SQL injection vulnerability in players-detail.php in UltraStats 0.2.136, 0.2.140, and 0.2.142 allows remote attackers to execute arbitrary SQL commands via the id parameter.Referenceshttps://www.exploit-db.com/exploits/6067http://www.securityfocus.com/bid/30212http://securityreason.com/securityalert/4021https://exchange.xforce.ibmcloud.com/vulnerabilities/43760http://www.shooter-szene.de/PNphpBB2-viewtopic-t-12730.phtml