Home page logo

bugtraq logo Bugtraq mailing list archives

SQL Injection Vulnerability In IBProArcade
From: mike bailey <mike () ub3r net>
Date: 31 Dec 2004 13:19:01 -0000

A flaw exists in the high scores module of IbProArcade which allows malicious SQL Code to be executed on the database 
the board & arcade use.

Demo: http://www.ibproarcade.com/index.php?act=Arcade&do=stats&gameid=104FOO

Fix this vuln by following the following directions...

open your sources/Arcade.php file

Find this code bit:

[code]       //----------------------------------------
       // Show_Stats
       // This shows the leaderboard

       function show_stats() {

               global $ibforums, $DB, $std;[/code]

Directly under that, add..

               $std->Error( array( 'LEVEL' => 1, 'MSG' => 'dont_try_it') );

then open up your lang/en/lang_Arcade.php file scroll down to the bottom where you will find

[code] );


right above that, add this:

dont_try_it             => "I don't think so annie."[/code]

And you're set.

  By Date           By Thread  

Current thread:
  • SQL Injection Vulnerability In IBProArcade mike bailey (Dec 31)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]