Admanager Content Manipulation Vulnerability
BID:4615
Info
Admanager Content Manipulation Vulnerability
| Bugtraq ID: | 4615 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 17 2002 12:00AM |
| Updated: | Apr 17 2002 12:00AM |
| Credit: | Discovery of this issue is credited to frog frog <[email protected]>. |
| Vulnerable: |
Admanager Admanager 1.1 |
| Not Vulnerable: | |
Discussion
Admanager Content Manipulation Vulnerability
Admanager is banner advertisement management software. It is written in PHP and will run on most Unix and Linux variants, in addition to Microsoft Windows operating systems.
Access to the 'add.php3' script does not require authentication. It is possible for a remote attacker to manipulate URL parameters of this script and change banner advertisement content.
Admanager is banner advertisement management software. It is written in PHP and will run on most Unix and Linux variants, in addition to Microsoft Windows operating systems.
Access to the 'add.php3' script does not require authentication. It is possible for a remote attacker to manipulate URL parameters of this script and change banner advertisement content.
Exploit / POC
Admanager Content Manipulation Vulnerability
This issue may be exploited with a web browser. The following example was submitted:
http://target/add.php3?url=http://www.url.com&adurl=http://URL/img.gif URL/
This issue may be exploited with a web browser. The following example was submitted:
http://target/add.php3?url=http://www.url.com&adurl=http://URL/img.gif URL/
Solution / Fix
Admanager Content Manipulation Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Admanager Content Manipulation Vulnerability
References:
References:
- Admanager Homepage (bc.scrypty.com)
- Security holes in 11 products... (frog frog
)