Jobs Pro Component for Joomla! 'search_jobs.html' SQL Injection Vulnerability
BID:41403
Info
Jobs Pro Component for Joomla! 'search_jobs.html' SQL Injection Vulnerability
| Bugtraq ID: | 41403 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-4994 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2010 12:00AM |
| Updated: | Mar 19 2015 08:41AM |
| Credit: | kevin j |
| Vulnerable: |
Instant Php Jobs Pro 1.3.2 |
| Not Vulnerable: |
Instant Php Jobs Pro 1.3.3 |
Discussion
Jobs Pro Component for Joomla! 'search_jobs.html' SQL Injection Vulnerability
The Jobs Pro component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Jobs Pro 1.3.2 is vulnerable; other versions may also be affected.
The Jobs Pro component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Jobs Pro 1.3.2 is vulnerable; other versions may also be affected.
Solution / Fix
Jobs Pro Component for Joomla! 'search_jobs.html' SQL Injection Vulnerability
Solution:
An update is available; please see the references for more information.
Solution:
An update is available; please see the references for more information.