<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns:vrda="http://vrda.jpcert.or.jp/mod_vrda/" xml:lang="ja" xmlns="http://www.w3.org/2005/Atom" xmlns:sec="http://jvn.jp/rss/mod_sec/">
  <id>http://vrda.jpcert.or.jp/feed/ja/atom.xml</id>
  <title>VRDA&#12501;&#12451;&#12540;&#12489;&#65306;&#33030;&#24369;&#24615;&#33029;&#23041;&#20998;&#26512;&#29992;&#24773;&#22577;&#12398;&#23450;&#22411;&#12487;&#12540;&#12479;&#37197;&#20449;</title>
  <subtitle>VRDA (Vulnerability Response Decision Assistance)&#12501;&#12451;&#12540;&#12489;&#12399;&#12289;&#32068;&#32340;&#12395;&#12362;&#12369;&#12427;&#12477;&#12501;&#12488;&#12454;&#12456;&#12450;&#31561;&#12398;&#33030;&#24369;&#24615;&#12510;&#12493;&#12472;&#12513;&#12531;&#12488;&#26989;&#21209;&#12398;&#21177;&#29575;&#21270;&#12539;&#30465;&#21147;&#21270;&#12434;&#25903;&#25588;&#12377;&#12427;&#12371;&#12392;&#12434;&#30446;&#30340;&#12392;&#12375;&#12390;&#12289;&#20844;&#38283;&#12373;&#12428;&#12390;&#12356;&#12427;&#33030;&#24369;&#24615;&#24773;&#22577;&#12395;&#38306;&#12377;&#12427;&#20998;&#26512;&#24773;&#22577;&#12434;&#12289;&#24773;&#22577;&#12398;&#20837;&#25163;&#12364;&#23481;&#26131;&#12391;&#21487;&#35501;&#24615;&#12398;&#39640;&#12356; HTML &#12501;&#12457;&#12540;&#12510;&#12483;&#12488;&#12392;&#12450;&#12503;&#12522;&#12465;&#12540;&#12471;&#12519;&#12531;&#31561;&#12395;&#12424;&#12427;&#27231;&#26800;&#20966;&#29702;&#12395;&#21521;&#12356;&#12383; XML &#12501;&#12457;&#12540;&#12510;&#12483;&#12488;&#12391;&#37197;&#20449;&#12375;&#12390;&#12356;&#12414;&#12377;&#12290;</subtitle>
  <link href="http://vrda.jpcert.or.jp/feed/ja/atom.xml" rel="self" type="application/atom+xml"/>
  <link href="http://vrda.jpcert.or.jp/feed/en/atom.xml" rel="alternate" hreflang="en" type="application/atom+xml"/>
  <updated>2012-02-10T04:07:33+09:00</updated>
  <author>
    <name>JPCERT Coordination Center</name>
    <email>kengine@jpcert.or.jp</email>
    <uri>http://www.jpcert.or.jp/</uri>
  </author>
  <vrda:entrycount>12667</vrda:entrycount>
  <vrda:startentryno>1</vrda:startentryno>
  <entry>
    <title>JVNDB-2012-001337:Sphinx Software Mobile Web Server &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001337_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001337_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001337_AD_1.html</id>
    <published>2012-02-09T16:52:50+09:00</published>
    <updated>2012-02-09T16:52:50+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Sphinx Software Mobile Web Server には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001337_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:sphinx-soft:mobile_web_server"/>
    <sec:identifier>JVNDB-2012-001337</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001336:HDWiki &#12398; attachement.php &#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#12434;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001336_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001336_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001336_AD_1.html</id>
    <published>2012-02-09T16:01:37+09:00</published>
    <updated>2012-02-09T16:01:37+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
HDWiki の attachement.php には、任意のコードを実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001336_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hudong:hdwik"/>
    <sec:identifier>JVNDB-2012-001336</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001335:HDWiki &#12398; model/comment.class.php &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001335_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001335_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001335_AD_1.html</id>
    <published>2012-02-09T16:00:52+09:00</published>
    <updated>2012-02-09T16:00:52+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
HDWiki の model/comment.class.php には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001335_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hudong:hdwik"/>
    <sec:identifier>JVNDB-2012-001335</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001334:WordPress &#29992; AllWebMenus &#12503;&#12521;&#12464;&#12452;&#12531;&#12398; actions.php &#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398; PHP &#12467;&#12540;&#12489;&#12434;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001334_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001334_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001334_AD_1.html</id>
    <published>2012-02-09T15:59:51+09:00</published>
    <updated>2012-02-09T15:59:51+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
WordPress 用 AllWebMenus プラグインの actions.php には、アクセス制限を回避され、任意の PHP コードをアップロードおよび実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001334_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:likno:allwebmenus_plugin"/>
    <sec:identifier>JVNDB-2012-001334</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001333:WordPress &#29992; AllWebMenus &#12503;&#12521;&#12464;&#12452;&#12531;&#12398; actions.php &#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398; PHP &#12467;&#12540;&#12489;&#12434;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001333_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001333_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001333_AD_1.html</id>
    <published>2012-02-09T15:59:19+09:00</published>
    <updated>2012-02-09T15:59:19+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
WordPress 用 AllWebMenus プラグインの actions.php には、任意の PHP コードを実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001333_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:likno:allwebmenus_plugin"/>
    <sec:identifier>JVNDB-2012-001333</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001332:OpenEMR &#12398; interface/fax/fax_dispatch.php &#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12510;&#12531;&#12489;&#12434;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001332_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001332_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001332_AD_1.html</id>
    <published>2012-02-09T15:57:52+09:00</published>
    <updated>2012-02-09T15:57:52+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
OpenEMR の interface/fax/fax_dispatch.php には、任意のコマンドを実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001332_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:openemr:openemr"/>
    <sec:identifier>JVNDB-2012-001332</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001331:OpenEMR &#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001331_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001331_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001331_AD_1.html</id>
    <published>2012-02-09T15:57:17+09:00</published>
    <updated>2012-02-09T15:57:17+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
OpenEMR には、ディレクトリトラバーサルの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001331_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:openemr:openemr"/>
    <sec:identifier>JVNDB-2012-001331</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001330:DClassifieds &#12398; admin/settings/update &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12522;&#12463;&#12456;&#12473;&#12488;&#12501;&#12457;&#12540;&#12472;&#12455;&#12522;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001330_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001330_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001330_AD_1.html</id>
    <published>2012-02-09T15:56:15+09:00</published>
    <updated>2012-02-09T15:56:15+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
DClassifieds の admin/settings/update には、クロスサイトリクエストフォージェリの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001330_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:dclassifieds:dclassifieds"/>
    <sec:identifier>JVNDB-2012-001330</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003686:Zenphoto &#12398; zp-core/admin.php &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003686_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003686_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003686_AD_1.html</id>
    <published>2012-02-09T11:18:19+09:00</published>
    <updated>2012-02-09T11:18:19+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Zenphoto の zp-core/admin.php には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003686_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:zenphoto:zenphoto"/>
    <sec:identifier>JVNDB-2011-003686</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003685:Zenphoto &#12398; zp-core/full-image.php &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003685_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003685_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003685_AD_1.html</id>
    <published>2012-02-09T11:12:41+09:00</published>
    <updated>2012-02-09T11:12:41+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Zenphoto の zp-core/full-image.php には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003685_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:zenphoto:zenphoto"/>
    <sec:identifier>JVNDB-2011-003685</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003684:Softbiz Article Directory Script &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003684_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003684_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003684_AD_1.html</id>
    <published>2012-02-09T11:12:06+09:00</published>
    <updated>2012-02-09T11:12:06+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Softbiz Article Directory Script の article_details.php には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003684_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:softbizscripts:article_directory_script"/>
    <sec:identifier>JVNDB-2011-003684</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003683:DBHcms &#12398; index.php &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003683_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003683_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003683_AD_1.html</id>
    <published>2012-02-09T11:10:54+09:00</published>
    <updated>2012-02-09T11:10:54+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
DBHcms の index.php には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003683_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:drbenhur:dbhcms"/>
    <sec:identifier>JVNDB-2011-003683</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003682:W-Agora &#12398; search.php3 &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003682_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003682_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003682_AD_1.html</id>
    <published>2012-02-09T11:10:28+09:00</published>
    <updated>2012-02-09T11:10:28+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
W-Agora の search.php3 には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003682_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:w-agora:w-agora"/>
    <sec:identifier>JVNDB-2011-003682</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003681:W-Agora &#12398; search.php3 &#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003681_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003681_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003681_AD_1.html</id>
    <published>2012-02-09T11:10:00+09:00</published>
    <updated>2012-02-09T11:10:00+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
