CVE-2010-1604 describes multiple SQL injection vulnerabilities in the admin_login.php script of NCT Jobs Portal Script. Remote attackers can exploit these flaws by injecting arbitrary SQL commands into the 'user' (login) and 'passwd' (password) parameters. This vulnerability carries a CVSS score of 6.8, indicating a medium severity risk with potential for partial confidentiality, integrity, and availability impacts, requiring medium attack complexity. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an ExploitDB entry details an authentication bypass, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:ncrypted:nct_jobs_portal_script:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.