<?xml version="1.0" encoding="utf-8" ?>
<rdf:RDF xmlns="http://purl.org/rss/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/">
<channel rdf:about="http://modxcms-jp.com/">
<title>modx Japan フォーラム</title>
<link>http://modxcms-jp.com/</link>
<description>modx日本語フォーラム＆日本公式サイトフォーラムの最新記事フィード</description>
<dc:language>ja</dc:language>
<dc:date>2012-01-19T00:52:27+09:00</dc:date>
<dc:publisher>MODx Japanese Team</dc:publisher>
<syn:updatePeriod>hourly</syn:updatePeriod>
<syn:updateFrequency>1</syn:updateFrequency>
<syn:updateBase>2012-01-19T00:52:27+09:00</syn:updateBase>
<items>
  <rdf:Seq>
<rdf:li resource="http://modx.jp/news/800.html" />
<rdf:li resource="http://modx.jp/news/796.html" />
<rdf:li resource="http://modx.jp/news/794.html" />
<rdf:li resource="http://modx.jp/news/793.html" />
<rdf:li resource="http://modx.jp/news/792.html" />
<rdf:li resource="http://modx.jp/news/790.html" />
<rdf:li resource="http://modx.jp/news/787.html" />
<rdf:li resource="http://modx.jp/news/788.html" />
<rdf:li resource="http://modx.jp/news/784.html" />
<rdf:li resource="http://modx.jp/news/781.html" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,67900.msg381421.html#msg381421" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,67900.msg381177.html#msg381177" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,66947.msg376951.html#msg376951" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,66364.msg374161.html#msg374161" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,65151.msg368235.html#msg368235" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,64823.msg366624.html#msg366624" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,64086.msg362540.html#msg362540" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,1030.msg359270.html#msg359270" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,63339.msg358752.html#msg358752" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,63339.msg358713.html#msg358713" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,60451.msg343741.html#msg343741" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,59421.msg338158.html#msg338158" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,58313.msg332802.html#msg332802" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,55314.msg318284.html#msg318284" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,55105.msg317273.html#msg317273" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,55062.msg317079.html#msg317079" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,50207.msg292386.html#msg292386" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,47759.msg280304.html#msg280304" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,38992.msg235150.html#msg235150" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,37961.msg229068.html#msg229068" />
<rdf:li resource="http://modxcms.com/forums/index.php/topic,30875.msg187190.html#msg187190" />
      </rdf:Seq>
</items>
</channel>
<item rdf:about="http://modx.jp/news/800.html">
    <title><![CDATA[WebMatrix版 1.0.5J-r10-p1リリースしました。]]></title>
    <link>http://modx.jp/news/800.html</link>
    <description><![CDATA[]]></description>
    <dc:subject></dc:subject>
    <dc:date>2012-01-19T00:52:27+09:00</dc:date>
    <dc:creator>MODX JAPAN</dc:creator>
</item>
<item rdf:about="http://modx.jp/news/796.html">
    <title><![CDATA[2011年振り返り]]></title>
    <link>http://modx.jp/news/796.html</link>
    <description><![CDATA[kmikage@広報担当です。2011年も、残り4時間ほどとなりました。皆様いかがお過ごしでしたでしょうか。]]></description>
    <dc:subject></dc:subject>
    <dc:date>2011-12-31T19:55:37+09:00</dc:date>
    <dc:creator>MODX JAPAN</dc:creator>
</item>
<item rdf:about="http://modx.jp/news/794.html">
    <title><![CDATA[MODX Revolution 2.2 RC3 をリリースしました]]></title>
    <link>http://modx.jp/news/794.html</link>
    <description><![CDATA[MODX Revolution 2.2 RC3がリリースされました。

■MODx Revolution 2.2 RC3 日本語版 ダウンロード
http://code.google.com/p/modx-revo-ja/downloads/detail?name=modx-2.2.0-rc3-ja.zip
Revolutionを稼働させるために必要な環境についてはこちら]]></description>
    <dc:subject></dc:subject>
    <dc:date>2011-12-24T15:00:00+09:00</dc:date>
    <dc:creator>MODX JAPAN</dc:creator>
</item>
<item rdf:about="http://modx.jp/news/793.html">
    <title><![CDATA[MODX Evolution 1.0.5J-r10をリリースしました]]></title>
    <link>http://modx.jp/news/793.html</link>