W-Agora の search.php3 には、ディレクトリトラバーサルの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003681_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:w-agora:w-agora"/>
    <sec:identifier>JVNDB-2011-003681</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003680:Chipmunk Board &#12398; index.php &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003680_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003680_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003680_AD_1.html</id>
    <published>2012-02-09T11:09:28+09:00</published>
    <updated>2012-02-09T11:09:28+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Chipmunk Board の index.php には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003680_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:chipmunk-scripts:chipmunk_board"/>
    <sec:identifier>JVNDB-2011-003680</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003679:Joomla! &#29992; JE Guestbook (com_jeguestbook) &#12467;&#12531;&#12509;&#12540;&#12493;&#12531;&#12488;&#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003679_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003679_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003679_AD_1.html</id>
    <published>2012-02-09T11:08:55+09:00</published>
    <updated>2012-02-09T11:08:55+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Joomla! 用 JE Guestbook (com_jeguestbook) コンポーネントには、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003679_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:harmistechnology:com_jeguestbook"/>
    <sec:identifier>JVNDB-2011-003679</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003678:Joomla! &#29992; Club Manager (com_clubmanager) &#12467;&#12531;&#12509;&#12540;&#12493;&#12531;&#12488;&#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003678_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003678_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003678_AD_1.html</id>
    <published>2012-02-09T11:08:20+09:00</published>
    <updated>2012-02-09T11:08:20+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Joomla! 用 Club Manager (com_clubmanager) コンポーネントには、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003678_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:danieljamesscott:com_clubmanager"/>
    <sec:identifier>JVNDB-2011-003678</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003677:GetSimple CMS &#12398; admin/changedata.php &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003677_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003677_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003677_AD_1.html</id>
    <published>2012-02-09T11:07:33+09:00</published>
    <updated>2012-02-09T11:07:33+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
GetSimple CMS の admin/changedata.php には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003677_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:cagintranetworks:getsimple_cms"/>
    <sec:identifier>JVNDB-2011-003677</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003676:Joomla! &#29992; JExtensions JE Director &#12467;&#12531;&#12509;&#12540;&#12493;&#12531;&#12488;&#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003676_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003676_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003676_AD_1.html</id>
    <published>2012-02-09T11:07:04+09:00</published>
    <updated>2012-02-09T11:07:04+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Joomla! 用 JExtensions JE Directory (com_jedirectory) コンポーネントには、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003676_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:harmistechnology:com_jedirectory"/>
    <category term="cpe:/a:joomla:joomla"/>
    <sec:identifier>JVNDB-2011-003676</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003675:webSPELL &#12398; asearch.php &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003675_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003675_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003675_AD_1.html</id>
    <published>2012-02-09T11:06:27+09:00</published>
    <updated>2012-02-09T11:06:27+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
webSPELL の asearch.php には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003675_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:webspell:webspell"/>
    <sec:identifier>JVNDB-2011-003675</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003674:MyPhpAuction &#12398; product_desc.php &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003674_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003674_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003674_AD_1.html</id>
    <published>2012-02-09T11:05:53+09:00</published>
    <updated>2012-02-09T11:05:53+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
MyPhpAuction の product_desc.php には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003674_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:galaxyscriptz:myphpauction"/>
    <sec:identifier>JVNDB-2011-003674</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003673:WebAsyst Shop-Script &#12398; index.php &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003673_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003673_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003673_AD_1.html</id>
    <published>2012-02-09T11:05:22+09:00</published>
    <updated>2012-02-09T11:05:22+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
WebAsyst Shop-Script の index.php には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003673_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:webasyst:shop-script"/>
    <sec:identifier>JVNDB-2011-003673</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003672:DNET Live-Stats &#12398; team.rc5-72.php &#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003672_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003672_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003672_AD_1.html</id>
    <published>2012-02-09T11:04:30+09:00</published>
    <updated>2012-02-09T11:04:30+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
DNET Live-Stats の team.rc5-72.php には、ディレクトリトラバーサルの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003672_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:joerg_risse:dnet_live-stats"/>
    <sec:identifier>JVNDB-2011-003672</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003671:CAG CMS &#12398; click.php &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003671_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003671_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003671_AD_1.html</id>
    <published>2012-02-09T11:03:58+09:00</published>
    <updated>2012-02-09T11:03:58+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
CAG CMS の click.php には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003671_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:curtiss_grymala:cag_cms"/>
    <sec:identifier>JVNDB-2011-003671</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003670:xWeblog &#12398; arsiv.asp &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003670_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003670_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003670_AD_1.html</id>
    <published>2012-02-09T11:03:11+09:00</published>
    <updated>2012-02-09T11:03:11+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
xWeblog の arsiv.asp には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003670_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:aspindir:xweblog"/>
    <sec:identifier>JVNDB-2011-003670</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003669:xWeblog &#12398; oku.asp &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003669_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003669_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003669_AD_1.html</id>
    <published>2012-02-09T11:02:43+09:00</published>
    <updated>2012-02-09T11:02:43+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
xWeblog の oku.asp には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003669_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:aspindir:xweblog"/>
    <sec:identifier>JVNDB-2011-003669</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003668:Zuitu &#12398; ajax/coupon.php &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003668_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003668_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003668_AD_1.html</id>
    <published>2012-02-09T11:02:06+09:00</published>
    <updated>2012-02-09T11:02:06+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Zuitu の ajax/coupon.php は、magic_quotes_gpc が無効になっている際に、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003668_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:zuitu:zuitu"/>
    <sec:identifier>JVNDB-2011-003668</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003667:Joomla! &#29992; ccInvoices &#12467;&#12531;&#12509;&#12540;&#12493;&#12531;&#12488;&#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003667_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003667_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003667_AD_1.html</id>
    <published>2012-02-09T11:01:34+09:00</published>
    <updated>2012-02-09T11:01:34+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Joomla! 用 ccInvoices コンポーネントには、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003667_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:chillcreations:com_ccinvoices"/>
    <sec:identifier>JVNDB-2011-003667</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2008-002517:Joomla! &#29992; nBill &#12467;&#12531;&#12509;&#12540;&#12493;&#12531;&#12488;&#12398; netinvoice.php &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2008-002517_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2008-002517_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2008-002517_AD_1.html</id>
    <published>2012-02-09T11:01:04+09:00</published>
    <updated>2012-02-09T11:01:04+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Joomla! 用 nBill (com_netinvoice) コンポーネントの netinvoice.php には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2008-002517_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:netshinesoftware:com_netinvoice"/>
    <sec:identifier>JVNDB-2008-002517</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003666:jSite &#12398; admin/login.php &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003666_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003666_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003666_AD_1.html</id>
    <published>2012-02-09T11:00:09+09:00</published>
    <updated>2012-02-09T11:00:09+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
jSite の admin/login.php には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003666_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:sclek:jsite"/>
    <sec:identifier>JVNDB-2011-003666</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003665:Sun Solaris &#12362;&#12424;&#12403; OpenSolaris &#12395;&#12362;&#12369;&#12427; MAC &#12398;&#12509;&#12522;&#12471;&#12540;&#12434;&#22238;&#36991;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003665_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003665_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003665_AD_1.html</id>
    <published>2012-02-09T10:59:41+09:00</published>
