CVE-2008-6365
Ad Server Solutions Ad Management Software Java - SQL Injection via logon.jsp uname or pass Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-6365. PoCs published by R3d-D3V!L.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass via SQL injection in Ad Management Java's login page. It uses a simple SQLi payload to bypass authentication by manipulating the login query.
Description
SQL injection vulnerability in logon.jsp in Ad Server Solutions Ad Management Software Java allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password, related to the uname or pass parameters to logon.jsp or logon_processing.jsp. NOTE: some of these details are obtained from third party information.
Exploits (2)
This exploit demonstrates an authentication bypass via SQL injection in Ad Management Java's login page. It uses a simple SQLi payload to bypass authentication by manipulating the login query.
The provided text describes a SQL injection vulnerability in Multiple Ad Server Solutions products, specifically Ad Management Software and Affiliate Software. It includes example payloads for exploiting the vulnerability via username and password fields.