Record summary

CVE-2009-0711 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable parameter, in conjunction with a Password value for the dbfield parameter. NOTE: this has been reported as a SQL injection vulnerability by some sources, but the provenance of that information is unknown.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBPHPFootball 1.6 - Remote Hash DisclosureExploitDB exploitby KinG-LioNNot analyzed1 file

linked to 3 vulnerabilities

ExploitDB

PoC details

References

4