    <description><![CDATA[キャッシュの仕組みを改善し、ページ数が多いサイトで表示が重くなりにくいようにしました。DB接続のキープにも工夫を加え、負荷に強い運用が可能です。]]></description>
    <dc:subject></dc:subject>
    <dc:date>2011-12-22T22:22:22+09:00</dc:date>
    <dc:creator>MODX JAPAN</dc:creator>
</item>
<item rdf:about="http://modx.jp/news/792.html">
    <title><![CDATA[MODX Revolution 2.2 RC2 をリリースしました]]></title>
    <link>http://modx.jp/news/792.html</link>
    <description><![CDATA[MODX Revolution 2.2 RC2がリリースされました。

■MODx Revolution 2.2 RC1 日本語版 ダウンロード
http://code.google.com/p/modx-revo-ja/downloads/detail?name=modx-2.2.0-rc2-ja.zip
Revolutionを稼働させるために必要な環境についてはこちら]]></description>
    <dc:subject></dc:subject>
    <dc:date>2011-12-17T19:20:00+09:00</dc:date>
    <dc:creator>MODX JAPAN</dc:creator>
</item>
<item rdf:about="http://modx.jp/news/790.html">
    <title><![CDATA[MODX Evolution日本語版 Microsoft WebMatrixに対応・配信開始。]]></title>
    <link>http://modx.jp/news/790.html</link>
    <description><![CDATA[昨今CMSデベロッパーで話題のMicrosoft WebMatrixに、MODX 1.0.5J-r9が対応。
アプリケーションの配信が開始されました。]]></description>
    <dc:subject></dc:subject>
    <dc:date>2011-12-09T18:41:35+09:00</dc:date>
    <dc:creator>MODX JAPAN</dc:creator>
</item>
<item rdf:about="http://modx.jp/news/787.html">
    <title><![CDATA[MODX Evolution 1.0.5J-r9をリリースしました]]></title>
    <link>http://modx.jp/news/787.html</link>
    <description><![CDATA[管理画面を整備し、リソース一覧の操作を改善。同じ階層内に多数のページを持つブログのようなコンテンツを管理しやすくなっています。]]></description>
    <dc:subject></dc:subject>
    <dc:date>2011-12-05T23:45:00+09:00</dc:date>
    <dc:creator>MODX JAPAN</dc:creator>
</item>
<item rdf:about="http://modx.jp/news/788.html">
    <title><![CDATA[CMSカンファレンス with WeeklyCMS on Microsoft参加します。]]></title>
    <link>http://modx.jp/news/788.html</link>
    <description><![CDATA[12月17日の土曜日、CMS同士が交流するUstream番組「WeeklyCMS」（ウィークリーCMS）にて、Ustreamを飛び出しマイクロソフトのセミナールームをお借りし、各CMSがセッション・ライトニングトークを行います。]]></description>
    <dc:subject></dc:subject>
    <dc:date>2011-12-05T23:37:46+09:00</dc:date>
    <dc:creator>MODX JAPAN</dc:creator>
</item>
<item rdf:about="http://modx.jp/news/784.html">
    <title><![CDATA[MODX勉強会「麦乃大学」開催します]]></title>
    <link>http://modx.jp/news/784.html</link>
    <description><![CDATA[MODX勉強会「麦乃大学」を、マイクロソフト様のご協力のもと、１２月１０日に開催いたします。]]></description>
    <dc:subject></dc:subject>
    <dc:date>2011-11-22T01:15:13+09:00</dc:date>
    <dc:creator>MODX JAPAN</dc:creator>
</item>
<item rdf:about="http://modx.jp/news/781.html">
    <title><![CDATA[オープンソースカンファレンス 2011 Tokyo/Fall開催中]]></title>
    <link>http://modx.jp/news/781.html</link>
    <description><![CDATA[本日]]></description>
    <dc:subject></dc:subject>
    <dc:date>2011-11-19T15:23:37+09:00</dc:date>
    <dc:creator>MODX JAPAN</dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,67900.msg381421.html#msg381421">
    <title><![CDATA[Re: Community Forum Transition to New Discuss Forum [Scheduled Downtime]]]></title>
    <link>http://modxcms.com/forums/index.php/topic,67900.msg381421.html#msg381421</link>
    <description><![CDATA[The maintenance page we will put up will also have 7 &quot;secrets&quot; on it. While you&#39;re waiting, you can try and find them.<br /><br />We&#39;ll also post any updates on the maintenance page as we go.]]></description>
    <dc:subject>Important News</dc:subject>
    <dc:date>2011-08-20T07:05:09+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,67900.msg381177.html#msg381177">
    <title><![CDATA[Community Forum Transition to New Discuss Forum [Scheduled Downtime]]]></title>
    <link>http://modxcms.com/forums/index.php/topic,67900.msg381177.html#msg381177</link>
    <description><![CDATA[This Saturday, August 20 we will be taking the MODX Community forums offline while we migrate the posts and data to the new MODX Discuss-based forums. This transition is tentatively scheduled for approximately 9PM CDT. We will have the forums back online as quickly as we can (likely 3-4PM CDT Sunday) but it is possible the forums may be down for 24 hours or more. <br /><br />Should we encounter any issues or major bugs that prevent the migration, we will attempt to do the migration/transition in 2 weeks on Saturday, September 3rd, 2011. We will post any change to this plan here. <br /><br />Thanks to those of you who helped and are helping test the new forums. We sincerely appreciate your valuable time and feedback. <br /><br />The MODX Team]]></description>