    <updated>2012-02-09T10:59:41+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Sun Solaris および OpenSolaris 内の Solaris Trusted Extensions の labeled networking の実装には、ラベル付きゾーンがインストール済みの状態の際、Mandatory Access Control (MAC) のポリシーを回避される、またはグローバルゾーンへのアクセス権を取得される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003665_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:sun:opensolaris"/>
    <category term="cpe:/o:sun:solaris:10"/>
    <sec:identifier>JVNDB-2011-003665</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003664:Apache JServ &#12395;&#12362;&#12369;&#12427; JDBC &#12497;&#12473;&#12527;&#12540;&#12489;&#12414;&#12383;&#12399;&#12381;&#12398;&#20182;&#12398;&#37325;&#35201;&#12394;&#24773;&#22577;&#12434;&#35211;&#12388;&#12369;&#12425;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003664_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003664_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003664_AD_1.html</id>
    <published>2012-02-09T10:58:52+09:00</published>
    <updated>2012-02-09T10:58:52+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Apache JServ 内の jserv.conf の jserv-status ハンドラのデフォルト設定は、&quot;allow from 127.0.0.1&quot; 行を含むため、JDBC パスワード、またはその他の重要な情報を見つけられる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2011-003664_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apache:jserv"/>
    <sec:identifier>JVNDB-2011-003664</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001329:Apache Struts &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001329_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001329_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001329_AD_1.html</id>
    <published>2012-02-08T16:35:13+09:00</published>
    <updated>2012-02-08T16:35:13+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Apache Struts には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001329_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apache:struts"/>
    <sec:identifier>JVNDB-2012-001329</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001328:Apache Struts &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001328_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001328_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001328_AD_1.html</id>
    <published>2012-02-08T16:34:47+09:00</published>
    <updated>2012-02-08T16:34:47+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Apache Struts には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001328_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apache:struts"/>
    <sec:identifier>JVNDB-2012-001328</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001327:&#35079;&#25968;&#12398; Symantec &#35069;&#21697;&#12395;&#12362;&#12369;&#12427;&#12463;&#12521;&#12452;&#12450;&#12531;&#12488;&#12408;&#12450;&#12463;&#12475;&#12473;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001327_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001327_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001327_AD_1.html</id>
    <published>2012-02-08T16:33:46+09:00</published>
    <updated>2012-02-08T16:33:46+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Symantec 製品は、リモートセッションの異常終了後のクライアントステータスを適切に処理しないため、クライアントへアクセスされる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001327_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:symantec:altiris_client_management_suite_pcanywhere_solution"/>
    <category term="cpe:/a:symantec:altiris_deployment_solution_remote_pcanywhere_solution"/>
    <category term="cpe:/a:symantec:altiris_it_management_suite_pcanywhere_solution"/>
    <category term="cpe:/a:symantec:pcanywhere"/>
    <sec:identifier>JVNDB-2012-001327</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001326:IBM AIX &#12398; TCP &#23455;&#35013;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001326_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001326_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001326_AD_1.html</id>
    <published>2012-02-08T16:28:28+09:00</published>
    <updated>2012-02-08T16:28:28+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
IBM AIX の TCP 実装には、Large Send Offload オプションが有効になっている際、サービス運用妨害 (表明違反およびパニック) 状態となる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001326_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:ibm:aix:5.3"/>
    <category term="cpe:/o:ibm:aix:6.1"/>
    <category term="cpe:/o:ibm:aix:7.1"/>
    <sec:identifier>JVNDB-2012-001326</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001325:Advantech/BroadWin WebAccess &#12398; webvrpcs.exe &#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#12434;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001325_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001325_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001325_AD_1.html</id>
    <published>2012-02-08T16:27:10+09:00</published>
    <updated>2012-02-08T16:27:10+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Advantech/BroadWin WebAccess の webvrpcs.exe には、任意のコードを実行される、またはセキュリティコードの値を取得される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001325_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:broadwin:webaccess"/>
    <sec:identifier>JVNDB-2012-001325</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001324:Opera &#12395;&#12362;&#12369;&#12427;&#25972;&#25968;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001324_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001324_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001324_AD_1.html</id>
    <published>2012-02-08T16:18:43+09:00</published>
    <updated>2012-02-08T16:18:43+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Opera には、整数オーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001324_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:opera_software:opera_web_browser"/>
    <sec:identifier>JVNDB-2012-001324</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001323:PHP &#12398; php_variables.c &#20869;&#12398; php_register_variable_ex &#38306;&#25968;&#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#12434;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001323_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001323_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001323_AD_1.html</id>
    <published>2012-02-08T16:16:06+09:00</published>
    <updated>2012-02-08T16:16:06+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
PHP の php_variables.c 内の php_register_variable_ex 関数には、任意のコードを実行される脆弱性が存在します。 本脆弱性は CVE-2011-4885 に対する修正が不十分だったことによる脆弱性です。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001323_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:php:php"/>
    <sec:identifier>JVNDB-2012-001323</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001322:EMC Documentum xPlore &#12395;&#12362;&#12369;&#12427;&#12458;&#12502;&#12472;&#12455;&#12463;&#12488;&#12398;&#23384;&#22312;&#12434;&#29305;&#23450;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001322_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001322_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001322_AD_1.html</id>
    <published>2012-02-08T16:15:38+09:00</published>
    <updated>2012-02-08T16:15:38+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
EMC Documentum xPlore は、BROWSE 権限の要求を行わないため、オブジェクトの存在を特定される、または オブジェクト metadata を読まれる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001322_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:emc:documentum_xplore"/>
    <sec:identifier>JVNDB-2012-001322</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001321:&#35079;&#25968;&#12398; Siemens &#35069;&#21697;&#12398; HMI Web &#12469;&#12540;&#12496;&#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12513;&#12514;&#12522;&#12525;&#12465;&#12540;&#12471;&#12519;&#12531;&#12363;&#12425;&#12487;&#12540;&#12479;&#12434;&#35501;&#12414;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001321_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001321_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001321_AD_1.html</id>
    <published>2012-02-08T11:12:09+09:00</published>
    <updated>2012-02-08T11:12:09+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Siemens 製品の HMI Web サーバの miniweb.exe は、0xfa 文字コードから始まる URI を適切に処理しないため、任意のメモリロケーションからデータを読まれる、またはサービス運用妨害 (アプリケーションクラッシュ) 状態となる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001321_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:siemens:simatic_hmi_panels"/>
    <category term="cpe:/a:siemens:simatic_wincc"/>
    <category term="cpe:/a:siemens:wincc_flexible"/>
    <category term="cpe:/a:siemens:wincc_flexible_runtime"/>
    <category term="cpe:/a:siemens:wincc_runtime_advanced"/>
    <sec:identifier>JVNDB-2012-001321</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001320:&#35079;&#25968;&#12398; Siemens &#35069;&#21697;&#12398; HMI Web &#12469;&#12540;&#12496;&#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001320_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001320_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001320_AD_1.html</id>
    <published>2012-02-08T11:11:14+09:00</published>
    <updated>2012-02-08T11:11:14+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Siemens 製品の HMI Web サーバの miniweb.exe には、ディレクトリトラバーサルの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001320_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:siemens:simatic_hmi_panels"/>
    <category term="cpe:/a:siemens:simatic_wincc"/>
    <category term="cpe:/a:siemens:wincc_flexible"/>
    <category term="cpe:/a:siemens:wincc_flexible_runtime"/>
    <category term="cpe:/a:siemens:wincc_runtime_advanced"/>
    <sec:identifier>JVNDB-2012-001320</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001319:&#35079;&#25968;&#12398; Siemens &#35069;&#21697;&#12398; HmiLoad &#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (&#12450;&#12503;&#12522;&#12465;&#12540;&#12471;&#12519;&#12531;&#12463;&#12521;&#12483;&#12471;&#12517;) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001319_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001319_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001319_AD_1.html</id>
    <published>2012-02-08T11:09:42+09:00</published>
    <updated>2012-02-08T11:09:42+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Siemens 製品のランタイムローダーの HmiLoad には、Transfer モードが有効であるとき、サービス運用妨害 (アプリケーションクラッシュ) 状態となる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001319_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:siemens:simatic_hmi_panels"/>
    <category term="cpe:/a:siemens:simatic_wincc"/>
    <category term="cpe:/a:siemens:wincc_flexible"/>
    <category term="cpe:/a:siemens:wincc_flexible_runtime"/>
    <category term="cpe:/a:siemens:wincc_runtime_advanced"/>
    <sec:identifier>JVNDB-2012-001319</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001318:&#35079;&#25968;&#12398; Siemens &#35069;&#21697;&#12398; HmiLoad &#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001318_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001318_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001318_AD_1.html</id>
    <published>2012-02-08T11:07:50+09:00</published>
    <updated>2012-02-08T11:07:50+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Siemens 製品のランタイムローダーの HmiLoad には、Transfer モードが有効であるとき、ディレクトリトラバーサルの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001318_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:siemens:simatic_hmi_panels"/>
    <category term="cpe:/a:siemens:simatic_wincc"/>
    <category term="cpe:/a:siemens:wincc_flexible"/>
    <category term="cpe:/a:siemens:wincc_flexible_runtime"/>
