CVE-2008-6366 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 3.4% (pctl 88)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password, possibly related to the uname and pass parameters to logon_process.jsp. NOTE: some of these details are obtained from third party information.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 3.35% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-03-02 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| adserversolutions | affiliate software java |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Multiple Ad Server Solutions Products - 'logon_processing.jsp' SQL Injection | 2008-12-11 |
| exploit-db | Affiliate Software Java 4.0 - Authentication Bypass | 2008-12-11 |
References
- http://packetstorm.linuxsecurity.com/0812-exploits/affiliatesj-sql.txt
- http://secunia.com/advisories/33072
- http://www.securityfocus.com/bid/32791
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47280
- https://www.exploit-db.com/exploits/7423
- http://packetstorm.linuxsecurity.com/0812-exploits/affiliatesj-sql.txt
- http://secunia.com/advisories/33072
- http://www.securityfocus.com/bid/32791
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47280
- https://www.exploit-db.com/exploits/7423
→ the Explorer · watch your stack · NVD