The exploit demonstrates a SQL injection vulnerability in UCStats 1.1 via the 'page' parameter in stats.php. The PoC URL manipulates the query to inject a single quote, potentially allowing unauthorized database access or manipulation.
Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:UCStats version 1.1
No auth needed
Prerequisites:Target running UCStats 1.1 with exposed stats.php