    <category term="cpe:/a:siemens:wincc_runtime_advanced"/>
    <sec:identifier>JVNDB-2012-001318</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001317:&#35079;&#25968;&#12398; Siemens &#35069;&#21697;&#12398; HmiLoad &#12395;&#12362;&#12369;&#12427;&#12473;&#12479;&#12483;&#12463;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001317_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001317_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001317_AD_1.html</id>
    <published>2012-02-08T11:06:46+09:00</published>
    <updated>2012-02-08T11:06:46+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Siemens 製品のランタイムローダーの HmiLoad には、Unicode 文字列に関する処理に不備があるため、Transfer モードが有効であるとき、スタックベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001317_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:siemens:simatic_hmi_panels"/>
    <category term="cpe:/a:siemens:simatic_wincc"/>
    <category term="cpe:/a:siemens:wincc_flexible"/>
    <category term="cpe:/a:siemens:wincc_flexible_runtime"/>
    <category term="cpe:/a:siemens:wincc_runtime_advanced"/>
    <sec:identifier>JVNDB-2012-001317</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001316:&#35079;&#25968;&#12398; Siemens &#35069;&#21697;&#12398; TELNET &#12487;&#12540;&#12514;&#12531;&#12395;&#12362;&#12369;&#12427;&#12450;&#12463;&#12475;&#12473;&#27177;&#12434;&#21462;&#24471;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001316_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001316_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001316_AD_1.html</id>
    <published>2012-02-08T11:00:55+09:00</published>
    <updated>2012-02-08T11:00:55+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Siemens 製品の TELNET デーモンは、認証を行わないため、容易にアクセス権を取得される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001316_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:siemens:simatic_hmi_panels"/>
    <category term="cpe:/a:siemens:simatic_wincc"/>
    <category term="cpe:/a:siemens:wincc_flexible"/>
    <category term="cpe:/a:siemens:wincc_flexible_runtime"/>
    <category term="cpe:/a:siemens:wincc_runtime_advanced"/>
    <sec:identifier>JVNDB-2012-001316</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001315:&#35079;&#25968;&#12398; Siemens &#35069;&#21697;&#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#12434;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001315_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001315_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001315_AD_1.html</id>
    <published>2012-02-08T10:56:55+09:00</published>
    <updated>2012-02-08T10:56:55+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Siemens 製品には、HMI Web サーバーおよびランタイムローダに関する処理に不備があるため、任意のコードを実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001315_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:siemens:simatic_hmi_panels"/>
    <category term="cpe:/a:siemens:simatic_wincc"/>
    <category term="cpe:/a:siemens:wincc_flexible"/>
    <category term="cpe:/a:siemens:wincc_flexible_runtime"/>
    <category term="cpe:/a:siemens:wincc_runtime_advanced"/>
    <sec:identifier>JVNDB-2012-001315</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001314:&#35079;&#25968;&#12398; Siemens &#35069;&#21697;&#12398; HMI Web &#12469;&#12540;&#12496;&#12395;&#12362;&#12369;&#12427; CRLF &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001314_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001314_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001314_AD_1.html</id>
    <published>2012-02-08T10:54:10+09:00</published>
    <updated>2012-02-08T10:54:10+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Siemens 製品の HMI Web サーバには、CRLF インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001314_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:siemens:simatic_hmi_panels"/>
    <category term="cpe:/a:siemens:simatic_wincc"/>
    <category term="cpe:/a:siemens:wincc_flexible"/>
    <category term="cpe:/a:siemens:wincc_flexible_runtime"/>
    <category term="cpe:/a:siemens:wincc_runtime_advanced"/>
    <sec:identifier>JVNDB-2012-001314</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001313:&#35079;&#25968;&#12398; Siemens &#35069;&#21697;&#12398; HMI Web &#12469;&#12540;&#12496;&#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001313_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001313_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001313_AD_1.html</id>
    <published>2012-02-08T10:53:30+09:00</published>
    <updated>2012-02-08T10:53:30+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Siemens 製品の HMI Web サーバには、クロスサイトスクリプティングの脆弱性が存在します。 本脆弱性は、CVE-2011-4510 とは異なる脆弱性です。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001313_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:siemens:simatic_hmi_panels"/>
    <category term="cpe:/a:siemens:simatic_wincc"/>
    <category term="cpe:/a:siemens:wincc_flexible"/>
    <category term="cpe:/a:siemens:wincc_flexible_runtime"/>
    <category term="cpe:/a:siemens:wincc_runtime_advanced"/>
    <sec:identifier>JVNDB-2012-001313</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001312:&#35079;&#25968;&#12398; Siemens &#35069;&#21697;&#12398; HMI Web &#12469;&#12540;&#12496;&#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001312_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001312_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001312_AD_1.html</id>
    <published>2012-02-08T10:51:24+09:00</published>
    <updated>2012-02-08T10:51:24+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Siemens 製品の HMI Web サーバには、クロスサイトスクリプティングの脆弱性が存在します。 本脆弱性は、CVE-2011-4511 とは異なる脆弱性です。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001312_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:siemens:simatic_hmi_panels"/>
    <category term="cpe:/a:siemens:simatic_wincc"/>
    <category term="cpe:/a:siemens:wincc_flexible"/>
    <category term="cpe:/a:siemens:wincc_flexible_runtime"/>
    <category term="cpe:/a:siemens:wincc_runtime_advanced"/>
    <sec:identifier>JVNDB-2012-001312</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001311:&#35079;&#25968;&#12398; Siemens &#35069;&#21697;&#12398; HMI Web &#12469;&#12540;&#12496;&#12395;&#12362;&#12369;&#12427;&#12450;&#12463;&#12475;&#12473;&#27177;&#12434;&#21462;&#24471;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001311_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001311_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001311_AD_1.html</id>
    <published>2012-02-08T10:50:53+09:00</published>
    <updated>2012-02-08T10:50:53+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Siemens 製品の HMI Web サーバは、管理者アカウントにデフォルトパスワードが不適切に設定されている際、容易にアクセス権を取得される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001311_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:siemens:simatic_hmi_panels"/>
    <category term="cpe:/a:siemens:simatic_wincc"/>
    <category term="cpe:/a:siemens:wincc_flexible"/>
    <category term="cpe:/a:siemens:wincc_flexible_runtime"/>
    <category term="cpe:/a:siemens:wincc_runtime_advanced"/>
    <sec:identifier>JVNDB-2012-001311</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001310:&#35079;&#25968;&#12398; Siemens &#35069;&#21697;&#12398; HMI Web &#12469;&#12540;&#12496;&#12395;&#12362;&#12369;&#12427;&#35469;&#35388;&#12434;&#22238;&#36991;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001310_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001310_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001310_AD_1.html</id>
    <published>2012-02-08T10:49:53+09:00</published>
    <updated>2012-02-08T10:49:53+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Siemens 製品の HMI Web サーバは、Cookie への予測可能な認証トークンを生成するため、認証を回避される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001310_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:siemens:simatic_hmi_panels"/>
    <category term="cpe:/a:siemens:simatic_wincc"/>
    <category term="cpe:/a:siemens:wincc_flexible"/>
    <category term="cpe:/a:siemens:wincc_flexible_runtime"/>
    <category term="cpe:/a:siemens:wincc_runtime_advanced"/>
    <sec:identifier>JVNDB-2012-001310</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1034:episerver_cms: Multiple cross-site scripting (XSS) vulnerabilities...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1034_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1034_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1034_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple cross-site scripting (XSS) vulnerabilities in the admin interface in EPiServer CMS through 6R2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1034_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:episerver:episerver_cms:5.1.422.122"/>
    <category term="cpe:/a:episerver:episerver_cms:5.1.422.256"/>
    <category term="cpe:/a:episerver:episerver_cms:5.1.422.267"/>
    <category term="cpe:/a:episerver:episerver_cms:5.1.422.4"/>
    <category term="cpe:/a:episerver:episerver_cms:5.2.375.133"/>
    <category term="cpe:/a:episerver:episerver_cms:5.2.375.236"/>
    <category term="cpe:/a:episerver:episerver_cms:5.2.375.7"/>
    <category term="cpe:/a:episerver:episerver_cms:6.0.530.0"/>
    <category term="cpe:/a:episerver:episerver_cms:6.1.379.0"/>
    <sec:identifier>CVE-2012-1034</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1018:mod_currencyconverter: Cross-site scripting (XSS) vulnerability in include...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1018_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1018_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1018_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Cross-site scripting (XSS) vulnerability in includes/convert.php in D-Mack Media Currency Converter (mod_currencyconverter) module 1.0.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the from parameter.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1018_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:dmackmedia:mod_currencyconverter:1.0.0"/>
    <category term="cpe:/a:joomla:joomla%21"/>
    <sec:identifier>CVE-2012-1018</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1031:episerver_cms: Unspecified vulnerability in EPiServer CMS 5 and 6 ...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1031_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1031_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1031_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Unspecified vulnerability in EPiServer CMS 5 and 6 through 6R2, in certain configurations using Forms Authentication, allows remote authenticated users to obtain WebAdmins access by leveraging Edit Mode privileges, a different vulnerability than CVE-2011-3416 and CVE-2011-3417.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1031_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:episerver:episerver_cms:5.1.422.122"/>
    <category term="cpe:/a:episerver:episerver_cms:5.1.422.256"/>
    <category term="cpe:/a:episerver:episerver_cms:5.1.422.267"/>
    <category term="cpe:/a:episerver:episerver_cms:5.1.422.4"/>
    <category term="cpe:/a:episerver:episerver_cms:5.2.375.133"/>
    <category term="cpe:/a:episerver:episerver_cms:5.2.375.236"/>
    <category term="cpe:/a:episerver:episerver_cms:5.2.375.7"/>
    <category term="cpe:/a:episerver:episerver_cms:6.0.530.0"/>
    <category term="cpe:/a:episerver:episerver_cms:6.1.379.0"/>