    <dc:subject>Important News</dc:subject>
    <dc:date>2011-08-18T23:32:03+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,66947.msg376951.html#msg376951">
    <title><![CDATA[MODX Revolution 2.1.3 Out Now - Resolves Tag Parsing Issue]]></title>
    <link>http://modxcms.com/forums/index.php/topic,66947.msg376951.html#msg376951</link>
    <description><![CDATA[<span><b>Revolution 2.1.3 Resolves Tag Parsing Issue </b></span><br /><br />An astute MODX user reported an issue occurring with nested tags being parsed incorrectly which led us to release Revolution 2.1.3. Some of the other more minor bug fixes include: Resource tree sorting, double-slash in the file path from drag-and-drop and includeParent input option in Resource List TV.<br /><br />For more information about the MODX Revolution 2.1 release, please review the <a href="http://modxcms.com/forums/index.php/topic,64823.0.html" target="_blank">original Announcement</a>.<br /><br />Download <a href="http://modx.com/download/release/" target="_blank">Revolution 2.1.3</a><br />Read the <a href="http://rtfm.modx.com/display/revolution20/Home" target="_blank">Revolution 2.1.3 Documentation</a><br />Read the <a href="http://rtfm.modx.com/display/revolution20/Basic+Installation" target="_blank">Installation Guide</a><br /><a href="http://rtfm.modx.com/display/revolution20/Upgrading+MODX" target="_blank">Upgrade Guide</a><br />Check the <a href="http://rtfm.modx.com/display/revolution21/Server+Requirements" target="_blank">Installation Requirements</a><br /><br />We&#39;re always improvi...]]></description>
    <dc:subject>Important News</dc:subject>
    <dc:date>2011-07-23T05:07:40+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,66364.msg374161.html#msg374161">
    <title><![CDATA[Revolution 2.1.2 Out Now - Lots of Little Fixes and MS SQL Server Improvements]]></title>
    <link>http://modxcms.com/forums/index.php/topic,66364.msg374161.html#msg374161</link>
    <description><![CDATA[<span><b>Revolution 2.1.2 Updated and Optimized</b></span><br /><br />In this update several interface and performance issues have been resolved. Since the release of MODX Revolution 2.1.1 we have been making refinements and improving Revolution based on your feedback and issues we found. You may notice several usability improvements to the Manager and better performance on Microsoft SQL Server installs.<br /><br />Here are some highlights of the changes to MODX Revolution 2.1.2:<br /><br /><ul><li>Corrected caching issues with non-cacheable MODX tags in Resources</li><li>File browser to thumbnail path issue resolved</li><li>Corrected scrolling issues with custom manager pages not using ExtJS</li><li>Optimizations and improvements added for MODX on Microsoft SQL Server</li><li>Usability improvements in manager interface</li></ul><br />For more information about the MODX Revolution 2.1 release, please review the <a href="http://modxcms.com/forums/index.php/topic,64823.0.html" target="_blank">original Announcement</a>.<br /><br />Download [url=http://modx.com/...]]></description>
    <dc:subject>Important News</dc:subject>
    <dc:date>2011-07-07T04:39:12+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,65151.msg368235.html#msg368235">
    <title><![CDATA[Revolution 2.1.1 Out Now: Fix to Package Management, Hardening and More]]></title>
    <link>http://modxcms.com/forums/index.php/topic,65151.msg368235.html#msg368235</link>
    <description><![CDATA[<b>Revolution 2.1.1 Fixes Package Management Issue, Enhances Security and Much More</b><br /><br />A week ago we released the highly anticipated MODX Revolution 2.1 which added Microsoft SQL Server support, huge performance and caching improvements, the elimination of thousands of lines of long-deprecated code and so much more. It has been our most successful release to date in terms of download statistics. There were more than 5500 downloads in just one week—more than 785 a day! With so many downloads and people using this new version of Revo, it was inevitable and expected we would find a few issues needing to be solved. Thanks to all those who downloaded, deployed and especially to those of you who reported issues and filed feature requests. <br /><br />Here are the highlights of the changes in Revolution &nbsp;2.1.1:<br /><ul><li>Corrected an issue with Package Management relating to updates of Extras</li><li>Hardened manager security against CSRF attacks in unlikely case an attacker had previous Administrator credentials. </li>...</ul>]]></description>
