vendor:
Spielothek
by:
Salvatore Fresta aka Drosophila
7,5
CVSS
HIGH
Multiple Blind SQL Injection
89
CWE
Product Name: Spielothek
Affected Version From: 1.6.9
Affected Version To: 1.6.9
Patch Exists: NO
Related CWE: N/A
CPE: a:spielban.de:spielothek:1.6.9
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Spielothek 1.6.9 Joomla Component Multiple Blind SQL Injection
Many parameters in various files such as battle.php, scores.php etc. are not properly sanitised before being used in SQL queries. Because of the number of flaws, it is not possible to report the entire vulnerable code.
Mitigation:
No fix.