Banner Exchange Software Java 'logon_license.jsp' Multiple SQL Injection Vulnerabilities
BID:32781
Info
Banner Exchange Software Java 'logon_license.jsp' Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 32781 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2008 12:00AM |
| Updated: | Dec 15 2008 06:31PM |
| Credit: | R3d-D3v!L |
| Vulnerable: |
Ad Server Solutions Banner Exchange Solution Java 0 |
| Not Vulnerable: | |
Discussion
Banner Exchange Software Java 'logon_license.jsp' Multiple SQL Injection Vulnerabilities
Banner Exchange Software Java is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Banner Exchange Software Java is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
Banner Exchange Software Java 'logon_license.jsp' Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example data is available:
Username: r0' or ' 1=1--
Password: r0' or ' 1=1--
Attackers can use a browser to exploit these issues.
The following example data is available:
Username: r0' or ' 1=1--
Password: r0' or ' 1=1--
Solution / Fix
Banner Exchange Software Java 'logon_license.jsp' Multiple SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Banner Exchange Software Java 'logon_license.jsp' Multiple SQL Injection Vulnerabilities
References:
References:
- Vendor Homepage (Ad Server Solutions)