Elite Gaming Ladders 3.0 – SQL Injection

  • 作者: Sora
    日期: 2010-01-03
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/10978/
  • # Exploit Title: Elite Gaming Ladders v3.0 SQL Injection Exploit
    # Date: January 3rd, 2010
    # Author: Sora
    # Version: 3.0
    # Tested on: Windows and Linux
    
    ----------------------------------------
    > Elite Gaming Ladders v3.0 SQL Injection Exploit
    > Contact: vhr95zw [at] hotmail [dot] com
    > Website: http://greyhathackers.wordpress.com/
    > Google Dork: "Fuck all script kiddies."
    
    # Vulnerability Description:
    Elite Gaming Ladders v3.0 suffers a remote SQL injection exploit (stats.php) in the "account" parameter.
    
    # Solution:
    Sanitize the database inputs or block the bad words. (UNION SELECT, UNION SELECT ALL, /*, --)
    
    # Proof of Concept:
    http://www.site.com/stats.php?account=627'