CVE-2009-1282

glFusion <= 1.1.2 - SQL Injection via glf_session Cookie Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-1282. PoCs published by Nine:Situations:Group.

AI-analyzed exploit summary This exploit targets a blind SQL injection vulnerability in glFusion <= 1.1.2 via the COM_applyFilter() function in session handling. It uses time-based techniques to extract admin hashes from the database.

Description

SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the glf_session cookie parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Nine:Situations:Group · phpwebappsphp
https://www.exploit-db.com/exploits/8347

This exploit targets a blind SQL injection vulnerability in glFusion <= 1.1.2 via the COM_applyFilter() function in session handling. It uses time-based techniques to extract admin hashes from the database.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: glFusion <= 1.1.2
Auth required
Prerequisites: Valid user credentials · MySQL >= 5.0.12 with SLEEP() function
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8347
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34575
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34361
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/53286
Exploit mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=123877379105028&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/49652
Patch, Vendor Advisory x_refsource_confirm
http://www.glfusion.org/wiki/doku.php?id=glfusion:whatsnew

Scores

EPSS 0.0272
EPSS Percentile 84.1%

Details

CWE
CWE-89
Status published
Products (5)
glfusion/glfusion 1.0.0 (3 CPE variants)
glfusion/glfusion 1.0.1
glfusion/glfusion 1.1.0 (2 CPE variants)
glfusion/glfusion 1.1.1
glfusion/glfusion < 1.1.2
Published Apr 09, 2009
Tracked Since Feb 18, 2026