CVE-2008-6366
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password, possibly related to the uname and pass parameters to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.35%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password, possibly related to the uname and pass parameters to logon_process.jsp. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 3.35% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- adserversolutions/affiliate software java
- Source
- cve@mitre.org
References
- http://packetstorm.linuxsecurity.com/0812-exploits/affiliatesj-sql.txtExploit
- http://secunia.com/advisories/33072Vendor Advisory
- http://www.securityfocus.com/bid/32791Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47280
- https://www.exploit-db.com/exploits/7423
- http://packetstorm.linuxsecurity.com/0812-exploits/affiliatesj-sql.txtExploit
- http://secunia.com/advisories/33072Vendor Advisory
- http://www.securityfocus.com/bid/32791Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47280
- https://www.exploit-db.com/exploits/7423
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.