20010219 Adcycle 0.78b Authenticationmailing list
http://www.securityfocus.com/archive/1/163942 CVE-2001-0425
Adcycle 0.77/0.78 - AdLibrary.pm Session Access
Record summary
CVE-2001-0425 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
AdLibrary.pm in AdCycle 0.78b allows remote attackers to gain privileges to AdCycle via a malformed Agent: header in the HTTP request, which is inserted into a resulting SQL query that is used to verify login information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAdcycle 0.77/0.78 - AdLibrary.pm Session AccessExploitDB exploitby Neil KNot analyzed1 file
References
32393vdb entry
http://www.securityfocus.com/bid/2393 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0425