vendor:
ladder.php
by:
Sora
9
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: ladder.php
Affected Version From: 2.6.1
Affected Version To: 2.6.1
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Vista Home Premium and Linux 2.6.28.1 (Backtrack 3)
N/A
Ulisse’s Scripts 2.6.1 ladder.php SQL Injection Vulnerability
Sora has advised that Ulisse's ladder.php file from Ulisse's Scripts 2.6.1 suffers a remote SQL injection vulnerability in the parameter 'gid'. The database inputs are not properly sanitized.
Mitigation:
Sanitize the unsanitized database inputs in the file ladder.php.