CVE-2009-1362

chcounter 3.1.3 - SQL Injection via login_name Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2009-1362. PoCs published by Valentin, tmh.

AI-analyzed exploit summary This writeup describes an indirect SQL injection and XSS vulnerability in chCounter 3.1.1, where an attacker manipulates page titles or user agents to inject malicious SQL or XSS payloads, which execute when an admin views visitor details in the backend.

Description

SQL injection vulnerability in administration/index.php in chCounter 3.1.3 allows remote attackers to execute arbitrary SQL commands via the login_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Exploits (2)

exploitdb WRITEUP VERIFIED
by Valentin · textwebappsphp
https://www.exploit-db.com/exploits/12456

This writeup describes an indirect SQL injection and XSS vulnerability in chCounter 3.1.1, where an attacker manipulates page titles or user agents to inject malicious SQL or XSS payloads, which execute when an admin views visitor details in the backend.

Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Moderate
Reliability
Theoretical
Target: chCounter 3.1.1
No auth needed
Prerequisites: Access to a website using chCounter · Admin interaction to view visitor details
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by tmh · textwebappsphp
https://www.exploit-db.com/exploits/8461

This exploit describes an authentication bypass vulnerability in chCounter 3.1.3, where using ' or = as the username and password allows unauthorized access. The exploit requires magic quotes to be disabled on the target system.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: chCounter 3.1.3
No auth needed
Prerequisites: magic quotes = off
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24879
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/50353

Scores

EPSS 0.0082
EPSS Percentile 52.4%

Details

CWE
CWE-89
Status published
Products (1)
chcounter/chcounter 3.1.3
Published Apr 22, 2009
Tracked Since Feb 18, 2026