VYPR

Neorecruit

by Joomla

CVEs (3)

  • CVE-2018-6370CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under the all-offers/ URI.

  • CVE-2010-4995Nov 1, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the NeoRecruit (com_neorecruit) component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in an offer_view action to index.php, a different vector than CVE-2007-4506.

  • CVE-2007-4506Aug 23, 2007
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in index.php in the NeoRecruit component (com_neorecruit) 1.4 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an offer_view action.