My Gaming Ladder v1.0 SQL Injection Vulnerability

# Exploit Title: My Gaming Ladder SQL Injection Vulnerability
# Date: January 4th, 2009
# Author: Sora
# Software Link:
# Version: 1.0
# Tested on: Windows and Linux
> Contact: vhr95zw [at] hotmail [dot] com
> Website:
> Google Dork: “In your dreams, script kiddies.”
> Cost of the program: $190.00 (wow!)

# Vulnerability Description:
My Gaming Ladder v1.0 suffers a remote SQL injection vulnerability in
the parameter “ladderid=” of ladder.php. The attacker can gain user cresedentials and deface
the vulnerable website. They will either infect the website, or they will deface it.

# Proof of Concept:′