    <dc:subject>Important News</dc:subject>
    <dc:date>2011-06-02T06:03:18+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,64823.msg366624.html#msg366624">
    <title><![CDATA[Revolution 2.1-pl Out Now]]></title>
    <link>http://modxcms.com/forums/index.php/topic,64823.msg366624.html#msg366624</link>
    <description><![CDATA[<b>Revolution 2.1 Adds Support for Microsoft SQL Server, Huge Performance Improvements, Long-deprecated Code Eliminated</b><br /><br />MODX Revolution 2.1 is a huge milestone for MODX. It adds Microsoft SQL Server support, huge performance and caching improvements, the elimination of thousands of lines of long-deprecated code and so much more. We are incredibly excited about this release and want to thank all the community members that have tested and reported issues in the lead up to this day.<br /><br /><b>What&#39;s New In 2.1:</b><br /><ul><li>Full Microsoft SQL Server support is new in 2.1. This is pretty cool and we&#39;re very excited about offering developers the choice of running MODX Revolution on a full MS stack.</li><li>The MODX caching system has been restructured to vastly improve caching times and performance. It now properly implements file locking, partitioning and multiple format support. We&#39;ve seen cache file sizes drop to nearly 30% (or greater) of their previous size and page load time significantly decrease. The co...</li></ul>]]></description>
    <dc:subject>Important News</dc:subject>
    <dc:date>2011-05-25T04:16:07+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,64086.msg362540.html#msg362540">
    <title><![CDATA[Out Now! Revolution 2.1 RC4: Final Testing before Public Release]]></title>
    <link>http://modxcms.com/forums/index.php/topic,64086.msg362540.html#msg362540</link>
    <description><![CDATA[<b>Revolution 2.1 Release Candidate 4: Final Testing before Public Release</b><br /><br />As you may already know, MODX Revolution 2.1 is a huge milestone in the development and future of MODX. From Microsoft SQL Server support to caching improvements to the elimination of thousands of lines of deprecated code, Release Candidate 4 (RC-4) fixes a number of additional issues and bugs identified by community members in the previous Release Candidate.<br /><br />We still need help from the community to ensure MODX Revolution is ready for its official public release. Testing, translations, documentation and updating Add-ons will all be part of this Release Candidate period which closes May 9th, 2011. We encourage you to test and use this release and welcome reports of issues to make sure that 2.1.0-pl will be a near-flawless release.<br /><br /><b>Test and Prepare</b><br />This is a Release Candidate and therefore <i>should not be considered safe for deployment on production servers without thorough testing</i> in a development or test environment....]]></description>
    <dc:subject>Important News</dc:subject>
    <dc:date>2011-05-03T21:35:42+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,1030.msg359270.html#msg359270">
    <title><![CDATA[Re: MODx Forum Guidelines]]></title>
    <link>http://modxcms.com/forums/index.php/topic,1030.msg359270.html#msg359270</link>
    <description><![CDATA[The guidelines have again been updated. Rants are now specifically addressed, whether they are made in forum signatures or repeated posts.]]></description>
    <dc:subject>Important News</dc:subject>
    <dc:date>2011-04-14T22:07:26+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,63339.msg358752.html#msg358752">
    <title><![CDATA[Re: Revolution 2.1 RC3 Lightens Further and Gets Lots of Little Fixes]]></title>
    <link>http://modxcms.com/forums/index.php/topic,63339.msg358752.html#msg358752</link>
