CVE-2007-2370

John Mordo Jobs <2.4 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a jobsview action. NOTE: the module name was originally reported as Job Listings.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ajann · perlwebappsphp
https://www.exploit-db.com/exploits/3672

Scores

EPSS 0.0059
EPSS Percentile 69.4%

Details

Status published
Products (1)
xoops/john_mordo_jobs_module < 2.4
Published Apr 30, 2007
Tracked Since Feb 18, 2026