CVE-2010-1606
NCT Jobs Portal Script - Cross-Site Scripting via Search Keywords Tags or Desired City Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1606. PoCs published by Sid3^effects.
AI-analyzed exploit summary This writeup describes an authentication bypass via SQL injection and a reflected XSS vulnerability in NCT Jobs Portal Script. The auth bypass uses a classic SQLi payload, while the XSS is triggered via a malformed search query parameter.
Description
Multiple cross-site scripting (XSS) vulnerabilities in NCT Jobs Portal Script allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) Keywords, (3) Tags, or (4) Desired City field.
Exploits (1)
This writeup describes an authentication bypass via SQL injection and a reflected XSS vulnerability in NCT Jobs Portal Script. The auth bypass uses a classic SQLi payload, while the XSS is triggered via a malformed search query parameter.