CVE-2009-0711

PHPFootball <1.6 - Info Disclosure

Title source: llm

Description

filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable parameter, in conjunction with a Password value for the dbfield parameter. NOTE: this has been reported as a SQL injection vulnerability by some sources, but the provenance of that information is unknown.

Exploits (1)

exploitdb WORKING POC VERIFIED
by KinG-LioN · perlwebappsphp
https://www.exploit-db.com/exploits/7636

Scores

EPSS 0.0064
EPSS Percentile 70.6%

Details

CWE
CWE-200
Status published
Products (2)
vlad_alexa_mancini/phpfootball 1.5
vlad_alexa_mancini/phpfootball 1.6
Published Feb 23, 2009
Tracked Since Feb 18, 2026