vendor:
Top 100
by:
t0pP8uZz & xprog
7.5
CVSS
HIGH
Arbitrary Delete Stats
20
CWE
Product Name: Top 100
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Prozilla Top 100 1.2 Arbitrary Delete Stats Vulnerability
Prozilla Top 100 1.2 is vulnerable due to very bad validating on there $_GET urls. This allows the remote attacker to delete the stats of a user of choice. Therefor pushing which ever site they want to the top of the list.
Mitigation:
Validate user input and restrict access to delete.php page.