CVE-2008-3267

mojoJobs - SQL Injection via cat_a Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-3267. PoCs published by Mr.SQL.

AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in MojoJobs.cgi by brute-forcing the admin password character-by-character. It uses LWP::UserAgent to send crafted HTTP requests and checks for a specific string in the response to determine if the injected condition is true.

Description

SQL injection vulnerability in mojoJobs.cgi in MojoJobs allows remote attackers to execute arbitrary SQL commands via the cat_a parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Mr.SQL · perlwebappscgi
https://www.exploit-db.com/exploits/6110

This Perl script exploits a blind SQL injection vulnerability in MojoJobs.cgi by brute-forcing the admin password character-by-character. It uses LWP::UserAgent to send crafted HTTP requests and checks for a specific string in the response to determine if the injected condition is true.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: MojoJobs.cgi (version unspecified)
No auth needed
Prerequisites: Target URL with vulnerable MojoJobs.cgi endpoint · Valid cat_a parameter value
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/43933
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6110
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31164
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2158/references
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4029

Scores

EPSS 0.0208
EPSS Percentile 79.1%

Details

CWE
CWE-89
Status published
Products (1)
mojoscripts/mojojobs
Published Jul 24, 2008
Tracked Since Feb 18, 2026