Ulisse's Scripts version 2.6.1 suffers from a remote SQL injection vulnerability in ladder.php.
3662f1abb30ab7a3dc33f968583b82391eeefb84830ffb52acf94002a3582c9d
# Exploit Title: Ulisse’s Scripts 2.6.1 ladder.php SQL Injection Vulnerability
# Date: January 6th, 2010
# Author: Sora
# Version: 2.6.1
# Tested on: Windows Vista Home Premium and Linux 2.6.28.1 (Backtrack 3)
——————————
> Ulisse’s Scripts 2.6.1 ladder.php SQL Injection Vulnerability
> Author: Sora
> Contact: vhr95zw [at] hotmail [dot] com
> Website: https://greyhathackers.wordpress.com/
> Google Dork: “In your dreams, script kiddies.”
# VULNERABILITY DESCRIPTION:
Type: SQL Injection
Level: 4/5 (CRITICAL)
Sora has advised that Ulisse’s ladder.php file from Ulisse’s Scripts 2.6.1
suffers a remote SQL injection vulnerability in the parameter ‘gid’. The database inputs
are not properly sanitized.
# VULNERABILITY SOLUTION:
Sanitize the unsanitized database inputs in the file ladder.php.
# Proof of Concept: https://www.site.com/ulisse/ladder.php?gid=1′