WHID 2008-49: ValueClick weak decryption and vulnerability to SQL injection

Updated: 
13 January 2009
Attack Information
WHID ID: 
2008-49
Date Occured: 
17 Mar 2008
Attack Method: 
Attack Method: 
Outcome Information
Outcome: 
Target Information
Attacked Entity Field: 
Marketing
Attacked Entity Geography: 
USA

As a side story to ValueClick indictment of deceptive marketing by the FTC, the FTC investigation also found SQL injection vulnerabilities and lack of sufficient encryption of sensitive customer information. These findings contributed to the $2.9 million fine the FTC levied on ValueClick as well as to the company being dumped from managing eBay's affiliate program.