Exploit ADManager 1.1 - Content Manipulation

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
21424
Проверка EDB
  1. Пройдено
Автор
FROG
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
null
Дата публикации
2002-04-17
Код:
source: https://www.securityfocus.com/bid/4615/info

Admanager is banner advertisement management software. It is written in PHP and will run on most Unix and Linux variants, in addition to Microsoft Windows operating systems.

Access to the 'add.php3' script does not require authentication. It is possible for a remote attacker to manipulate URL parameters of this script and change banner advertisement content.

http://target/add.php3?url=http://www.url.com&adurl=http://URL/img.gif URL/
 
Источник
www.exploit-db.com

Похожие темы