufficient-filtering-of-incoming-data-in-DaraLife-Engine-7.5.html</link>
<description><![CDATA[<b>Problem:</b> Lack of filtering incoming data.<br /><br /><b>Error in version:</b> 7.5 and below<br /><br /><b>The degree of danger:</b> Low<br /><br />To download the patch and copy to your server patch: <a href="http://dle-news.ru/files/dle75_path.zip" target="_blank">http://dle-news.ru/files/dle75_path.zip</a> (Note the patch is for version 7.5)<br /><br />Distribution version 7.5 has been updated. <br /><br /><br />Source:<br /><!--code1--><div class="scriptcode"><!--ecode1-->http&#58;//dle-news.ru/bags/v75/570-nedostatochnaya-filtraciya-vxodyashhix-dannyx.html<!--code2--></div><!--ecode2-->]]></description>
<category><![CDATA[Bug Fix]]></category>
<dc:creator>admin</dc:creator>
<pubDate>Sun, 26 Apr 2009 15:09:37 -0600</pubDate>
</item></channel></rss>