vendor:
Job Listing
by:
ajann
7.5
CVSS
HIGH
Remote Contents Change Vulnerability
284
CWE
Product Name: Job Listing
Affected Version From: 1.1
Affected Version To: 1.1
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
DMXReady Job Listing <= 1.1 Remote Contents Change Vulnerability
A vulnerability exists in DMXReady Job Listing version 1.1 which allows an attacker to remotely change the contents of the website. The vulnerability is due to the lack of proper authentication and authorization checks in the 'inc_joblistingmanager.asp' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable script. This can result in the attacker gaining access to the website and changing the contents of the website.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to upgrade to the latest version of DMXReady Job Listing.