33367Third-party advisory
http://secunia.com/advisories/33367 CVE-2009-0711
PHPFootball 1.6 - Remote Hash Disclosure
Record summary
CVE-2009-0711 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable parameter, in conjunction with a Password value for the dbfield parameter. NOTE: this has been reported as a SQL injection vulnerability by some sources, but the provenance of that information is unknown.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPHPFootball 1.6 - Remote Hash DisclosureExploitDB exploitby KinG-LioNNot analyzed1 file
References
451102vdb entry
http://www.osvdb.org/51102 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-0711 7636exploit
https://www.exploit-db.com/exploits/7636