<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5513033439123909785</id><updated>2012-02-15T22:35:18.684-08:00</updated><category term='Exploit'/><title type='text'>vendeta</title><subtitle type='html'>sebuah kejahatan tanpa "sebab", Ketika Hidup sudah Mengembara,, hanya ada satu Keyakinan yang Terdalam. Kesetiaan Menemaniku dalam Nyata. terlelap dalam melafalkan nama. .Allah Hu Akbar.....!!</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://vevendeta.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5513033439123909785/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://vevendeta.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>vendeta</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5513033439123909785.post-6353936752186502430</id><published>2010-01-22T01:00:00.000-08:00</published><updated>2010-01-22T01:02:58.303-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Exploit'/><title type='text'>joomla component com_jinc (newsid) Blind SQL Injection Vulnerability</title><content type='html'>---------------------------------------------------------------------------------&lt;br /&gt;joomla component com_jinc (newsid) Blind SQL Injection Vulnerability&lt;br /&gt;---------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Author          : Chip D3 Bi0s&lt;br /&gt;Group           : LatiHackTeam&lt;br /&gt;Email           : chipdebios[alt+64]gmail.com&lt;br /&gt;Date            : 21 September 2009&lt;br /&gt;Critical Lvl    : Moderate&lt;br /&gt;Impact         : Exposure of sensitive information&lt;br /&gt;Where         : From Remote&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;Affected software description:&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;&lt;br /&gt;Application     : JINC (Joomla! Integrated Newsletters Component)&lt;br /&gt;version         : 0.2&lt;br /&gt;Developer       : lhacky&lt;br /&gt;License         : GPL            type  : Non-Commercial&lt;br /&gt;Date Added      : 2 September 2009&lt;br /&gt;Demo            : http://www.lhacky.org/jextensions/index.php?option=com_content&amp;view=article&amp;id=18:how-to-use&amp;catid=12:jinc-documentation&amp;Itemid=28&lt;br /&gt;&lt;br /&gt;Download        : http://www.lhacky.org/jextensions/index.php?option=com_content&amp;view=article&amp;id=3&amp;Itemid=15&lt;br /&gt;&lt;br /&gt;Description     :&lt;br /&gt;&lt;br /&gt;JINC (Joomla! Integrated Newsletters Component) is a easy-to-use and administer newsletter component for Joomla!.&lt;br /&gt;Using JINC your website users can auto-subscribe and unsubscribe to newsletters you defined.&lt;br /&gt;&lt;br /&gt;JINC includes classical newsletter functionalities&lt;br /&gt;&lt;br /&gt;* Newsletter, messages and subscription management.&lt;br /&gt;* TAG substitution inside the messages body.&lt;br /&gt;* User auto-registration with welcome message at subscription time.&lt;br /&gt;* Newsletter Disclaimer.&lt;br /&gt;* HTML and Text Plain messages.&lt;br /&gt;* Massive or personalized messages.&lt;br /&gt;* Reports on message sending.&lt;br /&gt;* Subscription creating user "on the fly".&lt;br /&gt;* Message preview to message creator before sending to the newsletter subscribers&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I.Blind SQL injection (newsid) Poc/Exploit:&lt;br /&gt;~~~~~~~~~&lt;br /&gt;http://127.0.0.1/[path]/index.php?option=com_jinc&amp;view=messages&amp;newsid=1[blind]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To make, you must be registered&lt;br /&gt;&lt;br /&gt;+++++++++++++++++++++++++++++++++++++++&lt;br /&gt;[!] Produced in South America&lt;br /&gt;+++++++++++++++++++++++++++++++++++++++&lt;br /&gt;&lt;br /&gt;sumber milw0rm.com [2009-09-21]&lt;br /&gt;    &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5513033439123909785-6353936752186502430?l=vevendeta.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://vevendeta.blogspot.com/feeds/6353936752186502430/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://vevendeta.blogspot.com/2010/01/joomla-component-comjinc-newsid-blind.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5513033439123909785/posts/default/6353936752186502430'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5513033439123909785/posts/default/6353936752186502430'/><link rel='alternate' type='text/html' href='http://vevendeta.blogspot.com/2010/01/joomla-component-comjinc-newsid-blind.html' title='joomla component com_jinc (newsid) Blind SQL Injection Vulnerability'/><author><name>vendeta</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