    <description><![CDATA[We have corrected the Blank System Settings issue that existed in the build of Revolution 2.1-rc2 and have replaced it with a new build of Revolution 2.1-RC3. If you have installed RC2 you should probably download RC3. This bug didn&#39;t rear its head until the team created a build for distribution that was not apparent from our installs from GitHub. If you find a bug or issue in RC3, please make sure you file it here: <a href="http://bugs.modx.com/projects/revo/issues/new" target="_blank">http://bugs.modx.com/projects/revo/issues/new</a> <br /><br />Thanks.]]></description>
    <dc:subject>Important News</dc:subject>
    <dc:date>2011-04-12T06:41:17+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,63339.msg358713.html#msg358713">
    <title><![CDATA[Re: Revolution 2.1 RC2 Lightens Further and Gets Lots of Little Fixes]]></title>
    <link>http://modxcms.com/forums/index.php/topic,63339.msg358713.html#msg358713</link>
    <description><![CDATA[Due to a blocker bug in 2.1.0-rc2 that caused System Settings values to appear blank in the builds (yet not in Git installs), we have temporarily taken down the 2.1.0-rc2 install for now. We will re-release a fixed version later on today.<br /><br />For those who have already downloaded rc2, the patch for the bug can be found here: <a href="https://github.com/modxcms/revolution/commit/47bdab9230afe12f5261e69765972e70c2d2e9f6" target="_blank">https://github.com/modxcms/revolution/commit/47bdab9230afe12f5261e69765972e70c2d2e9f6</a>]]></description>
    <dc:subject>Important News</dc:subject>
    <dc:date>2011-04-12T03:11:31+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,60451.msg343741.html#msg343741">
    <title><![CDATA[MODx Evo 1.0.4 (and prior) SQL Injection and Directory Traversal Vulnerabities]]></title>
    <link>http://modxcms.com/forums/index.php/topic,60451.msg343741.html#msg343741</link>
    <description><![CDATA[<b>Status: Solved</b><br />Product: MODx Evolution<br />Severity: High<br />Versions: 1.0.4 and prior<br />Advisory Date: 2011-01-26<br />Fixed Date: 2011-01-19<br />Impact:<br />&nbsp;a) A remote attacker may access or view arbitrary files on the server.<br />&nbsp;b) A remote attacker may execute arbitrary PHP code as a result of SQL injection.<br /><br /><b>Description</b><br />JPCERT/CC has issued the following advisories:<br />&nbsp;a) <a href="http://jvn.jp/en/jp/JVN95385972/index.html" target="_blank">http://jvn.jp/en/jp/JVN95385972/index.html</a><br />&nbsp;b) <a href="http://jvn.jp/en/jp/JVN54092716/index.html" target="_blank">http://jvn.jp/en/jp/JVN54092716/index.html</a><br /><br /><b>Solution</b><br />Upgrade to MODx Revolution 1.0.5 available here:&nbsp; <a href="http://modxcms.com/download.html#ga" target="_blank">http://modxcms.com/download.html#ga</a><br />Read the <a href="http://modxcms.com/forums/index.php/topic,60045.0.html" target="_blank">Release Announcement</a> for Evolution 1.0.5.<br />]]></description>
    <dc:subject>Security Notices</dc:subject>
    <dc:date>2011-01-29T05:13:31+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,59421.msg338158.html#msg338158">
    <title><![CDATA[Critical PHP Bug Security Notice and Patch]]></title>
    <link>http://modxcms.com/forums/index.php/topic,59421.msg338158.html#msg338158</link>
    <description><![CDATA[Earlier this week, a PHP Security Notice was made due to a critical bug in PHP that could cause PHP to fail should a value of 2.2250738585072011e-308 be set to a PHP value.<br /><br />More information can be found here:<br /><ul><li><a href="http://bugs.php.net/bug.php?id=53632" target="_blank">http://bugs.php.net/bug.php?id=53632</a></li><li><a href="http://www.exploringbinary.com/php-hangs-on-numeric-value-2-2250738585072011e-308/" target="_blank">http://www.exploringbinary.com/php-hangs-on-numeric-value-2-2250738585072011e-308/</a></li></ul><br />This bug can affect MODx installations. MODx Revolution has been patched in GitHub for this. It is <b>highly</b> recommended that all MODx Revolution users patch their MODx installations with the fix made in this commit: <a href="https://github.com/modxcms/revolution/commit/3d8175c010374a3662fb86492fe7e808df0bae66" target="_blank">https://github.com/modxcms/revolution/commit/3d8175c010374a3662fb86492fe7e808df0bae66</a> (do not copy the entire modx.class.php file, just the affected lines)<br /><br />To patch for Revolution, simply paste the following lines into the file &quot;core/model/modx/modx.class.php&quot; after line 30 (after the comments):<br />[code]if (strstr(str_replace(&#39;.&#39;,&#39;&#39;,serialize($_REQUEST)), &#39;22250738585072011&#39;)) {<br />&nbsp;&nbsp;header(&#39;Status: 422 Unprocessable Entity&#39;); die();<br />}[/code...]]></description>
