CVE-2011-5218: Neubivljiv Dota Openstats

High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.

SQL injection vulnerability in DotA OpenStats 1.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

Affected products

  • Neubivljiv Dota Openstats: up to and including 1.3.9; version 1.1 only; version 1.1.9 only; version 1.2.1 only; version 1.2.2 only; version 1.2.3 only; …

Published 2012-10-25. Last modified 2026-06-16.