Multiple Ad Server Solutions Products 'logon_processing.jsp' SQL Injection Vulnerabilities
BID:32782
Info
Multiple Ad Server Solutions Products 'logon_processing.jsp' SQL Injection Vulnerabilities
| Bugtraq ID: | 32782 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2008 12:00AM |
| Updated: | Dec 15 2008 06:41PM |
| Credit: | ((?3d D3v!L)) |
| Vulnerable: |
Ad Server Solutions Affiliate Software 4.0 Ad Server Solutions Ad Management Software 0 |
| Not Vulnerable: | |
Discussion
Multiple Ad Server Solutions Products 'logon_processing.jsp' SQL Injection Vulnerabilities
Multiple Ad Server Solutions products are prone to SQL-injection vulnerabilities because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following Ad Server Solutions products are vulnerable:
Ad Management Software
Affiliate Software
Multiple Ad Server Solutions products are prone to SQL-injection vulnerabilities because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following Ad Server Solutions products are vulnerable:
Ad Management Software
Affiliate Software
Exploit / POC
Multiple Ad Server Solutions Products 'logon_processing.jsp' SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example data is available:
username: r0' or ' 1=1--
password: r0' or ' 1=1--
Attackers can use a browser to exploit these issues.
The following example data is available:
username: r0' or ' 1=1--
password: r0' or ' 1=1--
Solution / Fix
Multiple Ad Server Solutions Products 'logon_processing.jsp' SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple Ad Server Solutions Products 'logon_processing.jsp' SQL Injection Vulnerabilities
References:
References:
- Vendor Homepage (Ad Server Solutions)