Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2020-8645

Disclosure Date: February 07, 2020 (last updated February 21, 2025)
An issue was discovered in Simplejobscript.com SJS through 1.66. There is an unauthenticated SQL injection via the job applications search function. The vulnerable parameter is job_id. The function is getJobApplicationsByJobId(). The file is _lib/class.JobApplication.php.
Attacker Value
Unknown

CVE-2020-8440

Disclosure Date: January 31, 2020 (last updated February 21, 2025)
controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a resume.
Attacker Value
Unknown

CVE-2020-7229

Disclosure Date: January 21, 2020 (last updated February 21, 2025)
An issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search engine. The parameter is landing_location. The function is countSearchedJobs(). The file is _lib/class.Job.php.