7.5
CVSSv2

CVE-2011-5218

Published: 25/10/2012 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in DotA OpenStats 1.3.9 and previous versions allows remote malicious users to execute arbitrary SQL commands via the id parameter to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

neubivljiv dota openstats 1.3.8

neubivljiv dota openstats 1.3.7

neubivljiv dota openstats 1.3.0

neubivljiv dota openstats 1.2.9

neubivljiv dota openstats 1.2.1

neubivljiv dota openstats 1.1.9

neubivljiv dota openstats 1.3.6

neubivljiv dota openstats 1.3.5

neubivljiv dota openstats 1.2.8

neubivljiv dota openstats 1.2.7

neubivljiv dota openstats 1.1

neubivljiv dota openstats 1.3.4

neubivljiv dota openstats 1.3.3

neubivljiv dota openstats 1.2.6

neubivljiv dota openstats 1.2.5

neubivljiv dota openstats 1.2.4

neubivljiv dota openstats

neubivljiv dota openstats 1.3.2

neubivljiv dota openstats 1.3.1

neubivljiv dota openstats 1.2.3

neubivljiv dota openstats 1.2.2

Exploits

============= # Exploit Title: DotA OpenStats SQL Injection Vulnerability # Google Dork: "© 2011 Powered by DotA OpenStats" # Date: 19/12/2011 # Author: HvM17 # Version: 139 and below # Tested on: WinXP ============= # VenDor : openstatsizrs/ # Download script: sourceforgenet/projects/dotaopenstats/ ============= [~] Exploit ...