CVE-2010-1604
Multiple SQL injection vulnerabilities in admin_login.php in NCT Jobs Portal Script allow remote attackers to execute arbitrary SQL commands via the (1) user parameter (aka login field) and (2) passwd parameter (aka password field).
Does this matter?
Lower severity and a low EPSS score (0.91%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple SQL injection vulnerabilities in admin_login.php in NCT Jobs Portal Script allow remote attackers to execute arbitrary SQL commands via the (1) user parameter (aka login field) and (2) passwd parameter (aka password field). NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.91% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- ncrypted/nct jobs portal script
- Source
- cve@mitre.org
References
- http://packetstormsecurity.org/1004-exploits/nctjobsportal-sqlxss.txtExploit
- http://secunia.com/advisories/39601Vendor Advisory
- http://www.exploit-db.com/exploits/12370Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58080
- http://packetstormsecurity.org/1004-exploits/nctjobsportal-sqlxss.txtExploit
- http://secunia.com/advisories/39601Vendor Advisory
- http://www.exploit-db.com/exploits/12370Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58080
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.