May 24, 2012 - 11:45 AM Home Forum Downloads News Neueste Forum Posts Create an Account   
 
:: Online ::

You are an anonymous user. You can register for free by clicking here
User name
Password
 Remember me

:: Hauptmenu ::
|--> Forum

:: Suche ::
Suche @Shooter-szene.de
Website Search
Forum Search
 
Download Search
 

:: ShooterCenter ::
---> Crysis
---> Doom 3
---> FarCry
| `--> News
---> Prey
---> SoF2
---> UT3
---> Wa§ow

:: Infos ::
Impressum
sZene Team
Link Us
Disclaimer
AGB's
Need Klicks ?

:: Partner Seiten ::
Cod-community.de sniper50cent skd-mp Encores-Portal v3 ist online - vorbeischauen lohnt! united-fairplay xtreme-reflex-gamer lostis-world diealtengermanen TFP-Clan battelfield-szene callofduty CoD-Series cod-info HDTVTotal.com STP-Solutions

:: ServerStatus ::
CoD2 TDM
mp_toujane
Call of Duty 2
194.97.167.155:28960
Map: mp_toujane
Players: 0/32
Detailed info...
MGS-Server


:: Sprache ::
Preferred language:

Deutsch English

 

Thema: Fix for players-detail.php SQL Vulnerability
Post new topic   Reply to topic
View previous topic Printable version Log in to check your private messages View next topic
Author Message
deltarayOffline
Post subject: Fix for players-detail.php SQL Vulnerability  PostPosted: Jul 15, 2008 - 04:20 PM
Sitemast0r
Sitemast0r


Joined: Oct 22, 2005
Posts: 12339
Location: Terra - SOL System
Status: Offline
A few moments ago this was brought to my attention. A mistake in the validation code of the input Parameters in the file players-detail.php made an SQL Injection bug possible.

Details about this security flaw can be found here:
http://www.securityfocus.com/bid/30212/info
(DO NOT USE THE FIXED RECOMMEND IN THE EXPLOIT THERE, IT WILL BREAK FUNCTIONALITY HALF OF THE PLAYER DETAILS)

Affected Versions are:
UltraStats 0.2.136
UltraStats 0.2.140
UltraStats 0.2.142

In order to fix this issue manually please process these steps, or replace your players-detail.php with the attached one here. Please spread this information to all admins you know, who use UltraStats.

1. Open players-detail.php and search for:
Code:
         is_numeric($content['playerguid']) &&
         ( $content['playerguid'] > 4294967296 && $content['playerguid'] <= 0 )


2. Replace with this code:
Code:
         !is_numeric($content['playerguid'])
            ||
         ( $content['playerguid'] > 4294967296 && $content['playerguid'] <= 0 )


ATTENTION: I will update the UltraStats setup to a newer version in the next few days, as a few other things will be fixed along with this release.



players-detail-FIXED.rar
 Description:
Fixed Exploit from:
http://www.securityfocus.com/bid/30212/exploit

Download
 Filename:  players-detail-FIXED.rar
 Filesize:  4.72 KB
 Downloaded:  291 Time(s)


_________________
- For Support write into the forums pls ... btw u r a fag Wayne?

He Poops on you!
 
 View user's profile Send private message Send e-mail Visit poster's website ICQ Number 
Reply with quote Back to top
HarryRagOffline
Post subject: Fix for players-detail.php SQL Vulnerability  PostPosted: Jul 15, 2008 - 06:07 PM
Private
Private


Joined: Dec 01, 2007
Posts: 13

Status: Offline
thnx for the fast fix DeltaRay
 
 View user's profile Send private message Visit poster's website MSN Messenger  
Reply with quote Back to top
AnzeigenOffline
Post subject: Google Ads  PostPosted:
Guest


Joined: Dec 01, 2007
Posts
Location
Status: Offline
 
   
Reply with quote Back to top
eagleeyeOffline
Post subject: Fix for players-detail.php SQL Vulnerability  PostPosted: Jul 16, 2008 - 06:12 PM
Lance Corporal
Lance Corporal


Joined: Jun 18, 2006
Posts: 57

Status: Offline
tnx for the support, will pass the word

in 0.2.142 it's line 41 of the file.
 
 View user's profile Send private message  
Reply with quote Back to top
HunterOffline
6 Post subject: Fix for players-detail.php SQL Vulnerability  PostPosted: Jul 17, 2008 - 01:02 AM
Corporal
Corporal


Joined: Mar 10, 2006
Posts: 163

Status: Offline
Ok nice, no not nice but ........

_________________
 
 View user's profile Send private message Visit poster's website  
Reply with quote Back to top
Display posts from previous:     
Jump to:  
All times are GMT
Post new topic   Reply to topic
View previous topic Printable version Log in to check your private messages View next topic
Powered by PNphpBB2 © 2003-2007 The PNphpBB Group
Credits
(C) 2005-2011 by Shooter-Szene.de  •  All Rights Reserved  •  Disclaimer  •  Über uns  •  Powered by PostNuke
Partner: STP-Solutions  •  UltraStats  •  HDTV Total  •  ClanWarz  •  Funbilder  •  Viral Videos  •  Spiele-Szene.de  •  Spiele Videos  •  X-Sites.de
Page created in 0.35571980476379 seconds.