Praetorian503 Posted February 17, 2013 Report Posted February 17, 2013 Scripts Genie Top Sites script suffers from a remote SQL injection vulnerability.################################################################################## __ _ _ ____ / /___ _____ (_)_____________ ______(_)__ _____ / __ \_________ _ __ / / __ `/ __ \/ / ___/ ___/ __ `/ ___/ / _ \/ ___// / / / ___/ __ `// /_/ / /_/ / / / / (__ |__ ) /_/ / / / / __(__ )/ /_/ / / / /_/ / \____/\__,_/_/ /_/_/____/____/\__,_/_/ /_/\___/____(_)____/_/ \__, / /____/ ################################################################################## Top Sites Script, SQL Injection VulnerabilitiesSoftware Page: http://scriptsgenie.com/index.php?do=catalog&c=scripts&i=top_site_scriptProduct Page: http://www.hotscripts.com/listing/top-sites-2-2-1/Script Demo: http://scriptsgenie.com/demo/toplist.2.11/toplist/index.phpAuthor(Pentester): 3spi0nOn Social: Twitter.Com/eyyamgudeerGreetz: Grayhats Inc. and Janissaries Platform.##################################################################################[~] MySQL Injection on Demo Site (/out.php?id=)>>> http://scriptsgenie.com/demo/toplist.2.11/toplist/out.php?id=20' (MySQLi Found)Source: PacketStorm Quote