CVE-2010-5009
Published Nov 2, 2011SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter in a matchp action.
Vendor/product archive
2 CVEs tagged to ut-files / utstats — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter in a matchp action.
Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers to inject arbitrary web script or HTML via the mid paramet…