AdCycle Remote SQL Query Modification Vulnerability
BID:3741
Info
AdCycle Remote SQL Query Modification Vulnerability
| Bugtraq ID: | 3741 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1226 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 25 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | This vulnerability was posted to the BugTraq mailing list in a GOBBLES advisory on December 25th, 2001. |
| Vulnerable: |
Adcycle.com Adcycle 1.17 Adcycle.com Adcycle 1.16 Adcycle.com Adcycle 1.15 Adcycle.com Adcycle 1.14 Adcycle.com Adcycle 1.13 Adcycle.com Adcycle 1.12 |
| Not Vulnerable: | |
Discussion
AdCycle Remote SQL Query Modification Vulnerability
AdCycle is a set of shareware ad management scripts written in Perl and back-ended by MySQL.
Many instances exist in the AdCycle scripts which may allow a remote attacker to modify the logic of an existing SQL query and manipulate the MySQL database that the software is back-ended by.
AdCycle is a set of shareware ad management scripts written in Perl and back-ended by MySQL.
Many instances exist in the AdCycle scripts which may allow a remote attacker to modify the logic of an existing SQL query and manipulate the MySQL database that the software is back-ended by.
Exploit / POC
AdCycle Remote SQL Query Modification Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
AdCycle Remote SQL Query Modification Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.