Security Advisory

CVE-2008-6364

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-03-02 16:00:00
Last updated 2024-08-07 11:27:35
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

SQL injection vulnerability in logon_process.jsp in Ad Server Solutions Banner Exchange Solution Java allows remote attackers to execute arbitrary SQL commands via the (1) username (uname parameter) and (2) password (pass parameter). NOTE: some of these details are obtained from third party information.