PT-2006-6697 · Clicktech · Clicktech Texas Rank'Em
Published
2006-11-22
·
Updated
2018-10-17
·
CVE-2006-6050
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ClickTech Texas Rank'em (affected versions not specified)
Description
The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the
selPlayer parameter to "player.asp" or the tournament id parameter to "tournaments.asp".Recommendations
For ClickTech Texas Rank'em, consider restricting access to the "player.asp" and "tournaments.asp" pages until a fix is available.
As a temporary workaround, avoid using the
selPlayer parameter in the "player.asp" page and the tournament id parameter in the "tournaments.asp" page to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Clicktech Texas Rank'Em