CVE-2009-4561

WebLeague 2.2.0 - SQL Injection

Title source: llm

Description

Multiple SQL injection vulnerabilities in Admin/index.php in WebLeague 2.2.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ka0x · perlwebappsphp
https://www.exploit-db.com/exploits/9165

Scores

EPSS 0.0025
EPSS Percentile 48.6%

Details

CWE
CWE-89
Status published
Products (1)
worms-league/webleague 2.2.0
Published Jan 04, 2010
Tracked Since Feb 18, 2026