Topic : | Left 4 Dead Stats 1.1 SQL Injection Vulnerability
|
SecurityAlert : 7137
CVE : CVE-2010-0980
CWE : CWE-89
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : Sora
Published : 20.03.2010
Affected Software : | mitchell_sleeper:l4d_stats:1.1 |
 Advisory Content : ----------------------------------
> Left 4 Dead Stats SQL Injection Vulnerability
> Author: Sora
> Contact: vhr95zw [at] hotmail [dot] com
> Website: http://greyhathackers.wordpress.com/
> Google Dork: "In your dreams, script kiddies."
# VULNERABILITY DESCRIPTION:
Left 4 Dead Stats suffers from a remote SQL injection vulnerability in
player.php.
# VULNERABILITY SOLUTION:
The owner of the website can sanitize the database inputs.
# Proof of Concept: http://www.site.com/l4dstats/player.php?steamid='
# Greetz: Bw0mp, Popc0rn, Xermes, T3eS, Timeb0mb, [H]aruhiSuzumiya,
Revelation, and Max Mafiotu.
References :
http://xforce.iss.net/xforce/xfdb/55299
http://www.exploit-db.com/exploits/10930
http://secunia.com/advisories/38008
http://packetstormsecurity.org/1001-exploits/left4deadstats-sql.txt
http://osvdb.org/61472
http://greyhathackers.wordpress.com/2010/01/02/left-4-dead-stats-1-1-sql-injection-vulnerability/
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|