CVE-2009-0711 Information

Description

filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable parameter in conjunction with a Password value for the dbfield parameter. NOTE: this has been reported as a SQL injection vulnerability by some sources but the provenance of that information is unknown.

Reference

http://secunia.com/advisories/33367 http://www.osvdb.org/51102 https://www.exploit-db.com/exploits/7636

Share on: