header-logo
Suggest Exploit
vendor:
Cory Jobs Search
by:
SecurityFocus
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Cory Jobs Search
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: N/A
Related CWE: N/A
CPE: a:cory_jobs_search:cory_jobs_search:1.0
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013

Cory Jobs Search SQL Injection Vulnerability

Cory Jobs Search is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Mitigation:

Input validation should be used to ensure that untrusted data is not used to construct SQL statements that are executed by the application.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/65969/info

Cory Jobs Search is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input.

Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Cory Jobs Search 1.0 is vulnerable; other versions may also be affected. 

http://www.example.com/coryapps/jobsearch/admincp/city.php?cid=[MySQL Injection]