exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

THQ.com SQL Injection

THQ.com SQL Injection
Posted Jun 18, 2010

THQ.com suffers from multiple remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
SHA-256 | 03e07c7d92d4a120fc47d2523b9d6a53ef71eb5d3ce0bd79b08a44e66f907826

THQ.com SQL Injection

Change Mirror Download
This is pretty much because I want to embarrass these assholes. See: http://gamepolitics.com/2010/06/14/exec-thq-anti-used-game-initiative-could-make-everyone-happy

SQLi 1: http://www.thq.com/us/mythq/register?contentType=GAMEALERT&alertGame='4896

This one is pretty obvious. It's an injection via $_GET. The funniest part is that they don't just allow injection. They serve up the whole PHP source of the page for you. Giving you table names, and the actual syntax of the query being used.

SQLi 2:
The next one is an injection via POST in their registration form here: http://www.thq.com/us/mythq/register

I used burpsuite to inject it by editing the HTTP requests but you can probably just enter whatever you want right in the form. I used the UK subdomain for testing: http://uk.thq.com/uk/mythq/register. This one also shows the source.

Next one is your typical reflected XSS:

http://www.thq.com/us/search/index?keyw=%3Cscript%3Ealert%28document.cookie%29%3B%3C%2Fscript%3E

I hope this is enough to put off anyone who was thinking of buying shit from them.
Would you trust this company with your credit card information when they can't even properly sanitize a registration form?
These probably aren't even the only security bugs on their site. This is just after 10 minutes of pentesting. Do yourself a favor and stay far far away from this company. They have no clue about security and obviously don't give a shit about their customers.

BOYCOTT THQ




Login or Register to add favorites

File Archive:

October 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    0 Files
  • 2
    Oct 2nd
    22 Files
  • 3
    Oct 3rd
    0 Files
  • 4
    Oct 4th
    0 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    0 Files
  • 8
    Oct 8th
    0 Files
  • 9
    Oct 9th
    0 Files
  • 10
    Oct 10th
    0 Files
  • 11
    Oct 11th
    0 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    0 Files
  • 15
    Oct 15th
    0 Files
  • 16
    Oct 16th
    0 Files
  • 17
    Oct 17th
    0 Files
  • 18
    Oct 18th
    0 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close