<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>nGenuity Information Services &#187; Realty</title>
	<atom:link href="http://www.ngenuity.org/wordpress/category/verticals/realty/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ngenuity.org/wordpress</link>
	<description>Security for the A.D.D generation</description>
	<lastBuildDate>Wed, 10 Mar 2010 19:25:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>NGENUITY-2009-002 &#8211; Open-Realty SQL Injection</title>
		<link>http://www.ngenuity.org/wordpress/2009/01/27/ngenuity-2009-002-open-realty-sql-injection/</link>
		<comments>http://www.ngenuity.org/wordpress/2009/01/27/ngenuity-2009-002-open-realty-sql-injection/#comments</comments>
		<pubDate>Wed, 28 Jan 2009 05:22:56 +0000</pubDate>
		<dc:creator>Adam Baldwin</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Realty]]></category>
		<category><![CDATA[Web Application Security]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[blind sqli]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[sqli]]></category>
		<category><![CDATA[webappsec]]></category>

		<guid isPermaLink="false">http://www.ngenuity.org/wordpress/?p=98</guid>
		<description><![CDATA[nGenuity Information Services &#8211; Security Advisory
   Advisory ID: NGENUITY-2009-002
   Application: Open-Realty 2.5.5
        Vendor: Transparent Technologies,INC
Vendor website: http://www.transparent-tech.com/
        Author: Adam Baldwin (adam_baldwin@ngenuity-is.com)

  I. BACKGROUND
     "Open-Realty® is an open source web based real estate listing management
application. It is intended to [...]]]></description>
			<content:encoded><![CDATA[<p>nGenuity Information Services &#8211; Security Advisory</p>
<pre>   Advisory ID: NGENUITY-2009-002
   Application: Open-Realty 2.5.5
        Vendor: Transparent Technologies,INC
Vendor website: <a href="http://www.transparent-tech.com/">http://www.transparent-tech.com/</a>
        Author: Adam Baldwin (adam_baldwin@ngenuity-is.com)

  I. BACKGROUND
     "Open-Realty® is an open source web based real estate listing management
application. It is intended to be both easy to setup and use. Written
in PHP, Open-Realty® is designed to be a fast and flexible tool for
your real estate website" [1]

 II. DETAILS
     A Blind SQL Injection vulnerability exists within Open-Realty that is
     exploitable by a user with admin or agent privileges.

     This vulnerability can be exploited by inserting specially crafted SQL
     into the edit form field in the image upload feature of Open-Realty.

     Successful exploitation of this vulnerability could result in extraction
     of data from the Open-Realty database.

III. VENDOR
     1.27.2009 - Version 2.5.6 has been released and addresses this vulnerability.

 VI. REFERENCES
     [1] - http://www.open-realty.org/
Copyright (c) 2008 nGenuity Information Services, LLC</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.ngenuity.org/wordpress/2009/01/27/ngenuity-2009-002-open-realty-sql-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NGENUITY-2009-001 &#8211; Open-Realty Multiple XSS Vulnerabilities</title>
		<link>http://www.ngenuity.org/wordpress/2008/12/31/ngenuity-2009-001-open-realty-multiple-xss-vulnerabilities/</link>
		<comments>http://www.ngenuity.org/wordpress/2008/12/31/ngenuity-2009-001-open-realty-multiple-xss-vulnerabilities/#comments</comments>
		<pubDate>Wed, 31 Dec 2008 18:17:11 +0000</pubDate>
		<dc:creator>Adam Baldwin</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Realty]]></category>
		<category><![CDATA[Web Application Security]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.ngenuity.org/wordpress/?p=88</guid>
		<description><![CDATA[nGenuity Information Services &#8211; Security Advisory
   Advisory ID: NGENUITY-2009-001
   Application: Open-Realty 2.5.5
        Vendor: Transparent Technologies,INC
Vendor website: http://www.transparent-tech.com/
        Author: Adam Baldwin (adam_baldwin@ngenuity-is.com)

  I. BACKGROUND
     "Open-Realty® is an open source web based real estate listing management
application. It is intended to [...]]]></description>
			<content:encoded><![CDATA[<p>nGenuity Information Services &#8211; Security Advisory</p>
<pre>   Advisory ID: NGENUITY-2009-001
   Application: Open-Realty 2.5.5
        Vendor: Transparent Technologies,INC
Vendor website: <a href="http://www.transparent-tech.com/">http://www.transparent-tech.com/</a>
        Author: Adam Baldwin (adam_baldwin@ngenuity-is.com)

  I. BACKGROUND
     "Open-Realty® is an open source web based real estate listing management
application. It is intended to be both easy to setup and use. Written
in PHP, Open-Realty® is designed to be a fast and flexible tool for
your real estate website" [1]

 II. DETAILS
     Multiple reflected cross-site (xss) scripting vulnerabilities exist within
Open-Realty v2.5.5. These are due to user input being echoed back to the user
unaltered or properly encoded.

Reflected:

http://www.example.com/openrealty/index.php?action=contact_agent&amp;listing_id=XSS&amp;popup=yes

http://www.example.com/openrealty/index.php?action=contact_agent&amp;popup=yes&amp;agent_id=XSS

http://www.example.com/openrealty/index.php?action=calculator&amp;price=XSS&amp;popup=y

1.27.2009 - Version 2.5.6 has been released and addresses this vulnerability.

III. REFERENCES
     [1] - http://www.open-realty.org/
Copyright (c) 2008 nGenuity Information Services, LLC

 IV. EDITS
1/18/2008 - Vendor notification "releasing a new version of Open-Realty 2.5.6 this week to fix the XSS reflection vulnerabilities..."
1/20/2008 - Removed persistent section of advisory. Informed by the vendor that "There is an option to strip HTML from the
listing and agent fields when agents post in the Open-Realty  configuration, under Editor/Html. If that is on any html posted in a "
field by an agent will be removed."
1/27/2009 - Added vendor fix information.</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.ngenuity.org/wordpress/2008/12/31/ngenuity-2009-001-open-realty-multiple-xss-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
