CVE-2009-1347

Chcounter - SQL Injection

Title source: rule

Description

Multiple SQL injection vulnerabilities in stats/index.php in chCounter 3.1.3 allow remote attackers to execute arbitrary SQL commands via (1) the login_name parameter (aka the username field) or (2) the login_pw parameter (aka the password field).

Exploits (2)

exploitdb WRITEUP VERIFIED
by tmh · textwebappsphp
https://www.exploit-db.com/exploits/8461
exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/12456

Scores

EPSS 0.0049
EPSS Percentile 65.4%

Details

CWE
CWE-89
Status published
Products (1)
chcounter/chcounter 3.1.3
Published Apr 20, 2009
Tracked Since Feb 18, 2026