    <dc:subject>Security Notices</dc:subject>
    <dc:date>2011-01-07T00:43:30+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,58313.msg332802.html#msg332802">
    <title><![CDATA[Critical Security Upgrade Notice for FormIt, Quip and Login]]></title>
    <link>http://modxcms.com/forums/index.php/topic,58313.msg332802.html#msg332802</link>
    <description><![CDATA[We received a report of a potential vulnerability in <i>FormIt</i>, <i>Quip</i> and <i>Login</i> that could be used to expose system settings including database information. <br /><br />This has been been corrected and new versions have been posted. <b>Upgrading of FormIt, Login and Quip to the latest versions via Package Manager should be considered critical.</b><br /><br />This only affects MODX Revolution installations that have installed the Extras FormIt, Quip and Login.<br /><br />]]></description>
    <dc:subject>Security Notices</dc:subject>
    <dc:date>2010-12-09T23:17:16+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,55314.msg318284.html#msg318284">
    <title><![CDATA[phpThumb  Command-Injection Vulnerability]]></title>
    <link>http://modxcms.com/forums/index.php/topic,55314.msg318284.html#msg318284</link>
    <description><![CDATA[It has recently come to our attention that phpThumb (all versions) contains an unpatched vulnerability.<br /><div>Quote from: <a href="http://www.juniper.net/security/auto/vulnerabilities/vuln39605.html" target="_blank">http://www.juniper.net/security/auto/vulnerabilities/vuln39605.html</a></div><div>The application is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input to the &#39;fltr&#91;]&#39; parameter in the &#39;phpThumb.php&#39; script. <br /><br />Attackers can exploit this issue to execute arbitrary commands in the context of the webserver.<br /><br />Note that successful exploitation requires &#39;ImageMagick&#39; to be installed.<br /><br />phpThumb() 1.7.9 is affected; other versions may also be vulnerable.</div><br />If you are using phpThumb on any of your sites either as part of a plugin or standalone, you should use the following fix to secure your site: <br /><a href="http://modxcms.com/forums/index.php/topic,54874.msg316279.html#msg316279" target="_blank">http://modxcms.com/forums/index.php/topic,54874.msg316279.html#msg316279</a><br /><br />Note: This vulnerability does not affect the phpThumb that is included in the MODx Revolution distribution.<br />]]></description>
    <dc:subject>Security Notices</dc:subject>
    <dc:date>2010-10-06T01:01:07+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,55105.msg317273.html#msg317273">
    <title><![CDATA[MODx Revolution 2.0.3 Addresses Pair of Vulnerabilities]]></title>
    <link>http://modxcms.com/forums/index.php/topic,55105.msg317273.html#msg317273</link>
    <description><![CDATA[The MODx Revolution 2.0.3 release addresses a pair of <a href="http://modxcms.com/forums/index.php/topic,55062.0.html" target="_blank">reported security vulnerabilities</a> with MODx Revolution 2.0.2-pl and possibly earlier releases:<br /><br />Input passed via the &quot;modhash&quot; parameter to manager/index.php is not properly sanitized before being returned to the user and input passed via the &quot;class_key&quot; parameter to manager/controllers/default/resource/tvs.php is not properly verified before being used to include files.<br /><br /><b>We recommend that anyone running previous versions of MODx Revolution upgrade to 2.0.3.</b><br /><br />Download MODx Revolution 2.0.3-pl: <a href="http://modxcms.com/download/#pl" target="_blank">http://modxcms.com/download/#pl</a><br /><br />Details of other improvements introduced in the 2.0.3 release can be found here: <a href="http://modxcms.com/forums/index.php/topic,55104.0.html" target="_blank">http://modxcms.com/forums/index.php/topic,55104.0.html</a>]]></description>
    <dc:subject>Security Notices</dc:subject>
    <dc:date>2010-10-01T03:47:17+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,55062.msg317079.html#msg317079">
    <title><![CDATA[MODx Revolution Cross-Site Scripting and Local File Inclusion Vulnerabilities]]></title>
