[] NeoSense

UTStats - Cross-Site Scripting / SQL Injection / Full Path Disclosure

Author: LuM Member
type: webapps
platform: php
port: 
date_added: 2010-06-12 
date_updated:  
verified: 1 
codes: CVE-2010-5009;CVE-2010-5007;OSVDB-76896;OSVDB-76894 
tags: 
aliases:  
screenshot_url:  
application_url: 

# Exploit Title: UTStats XSS, SQL Injection & Full path disclosure
# Date: 13-06-2010
# Author: LuM Member
# Software Link: http://www.unrealadmin.org/forums/showthread.php?t=29786
# Version: All recent versions.
# Tested on: Windows 7 x64
# CVE : none
# Code :
There are most likely some more bugs in it. I didn't check the code in
detail.
If you check google, you see there are quite some installs.

XSS:
pages/match_report.php?mid=

Sql Injection:
index.php?p=matchp&pid='

Full Path Disclosure:
pages/servers_info.php


Greetings to LuM.