CVE-2009-0709

PHPFootball 1.6 - SQL Injection via User Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-0709.

AI-analyzed exploit summary This exploit targets a hash disclosure vulnerability in PHPFootball <= 1.6 by sending a crafted HTTP GET request to the 'filter.php' endpoint, which leaks user password hashes from the 'Accounts' table. The script parses the response to extract the disclosed hashes.

Description

SQL injection vulnerability in login.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Exploits (1)

exploitdb WORKING POC
perlwebappsphp
https://www.exploit-db.com/exploits/7636

This exploit targets a hash disclosure vulnerability in PHPFootball <= 1.6 by sending a crafted HTTP GET request to the 'filter.php' endpoint, which leaks user password hashes from the 'Accounts' table. The script parses the response to extract the disclosed hashes.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: PHPFootball <= 1.6
No auth needed
Prerequisites: Target must have PHPFootball <= 1.6 installed · The 'filter.php' endpoint must be accessible
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33367
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/51104
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/47720

Scores

EPSS 0.0023
EPSS Percentile 46.6%

Details

CWE
CWE-89
Status published
Products (1)
vlad_alexa_mancini/phpfootball 1.6
Published Feb 23, 2009
Tracked Since Feb 18, 2026