Description
|
|
Multiple vulnerabilities were identified in phpAdsNew and phpPgAds, which could be exploited by malicious users to perform SQL injection attacks or disclose sensitive information.
The first flaw is due to an input validation error in the "logout.php" script when processing a specially crafted "sessionID" cookie parameter, which may be exploited by malicious users to conduct SQL injection attacks.
The second issue is due to input validation errors in various scripts when called directly via the browser, which may be exploited by attackers to determine the installation path.
The third flaw is due to input validation errors in various scripts when handling malformed variables, which may be exploited by malicious users to conduct HTTP response splitting attacks.
|