Description

Remote SQL injection vulnerabilities exist in Softbiz Freelancers Script version 1 through search_form.php and other scripts. Multiple parameters are not properly sanitized before database queries.

Impact

Attackers can extract all data from the database including freelancer profiles, financial transaction data, employer information, and administrative credentials. This could lead to significant financial and privacy damage.

Solution

Apply parameterized queries to all user inputs. Contact Softbiz for a security patch.

References