| HIO-2008-0713 JOBBEX JobSite SQLi & XSS |
|
|
|
|
Jobbex JobSite contains flaws that allow remote SQL injection attacks and cross site scripting. SQLi occurs where the "jobstateid" and "jobcountryid" don't properly sanitize input submitted to the search_result.cfm script. Additionally, if a failed query is performed, the program will disclose the softwares installation path. Information disclosure occurs where the "grp" and "jobspage" don't properly sanitize input submitted to the search_result.cfm script, resulting in disclosure of resource locations. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks. Cross-site scripting occurs where the "opt" variable doesn't properly sanitize input submitted to the search_result.cfm script. References: BID: 30302 SA: 31089 Vendor Solution: Patch
|
| < Prev | Next > |
|---|