    <sec:identifier>CVE-2012-1031</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1023:4images: Open redirect vulnerability in admin/index.php in 4...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1023_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1023_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1023_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Open redirect vulnerability in admin/index.php in 4images 1.7.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1023_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:4homepages:4images:1.7.10"/>
    <sec:identifier>CVE-2012-1023</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1029:tube_ace: SQL injection vulnerability in mobile/search/index....</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1029_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1029_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1029_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
SQL injection vulnerability in mobile/search/index.php in Tube Ace (Adult PHP Tube Script) 1.6 allows remote attackers to execute arbitrary SQL commands via the q parameter.  NOTE: some of these details are obtained from third party information.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1029_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:tubeace:tube_ace:1.6"/>
    <sec:identifier>CVE-2012-1029</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1025:enigma2_webinterface: Absolute path traversal vulnerability in file in En...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1025_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1025_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1025_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Absolute path traversal vulnerability in file in Enigma2 Webinterface 1.6.0 through 1.6.8, 1.6rc3, and 1.7.0 allows remote attackers to read arbitrary files via a full pathname in the file parameter.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1025_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:dream-multimedia-tv:enigma2_webinterface:1.6.0"/>
    <category term="cpe:/a:dream-multimedia-tv:enigma2_webinterface:1.6.1"/>
    <category term="cpe:/a:dream-multimedia-tv:enigma2_webinterface:1.6.2"/>
    <category term="cpe:/a:dream-multimedia-tv:enigma2_webinterface:1.6.3"/>
    <category term="cpe:/a:dream-multimedia-tv:enigma2_webinterface:1.6.4"/>
    <category term="cpe:/a:dream-multimedia-tv:enigma2_webinterface:1.6.5"/>
    <category term="cpe:/a:dream-multimedia-tv:enigma2_webinterface:1.6.6"/>
    <category term="cpe:/a:dream-multimedia-tv:enigma2_webinterface:1.6.7"/>
    <category term="cpe:/a:dream-multimedia-tv:enigma2_webinterface:1.6.8"/>
    <category term="cpe:/a:dream-multimedia-tv:enigma2_webinterface:1.6:rc3"/>
    <category term="cpe:/a:dream-multimedia-tv:enigma2_webinterface:1.7.0"/>
    <sec:identifier>CVE-2012-1025</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1027:]project-open[: Cross-site scripting (XSS) vulnerability in account...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1027_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1027_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1027_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Cross-site scripting (XSS) vulnerability in account-closed.tcl in ]project-open[ (aka ]po[) 3.4.x, 3.5.0.1-2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the message parameter to register/account-closed.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1027_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:project-open:%5Dproject-open%5B:3.4.0"/>
    <category term="cpe:/a:project-open:%5Dproject-open%5B:3.5.0.1-2"/>
    <sec:identifier>CVE-2012-1027</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1022:4images: SQL injection vulnerability in admin/categories.php...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1022_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1022_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1022_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
SQL injection vulnerability in admin/categories.php in 4images 1.7.10 remote attackers to execute arbitrary SQL commands via the cat_parent_id parameter in an addcat action.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1022_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:4homepages:4images:1.7.10"/>
    <sec:identifier>CVE-2012-1022</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1021:4images: Cross-site scripting (XSS) vulnerability in admin/c...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1021_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1021_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1021_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Cross-site scripting (XSS) vulnerability in admin/categories.php in 4images 1.7.10 allows remote attackers to inject arbitrary web script or HTML via the cat_parent_id parameter in an addcat action.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1021_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:4homepages:4images:1.7.10"/>
    <sec:identifier>CVE-2012-1021</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1005:mobile_web_server: Multiple cross-site scripting (XSS) vulnerabilities...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1005_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1005_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1005_AD_1.html</id>
    <published>2012-02-07T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple cross-site scripting (XSS) vulnerabilities in Sphinx Software Mobile Web Server 3.1.2.47 allow remote attackers to inject arbitrary web script or HTML via the comment parameter to a blog, as demonstrated using (1) Blog/MyFirstBlog.txt or (2) Blog/AboutSomething.txt.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1005_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:sphinx-soft:mobile_web_server:3.1.2.47"/>
    <sec:identifier>CVE-2012-1005</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5077:hdwiki: Unrestricted file upload vulnerability in attacheme...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2011-5077_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2011-5077_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2011-5077_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Unrestricted file upload vulnerability in attachement.php in HDWiki 5.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in image directory.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2011-5077_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hudong:hdwiki:5.0"/>
    <sec:identifier>CVE-2011-5077</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1017:base: Multiple SQL injection vulnerabilities in base_qry_...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1017_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1017_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1017_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple SQL injection vulnerabilities in base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary SQL commands via the (1) ip_addr[0][1], (2) ip_addr[0][2], or (3) ip_addr[0][9] parameters.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1017_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:secureideas:base:1.4.5"/>
    <sec:identifier>CVE-2012-1017</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1008:officesip_server: OfficeSIP Server 3.1 allows remote attackers to cau...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1008_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1008_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1008_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
OfficeSIP Server 3.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted To header in a SIP INVITE message.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1008_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:officesip:officesip_server:3.1"/>
    <sec:identifier>CVE-2012-1008</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1024:enigma2_webinterface: Directory traversal vulnerability in file in Enigma...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1024_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1024_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1024_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Directory traversal vulnerability in file in Enigma2 Webinterface 1.5rc1 and 1.5beta4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1024_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:dream-multimedia-tv:enigma2_webinterface:1.5:beta4"/>
    <category term="cpe:/a:dream-multimedia-tv:enigma2_webinterface:1.5:rc1"/>
    <sec:identifier>CVE-2012-1024</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5076:hdwiki: SQL injection vulnerability in model/comment.class....</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2011-5076_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2011-5076_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2011-5076_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
SQL injection vulnerability in model/comment.class.php in HDWiki 5.0, 5.1, and possibly other versions allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to index.php.  NOTE: some of these details are obtained from third party information.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2011-5076_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hudong:hdwiki:5.0"/>
    <category term="cpe:/a:hudong:hdwiki:5.1"/>
    <sec:identifier>CVE-2011-5076</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1026:xray_cms: Multiple SQL injection vulnerabilities in login2.ph...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1026_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1026_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1026_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple SQL injection vulnerabilities in login2.php in XRay CMS 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1026_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:johannes_ekberg:xray_cms:1.1.1"/>
    <sec:identifier>CVE-2012-1026</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1011:allwebmenus_plugin: actions.php in the AllWebMenus plugin 1.1.8 for Wor...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1011_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1011_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1011_AD_1.html</id>
    <published>2012-02-07T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
actions.php in the AllWebMenus plugin 1.1.8 for WordPress allows remote attackers to bypass intended access restrictions to upload and execute arbitrary PHP code by setting the HTTP_REFERER to a certain value, then uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1011_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.1.8"/>
    <category term="cpe:/a:wordpress:wordpress"/>
    <sec:identifier>CVE-2012-1011</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-0990:dclassifieds: Cross-site request forgery (CSRF) vulnerability in ...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0990_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0990_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0990_AD_1.html</id>
    <published>2012-02-07T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attackers to hijack the authentication of administrators for requests that modify account settings such as the administrator password or email via certain Settings[] parameters.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0990_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:dclassifieds:dclassifieds:0.1:final"/>