    <link>http://modxcms.com/forums/index.php/topic,55062.msg317079.html#msg317079</link>
    <description><![CDATA[<b>Status: Solved</b> (See: <a href="http://modxcms.com/forums/index.php/topic,55105.0.html" target="_blank">Notice on fix</a>)<br />Product: MODx Revolution<br />Risk: Moderate<br />Versions: 2.0.x<br />Vunerability type: Cross-Site Scripting and Local File Inclusion Vulnerabilities<br />Report Date: 2010-09-29<br />Fixed Date: 2010-09-29<br /><br />Description<br />Issue reported as <a href="http://secunia.com/advisories/41638" target="_blank">Secunia Advisory SA41638</a>. <br /><br />Input passed via the &quot;modahsh&quot; parameter to manager/index.php is not properly sanitized before being returned to the user and input passed via the &quot;class_key&quot; parameter to manager/controllers/default/resource/tvs.php is not properly verified before being used to include files.<br /><br /><br />Affected Releases<br />MODx Revolution 2.0.2-pl however it is possible previous releases contain the vulnerability.<br /><br />Solution<br />Upgrade to MODx Revolution 2.0.3 available here: &nbsp;<a href="http://modxcms.com/download.html#pl" target="_blank">http://modxcms.com/download.html#pl</a><br />Read the <a href="http://modxcms.com/forums/index.php/topic,55104.0.html" target="_blank">Release Announcement[/ur...</a>]]></description>
    <dc:subject>Security Notices</dc:subject>
    <dc:date>2010-09-30T04:50:16+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,50207.msg292386.html#msg292386">
    <title><![CDATA[MODx Evolution SQL Injection Vulnerability]]></title>
    <link>http://modxcms.com/forums/index.php/topic,50207.msg292386.html#msg292386</link>
    <description><![CDATA[<b>Product:</b> MODx Evolution<br /><b>Risk:</b> Moderate<br /><b>Versions:</b> 1.0.3 and all previous releases<br /><b>Vunerability type:</b> SQL Injection<br /><b>Report Date:</b> 2010-May-28<br /><b>Fixed Date:</b> 2010-May-28<br /><br /><b>Description</b><br />Issue reported as <a href="http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_modx_cms_and_application_framework.html" target="_blank">HTB22412</a>. Attacker could potentially compromise MODx Evolution via an unsanitized variable on the /manager/index.php. <br />&nbsp; &nbsp; <br />No actual destructive exploit has yet been created or proven. The proof of concept offered on the htbridge.ch site, and variants, can only cause a SQL error to be displayed.<br /><br /><b>Affected Releases</b><br />All MODx 0.9.x/Evolution releases prior to and including MODx Evolution 1.0.3 are affected.<br /><br /><b>Solution</b><br />Upgrade to MODx Evolution 1.0.4 or later: <a href="http://modxcms.com/download.html#ga" target="_blank">http://modxcms.com/download.html#ga</a>]]></description>
    <dc:subject>Security Notices</dc:subject>
    <dc:date>2010-06-08T06:59:22+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,47759.msg280304.html#msg280304">
    <title><![CDATA[Security updates in MODx Evolution 1.0.3. You really should upgrade.]]></title>
    <link>http://modxcms.com/forums/index.php/topic,47759.msg280304.html#msg280304</link>
    <description><![CDATA[The MODx Evolution 1.0.3 release addresses a number of reported security vulnerabilities with previous MODx Evolution 1.0.2 and earlier releases:<br /><br /><ul><li> XSS possibilities with the SearchHighlight plugin (used by AjaxSearch) as reported in JVN#19774883 and JVN#46669729</li><li> Unwanted information disclosure about the site structure in the TinyMCE plugin</li><li> SQL Injection via WebLogin</li></ul><br /><b>We strongly recommend that anyone running previous versions of MODx Evolution (including 0.9.x releases) consider Evolution 1.0.3 a mandatory upgrade.</b><br /><br />Ddownload MODx Evolution 1.0.3: <a href="http://modxcms.com/download/" target="_blank">http://modxcms.com/download/</a><br /><br />Details of other improvements introduced in the 1.0.3 release can be found here: <a href="http://modxcms.com/forums/index.php/topic,47756.0.html" target="_blank">http://modxcms.com/forums/index.php/topic,47756.0.html</a>]]></description>
    <dc:subject>Security Notices</dc:subject>
    <dc:date>2010-04-02T12:11:06+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,38992.msg235150.html#msg235150">
