CVE-2008-6366
Ad Server Solutions Affiliate Software Java 4.0 - SQL Injection via Logon.jsp Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-6366. PoCs published by 3d D3v!L, R3d-D3V!L.
AI-analyzed exploit summary The exploit demonstrates SQL injection in Ad Server Solutions products by providing crafted username and password inputs that bypass authentication. It leverages improper sanitization of user-supplied data in SQL queries.
Description
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password, possibly related to the uname and pass parameters to logon_process.jsp. NOTE: some of these details are obtained from third party information.
Exploits (2)
The exploit demonstrates SQL injection in Ad Server Solutions products by providing crafted username and password inputs that bypass authentication. It leverages improper sanitization of user-supplied data in SQL queries.
This exploit demonstrates an authentication bypass via SQL injection in Affiliate Software Java 4.0. It provides credentials to bypass login by injecting SQL into the username and password fields.