    <sec:identifier>CVE-2012-0990</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-0992:openemr: interface/fax/fax_dispatch.php in OpenEMR 4.1.0 all...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0992_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0992_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0992_AD_1.html</id>
    <published>2012-02-07T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
interface/fax/fax_dispatch.php in OpenEMR 4.1.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the file parameter.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0992_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:openemr:openemr:4.1.0"/>
    <sec:identifier>CVE-2012-0992</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1002:openconf: Unspecified vulnerability in OpenConf 4.x before 4....</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1002_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Unspecified vulnerability in OpenConf 4.x before 4.12 has unknown impact and attack vectors.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:zakongroup:openconf:4.00"/>
    <category term="cpe:/a:zakongroup:openconf:4.01"/>
    <category term="cpe:/a:zakongroup:openconf:4.02"/>
    <category term="cpe:/a:zakongroup:openconf:4.10"/>
    <category term="cpe:/a:zakongroup:openconf:4.11"/>
    <sec:identifier>CVE-2012-1002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-0991:openemr: Multiple directory traversal vulnerabilities in Ope...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0991_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0991_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0991_AD_1.html</id>
    <published>2012-02-07T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple directory traversal vulnerabilities in OpenEMR 4.1.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the formname parameter to (1) contrib/acog/print_form.php; or (2) load_form.php, (3) view_form.php, or (4) trend_form.php in interface/patient_file/encounter.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0991_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:openemr:openemr:4.1.0"/>
    <sec:identifier>CVE-2012-0991</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1010:allwebmenus_plugin: Unrestricted file upload vulnerability in actions.p...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1010_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1010_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1010_AD_1.html</id>
    <published>2012-02-07T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1010_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.0.1"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.0.10"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.0.11"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.0.12"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.0.17"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.0.18"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.0.19"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.0.20"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.0.21"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.0.22"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.0.23"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.0.24"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.0.3"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.0.4"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.0.9"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.1.1"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.1.2"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.1.3"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.1.4"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.1.5"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.1.6"/>
    <category term="cpe:/a:likno:allwebmenus_plugin:1.1.7 and previous versions"/>
    <category term="cpe:/a:wordpress:wordpress"/>
    <sec:identifier>CVE-2012-1010</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1004:foswiki: Multiple cross-site scripting (XSS) vulnerabilities...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1004_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1004_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1004_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple cross-site scripting (XSS) vulnerabilities in UI/Register.pm in Foswiki before 1.1.5 allow remote authenticated users with CHANGE privileges to inject arbitrary web script or HTML via the (1) text, (2) FirstName, (3) LastName, (4) OrganisationName, (5) OrganisationUrl, (6) Profession, (7) Country, (8) State, (9) Address, (10) Location, (11) Telephone, (12) VoIP, (13) InstantMessagingIM, (14) Email, (15) HomePage, or (16) Comment parameter.  NOTE: some of these details are obtained fr...&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1004_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:foswiki:foswiki:1.1.0"/>
    <category term="cpe:/a:foswiki:foswiki:1.1.1"/>
    <category term="cpe:/a:foswiki:foswiki:1.1.2"/>
    <category term="cpe:/a:foswiki:foswiki:1.1.3"/>
    <category term="cpe:/a:foswiki:foswiki:1.1.4"/>
    <category term="cpe:/a:foswiki:foswiki:1.1.4:beta"/>
    <category term="cpe:/a:foswiki:foswiki:1.1.4:rc"/>
    <sec:identifier>CVE-2012-1004</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1028:simplegroupware: Cross-site scripting (XSS) vulnerability in bin/ind...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1028_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1028_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1028_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Cross-site scripting (XSS) vulnerability in bin/index.php in SimpleGroupware 0.742 and other versions before 0.743 allows remote attackers to inject arbitrary web script or HTML via the export parameter.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1028_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:simple-groupware:simplegroupware:0.742"/>
    <sec:identifier>CVE-2012-1028</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1020:nexorone_online_banking_system: Multiple cross-site scripting (XSS) vulnerabilities...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1020_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1020_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1020_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple cross-site scripting (XSS) vulnerabilities in login.php in NexorONE Online Banking allow remote attackers to inject arbitrary web script or HTML via the (1) visitor_language parameter to register.php or (2) message parameter.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1020_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:overseaswtc:nexorone_online_banking_system:-"/>
    <sec:identifier>CVE-2012-1020</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1019:xwiki_enterprise: Multiple cross-site scripting (XSS) vulnerabilities...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1019_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1019_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1019_AD_1.html</id>
    <published>2012-02-08T00:00:00+09:00</published>
    <updated>2012-02-08T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple cross-site scripting (XSS) vulnerabilities in XWiki Enterprise 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) XWiki.XWikiComments_comment parameter to xwiki/bin/commentadd/Main/WebHome, (2) XWiki.XWikiUsers_0_company parameter when editing a user profile, or (3) projectVersion parameter to xwiki/bin/view/DownloadCode/DownloadFeedback.  NOTE: some of these details are obtained from third party information.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1019_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:xwiki:xwiki_enterprise:3.4"/>
    <sec:identifier>CVE-2012-1019</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001309:Project Open &#12395;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001309_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001309_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001309_AD_1.html</id>
    <published>2012-02-07T16:22:31+09:00</published>
    <updated>2012-02-07T16:22:31+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Project Open には、クロスサイトスクリプティングの脆弱性が存在します。  Project Open には、入力パラメータの処理に問題があり、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001309_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:misc:project-open_%5Dpo%5B"/>
    <sec:identifier>JVNDB-2012-001309</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001308:HTC &#35069; Android &#31471;&#26411;&#12395; Wi-Fi &#35469;&#35388;&#24773;&#22577;&#28431;&#12360;&#12356;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001308_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001308_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001308_AD_1.html</id>
    <published>2012-02-07T16:21:51+09:00</published>
    <updated>2012-02-07T16:21:51+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
HTC 製 Android 端末には、Wi-Fi の認証情報が漏えいする脆弱性が存在します。  HTC 製 Android 端末には、認証情報の管理に問題があり、Wi-Fi の認証情報が漏えいする脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001308_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/h:htc:desire_hd"/>
    <category term="cpe:/h:htc:desire_s"/>
    <category term="cpe:/h:htc:droid_incredible"/>
    <category term="cpe:/h:htc:evo_3d"/>
    <category term="cpe:/h:htc:evo_4g"/>
    <category term="cpe:/h:htc:glacier"/>
    <category term="cpe:/h:htc:sensation_4g"/>
    <category term="cpe:/h:htc:sensation_z710e"/>
    <category term="cpe:/h:htc:thunderbolt_4g"/>
    <sec:identifier>JVNDB-2012-001308</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001307:Scriptsez.net &#12398; Ez Album &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001307_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001307_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001307_AD_1.html</id>
    <published>2012-02-07T16:19:18+09:00</published>
    <updated>2012-02-07T16:19:18+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Scriptsez.net の Ez Album には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001307_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:scriptsez:ez_album"/>
    <sec:identifier>JVNDB-2012-001307</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001306:Vastal I-Tech Agent Zone &#12398; search.php &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001306_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001306_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001306_AD_1.html</id>
    <published>2012-02-07T16:18:29+09:00</published>
    <updated>2012-02-07T16:18:29+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Vastal I-Tech Agent Zone の search.php には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001306_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:vastal:agent_zone"/>
    <sec:identifier>JVNDB-2012-001306</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001305:phpShowtime &#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12362;&#12424;&#12403;&#12452;&#12513;&#12540;&#12472;&#12501;&#12449;&#12452;&#12523;&#12434;&#12522;&#12473;&#12488;&#12450;&#12483;&#12503;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001305_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001305_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001305_AD_1.html</id>
