CVE-2009-3713
MorcegoCMS < 1.7.6 - SQL Injection via Fichero.php Query String
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3713. PoCs published by darkjoker.
AI-analyzed exploit summary This exploit targets a blind SQL injection vulnerability in Morcego CMS <= 1.7.6. It brute-forces the password hash for a given username by checking each character position against a predefined character set.
Description
SQL injection vulnerability in fichero.php in MorcegoCMS 1.7.6 and earlier allows remote attackers to execute arbitrary SQL commands via the query string.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by darkjoker · phpwebappsphp
https://www.exploit-db.com/exploits/9121
This exploit targets a blind SQL injection vulnerability in Morcego CMS <= 1.7.6. It brute-forces the password hash for a given username by checking each character position against a predefined character set.
Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target:
Morcego CMS <= 1.7.6
No auth needed
Prerequisites:
Network access to the target web application · Knowledge of a valid username
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/51658
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/55796
Exploit, Third Party Advisory exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/9121
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35778
Scores
EPSS
0.0101
EPSS Percentile
58.6%
Details
CWE
CWE-89
Status
published
Products (4)
morcego/morcegocms
0.9.6
morcego/morcegocms
1.1.0
morcego/morcegocms
1.5.0
morcego/morcegocms
< 1.7.6
Published
Oct 16, 2009
Tracked Since
Feb 18, 2026