Vulnerabilities > Ultrastats

DATE CVE VULNERABILITY TITLE RISK
2009-02-24 CVE-2008-6260 SQL Injection vulnerability in Ultrastats 0.2.144/0.3.11
SQL injection vulnerability in index.php in Ultrastats 0.2.144 and 0.3.11 allows remote attackers to execute arbitrary SQL commands via the serverid parameter.
network
low complexity
ultrastats CWE-89
7.5
2008-07-21 CVE-2008-3241 SQL Injection vulnerability in Ultrastats 0.2.136/0.2.140/0.2.142
SQL injection vulnerability in players-detail.php in UltraStats 0.2.136, 0.2.140, and 0.2.142 allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
ultrastats CWE-89
7.5