PT-2005-4620 · Ad Center · Ad Center Adc2000 Ng Pro
Published
2005-11-29
·
Updated
2011-03-08
·
CVE-2005-3876
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AD Center ADC2000 NG Pro versions 1.2
Description
The issue concerns SQL injection vulnerabilities in the adcbrowres.php file. Remote attackers can execute arbitrary SQL commands by manipulating the
cat and lang parameters.Recommendations
For AD Center ADC2000 NG Pro version 1.2, as a temporary workaround, consider restricting access to the adcbrowres.php file until a patch is available. Avoid using the
cat and lang parameters in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ad Center Adc2000 Ng Pro