AdLogin.pm in AdCycle 1.15 and earlier allows remote attackers to bypass authentication and gain privileges by injecting SQL code in the $password argument.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2001-07/0249.html | Exploit Patch Vendor Advisory |
http://www.securityfocus.com/bid/3032 | Exploit Patch Vendor Advisory |
http://www.adcycle.com/cgi-bin/download.cgi?type=UNIX&version=1.17 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6837 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2001-07-12 21:00
Updated : 2017-10-09 18:29
NVD link : CVE-2001-1053
Mitre link : CVE-2001-1053
JSON object : View
CWE
Products Affected
adcycle
- adcycle