    <published>2012-02-07T16:17:19+09:00</published>
    <updated>2012-02-07T16:17:19+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
phpShowtime には、任意のディレクトリおよびイメージファイルをリストアップされる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001305_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:kybernetika:phpshowtime"/>
    <sec:identifier>JVNDB-2012-001305</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001304:phux Download Manager &#12398; download.php &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001304_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001304_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001304_AD_1.html</id>
    <published>2012-02-07T16:16:14+09:00</published>
    <updated>2012-02-07T16:16:14+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
phux Download Manager の download.php には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001304_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:phux:download_manager"/>
    <sec:identifier>JVNDB-2012-001304</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001303:TWiki &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001303_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001303_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001303_AD_1.html</id>
    <published>2012-02-07T16:14:07+09:00</published>
    <updated>2012-02-07T16:14:07+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
TWiki には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001303_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:twiki:twiki"/>
    <sec:identifier>JVNDB-2012-001303</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001302:LuraWave JP2 Browser Plug-In &#12395;&#12362;&#12369;&#12427;&#12473;&#12479;&#12483;&#12463;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001302_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001302_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001302_AD_1.html</id>
    <published>2012-02-07T16:13:19+09:00</published>
    <updated>2012-02-07T16:13:19+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
LuraWave JP2 Browser Plug-In の npjp2.dll には、スタックベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001302_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:luratech:lurawave_jp2_browser_plug-in"/>
    <sec:identifier>JVNDB-2012-001302</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001301:LuraWave JP2 ActiveX Control &#12395;&#12362;&#12369;&#12427;&#12473;&#12479;&#12483;&#12463;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001301_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001301_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001301_AD_1.html</id>
    <published>2012-02-07T16:12:28+09:00</published>
    <updated>2012-02-07T16:12:28+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
LuraWave JP2 ActiveX Control の jp2_x.dll には、スタックベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001301_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:luratech:lurawave_jp2_activex_control"/>
    <sec:identifier>JVNDB-2012-001301</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001300:SilverStripe &#12398; admin/EditForm &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001300_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001300_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001300_AD_1.html</id>
    <published>2012-02-07T16:10:28+09:00</published>
    <updated>2012-02-07T16:10:28+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
SilverStripe の admin/EditForm には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001300_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:silverstripe:silverstripe"/>
    <sec:identifier>JVNDB-2012-001300</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001299:Image Hosting Script DPI &#12398; misc.php &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001299_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001299_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001299_AD_1.html</id>
    <published>2012-02-07T16:00:31+09:00</published>
    <updated>2012-02-07T16:00:31+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Image Hosting Script DPI の misc.php には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001299_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:clixint:image_hosting_script_dpi"/>
    <sec:identifier>JVNDB-2012-001299</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001298:&#35079;&#25968;&#12398; BSD-based &#12458;&#12506;&#12524;&#12540;&#12486;&#12451;&#12531;&#12464;&#12471;&#12473;&#12486;&#12512;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001298_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001298_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001298_AD_1.html</id>
    <published>2012-02-07T15:51:09+09:00</published>
    <updated>2012-02-07T15:51:09+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の BSD-based オペレーティングシステムの IPv6 スタック内にある Neighbor Discovery (ND) プロトコルの実装には、サービス運用妨害 (CPU 資源の消費およびデバイスハング) 状態となる脆弱性が存在します。 本脆弱性は、CVE-2010-4670 と類似した脆弱性です。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001298_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:freebsd:freebsd"/>
    <category term="cpe:/o:netbsd:netbsd"/>
    <sec:identifier>JVNDB-2012-001298</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001297:Linux kernel &#12395;&#12362;&#12369;&#12427;&#12493;&#12483;&#12488;&#12527;&#12540;&#12463;&#30423;&#32884;&#12434;&#26908;&#20986;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001297_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001297_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001297_AD_1.html</id>
    <published>2012-02-07T15:50:17+09:00</published>
    <updated>2012-02-07T15:50:17+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Linux kernel には、IPv6 を利用するとき、ホストがネットワーク盗聴をしているかどうかを検出される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001297_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:linux:linux_kernel"/>
    <sec:identifier>JVNDB-2012-001297</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2012-001296:Microsoft Windows &#12395;&#12362;&#12369;&#12427;&#12493;&#12483;&#12488;&#12527;&#12540;&#12463;&#30423;&#32884;&#12434;&#26908;&#20986;&#12373;&#12428;&#12427;&#21839;&#38988;</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001296_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001296_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001296_AD_1.html</id>
    <published>2012-02-07T15:44:59+09:00</published>
    <updated>2012-02-07T15:44:59+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Microsoft Windows は、IPv6 を利用するとき、ホストがネットワーク盗聴をしているかどうかを検出される問題が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/JVNiPedia_JVNDB-2012-001296_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:microsoft:windows-nt:2000"/>
    <category term="cpe:/o:microsoft:windows-nt:2003"/>
    <category term="cpe:/o:microsoft:windows-nt:vista"/>
    <category term="cpe:/o:microsoft:windows-nt:xp"/>
    <category term="cpe:/o:microsoft:windows_7"/>
    <category term="cpe:/o:microsoft:windows_server_2008"/>
    <sec:identifier>JVNDB-2012-001296</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4041:webaccess: webvrpcs.exe in Advantech/BroadWin WebAccess allows...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2011-4041_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2011-4041_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2011-4041_AD_1.html</id>
    <published>2012-02-06T00:00:00+09:00</published>
    <updated>2012-02-07T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code value via a long string in an RPC request to TCP port 4592.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2011-4041_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:broadwin:webaccess"/>
    <sec:identifier>CVE-2011-4041</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-0290:pcanywhere, altiris_client_management_suite_pcanywhere_solution, altiris_deployme...: Symantec pcAnywhere through 12.5.3, Altiris IT Mana...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0290_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0290_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0290_AD_1.html</id>
    <published>2012-02-06T00:00:00+09:00</published>
    <updated>2012-02-07T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) do not properly handle the client state after abnormal termination of a remote session, which allows remote attackers to obtain access to the client by leveraging an &quot;open client session.&quot;&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0290_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:symantec:altiris_client_management_suite_pcanywhere_solution:12.5"/>
    <category term="cpe:/a:symantec:altiris_client_management_suite_pcanywhere_solution:12.5:sp1"/>
    <category term="cpe:/a:symantec:altiris_client_management_suite_pcanywhere_solution:12.5:sp2"/>
    <category term="cpe:/a:symantec:altiris_client_management_suite_pcanywhere_solution:12.6"/>
    <category term="cpe:/a:symantec:altiris_client_management_suite_pcanywhere_solution:12.6:sp1"/>
    <category term="cpe:/a:symantec:altiris_client_management_suite_pcanywhere_solution:12.6:sp2"/>
    <category term="cpe:/a:symantec:altiris_deployment_solution_remote_pcanywhere_solution:12.5"/>
    <category term="cpe:/a:symantec:altiris_deployment_solution_remote_pcanywhere_solution:12.5:sp1"/>
    <category term="cpe:/a:symantec:altiris_deployment_solution_remote_pcanywhere_solution:12.5:sp2"/>
    <category term="cpe:/a:symantec:altiris_deployment_solution_remote_pcanywhere_solution:12.6"/>
    <category term="cpe:/a:symantec:altiris_deployment_solution_remote_pcanywhere_solution:12.6:sp1"/>
    <category term="cpe:/a:symantec:altiris_deployment_solution_remote_pcanywhere_solution:12.6:sp2"/>
    <category term="cpe:/a:symantec:pcanywhere:10.5"/>
    <category term="cpe:/a:symantec:pcanywhere:11.5"/>
    <category term="cpe:/a:symantec:pcanywhere:11.5.1"/>
    <category term="cpe:/a:symantec:pcanywhere:12.1"/>
    <category term="cpe:/a:symantec:pcanywhere:12.5"/>
    <category term="cpe:/a:symantec:pcanywhere:12.5.265"/>
    <category term="cpe:/a:symantec:pcanywhere:12.5.3 and previous versions"/>
    <category term="cpe:/a:symantec:pcanywhere:12.5.539"/>
    <category term="cpe:/a:symantec:pcanywhere:12.5:sp1"/>
    <category term="cpe:/a:symantec:pcanywhere:12.5:sp2"/>
    <category term="cpe:/a:symantec:pcanywhere:12.5:sp3"/>
    <category term="cpe:/a:symantec:pcanywhere:12.6.65"/>
    <category term="cpe:/a:symantec:pcanywhere:12.6.7580"/>
    <category term="cpe:/a:symantec:pcanywhere:5.0"/>
    <category term="cpe:/a:symantec:pcanywhere:8.0"/>
    <category term="cpe:/a:symantec:pcanywhere:9.2"/>
    <sec:identifier>CVE-2012-0290</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1006:struts: Multiple cross-site scripting (XSS) vulnerabilities...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1006_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1006_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1006_AD_1.html</id>
    <published>2012-02-07T00:00:00+09:00</published>
    <updated>2012-02-07T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to struts2-showcase/person/editPerson.action, or the (3) clientName parameter to struts2-rest-showcase/orders.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1006_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apache:struts:2.0.14"/>
