header-logo
Suggest Exploit
vendor:
Jobs Portal
by:
Unknown
7.5
CVSS
HIGH
HTML Injection, SQL Injection
79, 89
CWE
Product Name: Jobs Portal
Affected Version From: 3
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2012-4255, CVE-2012-4256
CPE: a:netartmedia:jobs_portal:3.0
Metasploit:
Other Scripts:
Platforms Tested:
2012

NetArt Media Jobs Portal Multiple HTML and SQL Injection Vulnerabilities

NetArt Media Jobs Portal is prone to multiple HTML-injection vulnerabilities and an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input data. Exploiting these issues may allow an attacker to compromise the application, access or modify data, exploit vulnerabilities in the underlying database, execute HTML and script code in the context of the affected site, steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.

Mitigation:

To mitigate these vulnerabilities, it is recommended to implement proper input validation and sanitization techniques in the affected application. Input data should be properly validated and sanitized before being used in SQL queries or rendered in HTML output.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/54026/info

NetArt Media Jobs Portal is prone to multiple HTML-injection vulnerabilities and an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input data.

Exploiting these issues may allow an attacker to compromise the application, access or modify data, exploit vulnerabilities in the underlying database, execute HTML and script code in the context of the affected site, steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.

NetArt Media Jobs Portal 3.0 is vulnerable; other versions may also be affected. 

http://www.example.com/EMPLOYERS/index.php?category=application_management&folder=my&page=details&posting_id=113&apply_id=68+order+%20by+1--%20[SQL INJECTION]--