PT-2005-4620 · Ad Center · Ad Center Adc2000 Ng Pro

Published

2005-11-29

·

Updated

2011-03-08

·

CVE-2005-3876

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AD Center ADC2000 NG Pro versions 1.2
Description The issue concerns SQL injection vulnerabilities in the adcbrowres.php file. Remote attackers can execute arbitrary SQL commands by manipulating the cat and lang parameters.
Recommendations For AD Center ADC2000 NG Pro version 1.2, as a temporary workaround, consider restricting access to the adcbrowres.php file until a patch is available. Avoid using the cat and lang parameters in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3876

Affected Products

Ad Center Adc2000 Ng Pro