    <category term="cpe:/a:apache:struts:2.2.3"/>
    <sec:identifier>CVE-2012-1006</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1003:opera_browser: Multiple integer overflows in Opera 11.60 and earli...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1003_AD_1.html</id>
    <published>2012-02-07T00:00:00+09:00</published>
    <updated>2012-02-07T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple integer overflows in Opera 11.60 and earlier allow remote attackers to cause a denial of service (application crash) via a large integer argument to the (1) Int32Array, (2) Float32Array, (3) Float64Array, (4) Uint32Array, (5) Int16Array, or (6) ArrayBuffer function.  NOTE: the vendor reportedly characterizes this as &quot;a stability issue, not a security issue.&quot;&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:opera:opera_browser:10.00"/>
    <category term="cpe:/a:opera:opera_browser:10.00:beta1"/>
    <category term="cpe:/a:opera:opera_browser:10.00:beta2"/>
    <category term="cpe:/a:opera:opera_browser:10.00:beta3"/>
    <category term="cpe:/a:opera:opera_browser:10.01"/>
    <category term="cpe:/a:opera:opera_browser:10.10"/>
    <category term="cpe:/a:opera:opera_browser:10.10:beta1"/>
    <category term="cpe:/a:opera:opera_browser:10.11"/>
    <category term="cpe:/a:opera:opera_browser:10.50"/>
    <category term="cpe:/a:opera:opera_browser:10.50:beta1"/>
    <category term="cpe:/a:opera:opera_browser:10.50:beta2"/>
    <category term="cpe:/a:opera:opera_browser:10.51"/>
    <category term="cpe:/a:opera:opera_browser:10.52"/>
    <category term="cpe:/a:opera:opera_browser:10.52:beta1"/>
    <category term="cpe:/a:opera:opera_browser:10.52:beta2"/>
    <category term="cpe:/a:opera:opera_browser:10.53"/>
    <category term="cpe:/a:opera:opera_browser:10.53:beta1"/>
    <category term="cpe:/a:opera:opera_browser:10.54"/>
    <category term="cpe:/a:opera:opera_browser:10.60"/>
    <category term="cpe:/a:opera:opera_browser:10.60:beta1"/>
    <category term="cpe:/a:opera:opera_browser:10.61"/>
    <category term="cpe:/a:opera:opera_browser:10.62"/>
    <category term="cpe:/a:opera:opera_browser:10.63"/>
    <category term="cpe:/a:opera:opera_browser:11.00"/>
    <category term="cpe:/a:opera:opera_browser:11.00:beta"/>
    <category term="cpe:/a:opera:opera_browser:11.01"/>
    <category term="cpe:/a:opera:opera_browser:11.10"/>
    <category term="cpe:/a:opera:opera_browser:11.10:beta"/>
    <category term="cpe:/a:opera:opera_browser:11.11"/>
    <category term="cpe:/a:opera:opera_browser:11.50"/>
    <category term="cpe:/a:opera:opera_browser:11.50:beta"/>
    <category term="cpe:/a:opera:opera_browser:11.51"/>
    <category term="cpe:/a:opera:opera_browser:11.52"/>
    <category term="cpe:/a:opera:opera_browser:11.60 and previous versions"/>
    <category term="cpe:/a:opera:opera_browser:11.60:beta"/>
    <category term="cpe:/a:opera:opera_browser:5.0"/>
    <category term="cpe:/a:opera:opera_browser:5.02"/>
    <category term="cpe:/a:opera:opera_browser:5.0:beta2"/>
    <category term="cpe:/a:opera:opera_browser:5.0:beta3"/>
    <category term="cpe:/a:opera:opera_browser:5.0:beta4"/>
    <category term="cpe:/a:opera:opera_browser:5.0:beta5"/>
    <category term="cpe:/a:opera:opera_browser:5.0:beta6"/>
    <category term="cpe:/a:opera:opera_browser:5.0:beta7"/>
    <category term="cpe:/a:opera:opera_browser:5.0:beta8"/>
    <category term="cpe:/a:opera:opera_browser:5.10"/>
    <category term="cpe:/a:opera:opera_browser:5.11"/>
    <category term="cpe:/a:opera:opera_browser:5.12"/>
    <category term="cpe:/a:opera:opera_browser:6.0"/>
    <category term="cpe:/a:opera:opera_browser:6.01"/>
    <category term="cpe:/a:opera:opera_browser:6.02"/>
    <category term="cpe:/a:opera:opera_browser:6.03"/>
    <category term="cpe:/a:opera:opera_browser:6.04"/>
    <category term="cpe:/a:opera:opera_browser:6.05"/>
    <category term="cpe:/a:opera:opera_browser:6.06"/>
    <category term="cpe:/a:opera:opera_browser:6.0:beta1"/>
    <category term="cpe:/a:opera:opera_browser:6.0:beta2"/>
    <category term="cpe:/a:opera:opera_browser:6.0:beta3"/>
    <category term="cpe:/a:opera:opera_browser:6.0:tp1"/>
    <category term="cpe:/a:opera:opera_browser:6.0:tp2"/>
    <category term="cpe:/a:opera:opera_browser:6.0:tp3"/>
    <category term="cpe:/a:opera:opera_browser:6.1"/>
    <category term="cpe:/a:opera:opera_browser:6.11"/>
    <category term="cpe:/a:opera:opera_browser:6.12"/>
    <category term="cpe:/a:opera:opera_browser:6.1:beta1"/>
    <category term="cpe:/a:opera:opera_browser:7.0"/>
    <category term="cpe:/a:opera:opera_browser:7.01"/>
    <category term="cpe:/a:opera:opera_browser:7.02"/>
    <category term="cpe:/a:opera:opera_browser:7.03"/>
    <category term="cpe:/a:opera:opera_browser:7.0:beta1"/>
    <category term="cpe:/a:opera:opera_browser:7.0:beta1_v2"/>
    <category term="cpe:/a:opera:opera_browser:7.0:beta2"/>
    <category term="cpe:/a:opera:opera_browser:7.10"/>
    <category term="cpe:/a:opera:opera_browser:7.10:beta1"/>
    <category term="cpe:/a:opera:opera_browser:7.11"/>
    <category term="cpe:/a:opera:opera_browser:7.11:beta2"/>
    <category term="cpe:/a:opera:opera_browser:7.20"/>
    <category term="cpe:/a:opera:opera_browser:7.20:beta7"/>
    <category term="cpe:/a:opera:opera_browser:7.21"/>
    <category term="cpe:/a:opera:opera_browser:7.22"/>
    <category term="cpe:/a:opera:opera_browser:7.23"/>
    <category term="cpe:/a:opera:opera_browser:7.50"/>
    <category term="cpe:/a:opera:opera_browser:7.50:beta1"/>
    <category term="cpe:/a:opera:opera_browser:7.51"/>
    <category term="cpe:/a:opera:opera_browser:7.52"/>
    <category term="cpe:/a:opera:opera_browser:7.53"/>
    <category term="cpe:/a:opera:opera_browser:7.54"/>
    <category term="cpe:/a:opera:opera_browser:7.54:update1"/>
    <category term="cpe:/a:opera:opera_browser:7.54:update2"/>
    <category term="cpe:/a:opera:opera_browser:8.0"/>
    <category term="cpe:/a:opera:opera_browser:8.01"/>
    <category term="cpe:/a:opera:opera_browser:8.02"/>
    <category term="cpe:/a:opera:opera_browser:8.0:beta1"/>
    <category term="cpe:/a:opera:opera_browser:8.0:beta2"/>
    <category term="cpe:/a:opera:opera_browser:8.0:beta3"/>
    <category term="cpe:/a:opera:opera_browser:8.50"/>
    <category term="cpe:/a:opera:opera_browser:8.51"/>
    <category term="cpe:/a:opera:opera_browser:8.52"/>
    <category term="cpe:/a:opera:opera_browser:8.53"/>
    <category term="cpe:/a:opera:opera_browser:8.54"/>
    <category term="cpe:/a:opera:opera_browser:9.0"/>
    <category term="cpe:/a:opera:opera_browser:9.01"/>
    <category term="cpe:/a:opera:opera_browser:9.02"/>
    <category term="cpe:/a:opera:opera_browser:9.0:beta1"/>
    <category term="cpe:/a:opera:opera_browser:9.0:beta2"/>
    <category term="cpe:/a:opera:opera_browser:9.10"/>
    <category term="cpe:/a:opera:opera_browser:9.20"/>
    <category term="cpe:/a:opera:opera_browser:9.20:beta1"/>
    <category term="cpe:/a:opera:opera_browser:9.21"/>
    <category term="cpe:/a:opera:opera_browser:9.22"/>
    <category term="cpe:/a:opera:opera_browser:9.23"/>
    <category term="cpe:/a:opera:opera_browser:9.24"/>
    <category term="cpe:/a:opera:opera_browser:9.25"/>
    <category term="cpe:/a:opera:opera_browser:9.26"/>
    <category term="cpe:/a:opera:opera_browser:9.27"/>
    <category term="cpe:/a:opera:opera_browser:9.50"/>
    <category term="cpe:/a:opera:opera_browser:9.50:beta1"/>
    <category term="cpe:/a:opera:opera_browser:9.50:beta2"/>
    <category term="cpe:/a:opera:opera_browser:9.51"/>
    <category term="cpe:/a:opera:opera_browser:9.52"/>
    <category term="cpe:/a:opera:opera_browser:9.60"/>
    <category term="cpe:/a:opera:opera_browser:9.60:beta1"/>
    <category term="cpe:/a:opera:opera_browser:9.61"/>
    <category term="cpe:/a:opera:opera_browser:9.62"/>
    <category term="cpe:/a:opera:opera_browser:9.63"/>
    <category term="cpe:/a:opera:opera_browser:9.64"/>
    <sec:identifier>CVE-2012-1003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-1007:struts: Multiple cross-site scripting (XSS) vulnerabilities...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1007_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1007_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1007_AD_1.html</id>
    <published>2012-02-07T00:00:00+09:00</published>
    <updated>2012-02-07T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) struts-cookbook/processSimple.do or (3) struts-cookbook/processDyna.do.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-1007_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apache:struts:1.3.10"/>
    <sec:identifier>CVE-2012-1007</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-0830:php: The php_register_variable_ex function in php_variab...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0830_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0830_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0830_AD_1.html</id>
    <published>2012-02-06T00:00:00+09:00</published>
    <updated>2012-02-07T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0830_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:php:php:5.3.9"/>
    <sec:identifier>CVE-2012-0830</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-0396:documentum_xplore: EMC Documentum xPlore 1.0, 1.1 before P07, and 1.2 ...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0396_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0396_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0396_AD_1.html</id>
    <published>2012-02-06T00:00:00+09:00</published>
    <updated>2012-02-07T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
EMC Documentum xPlore 1.0, 1.1 before P07, and 1.2 does not properly enforce the requirement for BROWSE permission, which allows remote authenticated users to determine the existence of an object, or read object metadata, via a search.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0396_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:emc:documentum_xplore:1.0"/>
    <category term="cpe:/a:emc:documentum_xplore:1.1"/>
    <category term="cpe:/a:emc:documentum_xplore:1.1:p01"/>
    <category term="cpe:/a:emc:documentum_xplore:1.1:p03"/>
    <category term="cpe:/a:emc:documentum_xplore:1.2"/>
    <sec:identifier>CVE-2012-0396</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2012-0194:aix: The TCP implementation in IBM AIX 5.3, 6.1, and 7.1...</title>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0194_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0194_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0194_AD_1.html</id>
    <published>2012-02-06T00:00:00+09:00</published>
    <updated>2012-02-07T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
The TCP implementation in IBM AIX 5.3, 6.1, and 7.1, when the Large Send Offload option is enabled, allows remote attackers to cause a denial of service (assertion failure and panic) via an unspecified series of packets.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/ja/NISTNVD_CVE-2012-0194_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:ibm:aix:5.3"/>
    <category term="cpe:/o:ibm:aix:6.1"/>
    <category term="cpe:/o:ibm:aix:7.1"/>
    <sec:identifier>CVE-2012-0194</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
</feed>

