Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2020-8645
Disclosure Date: February 07, 2020 (last updated February 21, 2025)
An issue was discovered in Simplejobscript.com SJS through 1.66. There is an unauthenticated SQL injection via the job applications search function. The vulnerable parameter is job_id. The function is getJobApplicationsByJobId(). The file is _lib/class.JobApplication.php.
0
Attacker Value
Unknown
CVE-2020-8440
Disclosure Date: January 31, 2020 (last updated February 21, 2025)
controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a resume.
0
Attacker Value
Unknown
CVE-2020-7229
Disclosure Date: January 21, 2020 (last updated February 21, 2025)
An issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search engine. The parameter is landing_location. The function is countSearchedJobs(). The file is _lib/class.Job.php.
0
Attacker Value
Unknown
CVE-2010-0341
Disclosure Date: January 15, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the BB Simple Jobs (bb_simplejobs) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-4601
Disclosure Date: January 12, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in basic_search_result.php in Zeeways ZeeJobsite 3x allows remote attackers to inject arbitrary web script or HTML via the title parameter.
0
Attacker Value
Unknown
CVE-2008-6913
Disclosure Date: August 07, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile edit action, then accessing the file via a direct request to jobseekers/logos/.
0
Attacker Value
Unknown
CVE-2008-3706
Disclosure Date: August 19, 2008 (last updated October 04, 2023)
SQL injection vulnerability in bannerclick.php in ZEEJOBSITE 2.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.
0
Attacker Value
Unknown
CVE-2006-6805
Disclosure Date: December 28, 2006 (last updated October 04, 2023)
SQL injection vulnerability in newsdetail.asp in Enthrallweb eJobs allows remote attackers to execute arbitrary SQL commands via the ID parameter.
0