Praetorian503 Posted February 17, 2013 Report Posted February 17, 2013 Scripts Genie Games Site script suffers from a remote SQL injection vulnerability.################################################################################## __ _ _ ____ / /___ _____ (_)_____________ ______(_)__ _____ / __ \_________ _ __ / / __ `/ __ \/ / ___/ ___/ __ `/ ___/ / _ \/ ___// / / / ___/ __ `// /_/ / /_/ / / / / (__ |__ ) /_/ / / / / __(__ )/ /_/ / / / /_/ / \____/\__,_/_/ /_/_/____/____/\__,_/_/ /_/\___/____(_)____/_/ \__, / /____/ ################################################################################## Games Site Script, MySQL Injection VulnerabilitiesSoftware Page: http://scriptsgenie.com/index.php?do=catalog&c=scripts&i=games_site_scriptProduct Page: http://www.hotscripts.com/listing/150-flash-game-script-comes-with-150-games/Script Demo: http://scriptsgenie.com/demo/GameScript150Games/Author(Pentester): 3spi0nOn Social: Twitter.Com/eyyamgudeerGreetz: Grayhats Inc. and Janissaries Platform.##################################################################################[~] MySQL Injection on Demo Site (/index.php?act=play&id=)>>> http://scriptsgenie.com/demo/GameScript150Games/index.php?act=play&id=122' (MySQLi Found)Source: PacketStorm Quote