MobFox mAdserve Multiple SQL Injection Vulnerabilities
BID:66661
Info
MobFox mAdserve Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 66661 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2654 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 04 2014 12:00AM |
| Updated: | Apr 17 2014 02:50AM |
| Credit: | High-Tech Bridge Security Research Lab |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
MobFox mAdserve Multiple SQL Injection Vulnerabilities
mAdserve is prone to multiple SQL-injection vulnerabilities because they fail to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
mAdserve 2.0 and prior versions are vulnerable.
mAdserve is prone to multiple SQL-injection vulnerabilities because they fail to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
mAdserve 2.0 and prior versions are vulnerable.
Exploit / POC
MobFox mAdserve Multiple SQL Injection Vulnerabilities
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
MobFox mAdserve Multiple SQL Injection Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
MobFox mAdserve Multiple SQL Injection Vulnerabilities
References:
References: