vendor:
Module Jobs
by:
ajann
7.5
CVSS
HIGH
Remote Blind SQL Injection
CWE
Product Name: Module Jobs
Affected Version From: 2
Affected Version To: 2.4
Patch Exists: No
Related CWE:
CPE:
Platforms Tested:
XOOPS Module Jobs <= 2.4 (cid) Remote BLIND SQL Injection Exploit
This exploit allows an attacker to perform a blind SQL injection attack on the XOOPS Module Jobs <= 2.4. By manipulating the 'cid' parameter in the index.php file, an attacker can retrieve sensitive information from the database, including the usernames and passwords of the admin users.
Mitigation:
Update to a patched version of the XOOPS Module Jobs or apply appropriate security measures to prevent SQL injection attacks.