AdCycle 1.17 and earlier allow remote attackers to modify SQL queries, which are not properly sanitized before being passed to the MySQL database.
| Software | From | Fixed in |
|---|---|---|
| adcycle / adcycle | 1.14 | 1.14.x |
| adcycle / adcycle | 1.12 | 1.12.x |
| adcycle / adcycle | 1.15 | 1.15.x |
| adcycle / adcycle | 1.13 | 1.13.x |
| adcycle / adcycle | 1.17 | 1.17.x |
| adcycle / adcycle | 1.16 | 1.16.x |