Jump to content
GIGN Forum

Psyhostats Fix


Recommended Posts

Ko man jadara, lai pataisit drosakus sos status pret hakeriem, luuk ko izlasiju, un tagad negribetos, lai kads loznajas pa manu DB

Details : SecurityAlert

Topic : PsychoStats v3.0.6b Multiple Cross-Site Scripting Vulnerabilities

SecurityAlert : 2750

CVE : CVE-2007-2914

SecurityRisk : Low

Remote Exploit : Yes

Local Exploit : No

Exploit Given : Yes

Credit : john martinelli

Date : 03.06.2007

Affected Software : PsychoStats v3.0.6b

Advisory Text :

PsychoStats v3.0.6b Multiple Cross-Site Scripting

Vulnerabilities

PsychoStats contains multiple cross-site scripting

vulnerabilities that may be exploited through the URI.

Vulnerable Files: awards.php, login.php, register.php,

weapons.php - other files may also be susceptible to this

vulnerability.

Vulnerability:

http://target.com/psychostats/weapons.php/...t;><scrip

t>alert(1)</script>

Vulnerable: PsychoStats v3.0.6b (other versions may also be

vulnerable)

Google d0rk: "Powered by PsychoStats v3.0.6b"

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
 Share

×
×
  • Create New...