    <title><![CDATA[MODx CMS Japan &#26085;&#26412;&#20844;&#24335;&#12501;&#12457;&#12540;&#12521;&#12512; (Official Forums)]]></title>
    <link>http://modxcms.com/forums/index.php/topic,38992.msg235150.html#msg235150</link>
    <description><![CDATA[2009&#24180;9&#26376;&#12363;&#12425;&#12289;<b>MODx CMS Japan &#26085;&#26412;&#20844;&#24335;&#12501;&#12457;&#12540;&#12521;&#12512;</b>&#12364;&#12473;&#12479;&#12540;&#12488;&#12375;&#12414;&#12377;&#65281;<br />(MODx CMS Japan official forum starts in September 2009.)<br /><br />&#26085;&#26412;&#20844;&#24335;&#12501;&#12457;&#12540;&#12521;&#12512;&#12395;&#38306;&#12377;&#12427;&#20107;&#21069;&#12450;&#12490;&#12454;&#12531;&#12473;(Announce)<br /><a href="http://modxcms.com/forums/index.php/topic,38596.0.html" target="_blank">http://modxcms.com/forums/index.php/topic,38596.0.html</a><br /><br />===== MODx CMS Japan Official Forum =====<br /><br /><b><span>&#12488;&#12483;&#12503;&#12506;&#12540;&#12472;(Top Page)</span></b> <a href="http://modxcms-jp.com/bb/" target="_blank">http://modxcms-jp.com/bb/</a><br /><b><span>RSS&#12501;&#12451;&#12540;&#12489;(RSS Feed)</span></b> <a href="http://modxcms-jp.com/bb/rss.php?mode=posts" target="_blank">http://modxcms-jp.com/bb/rss.php?mode=posts</a><br /><br />===== Category / SubForum =====<br /><br /><b><span>&#12467;&#12511;&#12517;&#12491;&#12486;&#12451;(Community)</span></b>&#12288;<a href="http://modxcms-jp.com/bb/viewforum.php?f=18" target="_blank">http://modxcms-jp.com/bb/viewforum.php?f=18</a><br /><br /><ul><li>&#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#24773;&#22577;(Security)&#12288;<a href="http://modxcms-jp.com/bb/viewforum.php?f=33" target="_blank">http://modxcms-jp.com/bb/viewforum.php?f=33</a></li><li>&#12362;&#30693;&#12425;&#12379;(Information)&#12288;<a href="http://modxcms-jp.com/bb/viewforum.php?f=19" target="_blank">http://modxcms-jp.com/bb/viewforum.php?f=19</a></li><li>&#38609;&#35527;(Off-topic)&#12288;[url=http://modxcms...</li></ul>]]></description>
    <dc:subject>Japanese</dc:subject>
    <dc:date>2009-08-20T19:59:31+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,37961.msg229068.html#msg229068">
    <title><![CDATA[Security Fix for MODx Revolution 2.0-beta2 (and beta1)]]></title>
    <link>http://modxcms.com/forums/index.php/topic,37961.msg229068.html#msg229068</link>
    <description><![CDATA[There has been a reported security vulnerability for MODx Revolution 2.0 beta1 and beta2. <br /><br />We have committed a temporary fix until we hit the root of the issue, which is a problem with the modAccessibleObject and Context Policy loading.<br /><br />SVN users, to fix this vulnerability, please update to r5505.<br /><br />Non-SVN users, please make the changes as illustrated here:<br /><a href="http://svn.modxcms.com/crucible/changelog/modx/?cs=5501" target="_blank">http://svn.modxcms.com/crucible/changelog/modx/?cs=5501</a> <br /><br />and here:<br /><a href="http://svn.modxcms.com/crucible/changelog/modx/?cs=5505" target="_blank">http://svn.modxcms.com/crucible/changelog/modx/?cs=5505</a><br /><br />Again, MODx recommends that you not use any beta products on shared or public servers without acknowledging the risk of potential undiscovered vulnerabilities. If you do choose to use such products, MODx recommends using a restricted username and/or password that is limited only to the MODx install. This also applies to file and user permissions. <br /><br />We apologize for any inconvience this might have caused.]]></description>
    <dc:subject>Security Notices</dc:subject>
    <dc:date>2009-07-24T04:28:34+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
<item rdf:about="http://modxcms.com/forums/index.php/topic,30875.msg187190.html#msg187190">
    <title><![CDATA[Re: Reflect RFI Exploit]]></title>
    <link>http://modxcms.com/forums/index.php/topic,30875.msg187190.html#msg187190</link>
    <description><![CDATA[The permanent solution is in fact to simply rename the reference snippet with a .txt extension or to remove them completely. They were included as a reference, and they have been removed from the current download distribution on the site.]]></description>
    <dc:subject>Security Notices</dc:subject>
    <dc:date>2008-11-25T07:46:49+09:00</dc:date>
    <dc:creator></dc:creator>
</item>
</rdf:RDF>

