AdLogin.pm in AdCycle 1.15 and earlier allows remote attackers to bypass authentication and gain privileges by injecting SQL code in the $password argument.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Adcycle | Adcycle | 0.77 (including) | 0.77 (including) |
Adcycle | Adcycle | 0.77b (including) | 0.77b (including) |
Adcycle | Adcycle | 0.78b (including) | 0.78b (including) |
Adcycle | Adcycle | 1.0 (including) | 1.0 (including) |
Adcycle | Adcycle | 1.12 (including) | 1.12 (including) |
Adcycle | Adcycle | 1.13 (including) | 1.13 (including) |
Adcycle | Adcycle | 1.14 (including) | 1.14 (including) |
Adcycle | Adcycle | 1.15 (including) | 1.15 (including) |