CVE-2009-4791

Family Connections <1.8.2 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-4791. PoCs published by Salvatore Fresta.

AI-analyzed exploit summary This exploit demonstrates a blind SQL injection vulnerability in Family Connection CMS <= 1.8.2, allowing remote command execution by writing a malicious PHP file to the server via SQL injection in the authentication cookie.

Description

Multiple SQL injection vulnerabilities in Family Connections (aka FCMS) before 1.8.2 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter to addressbook.php, (2) id parameter to recipes.php, (3) year parameter to register.php, (4) poll_id parameter to home.php, and (5) email parameter to lostpw.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Salvatore Fresta · textwebappsphp
https://www.exploit-db.com/exploits/8319

This exploit demonstrates a blind SQL injection vulnerability in Family Connection CMS <= 1.8.2, allowing remote command execution by writing a malicious PHP file to the server via SQL injection in the authentication cookie.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Family Connection CMS <= 1.8.2
No auth needed
Prerequisites: Network access to the target server · SQL injection vulnerability in the authentication system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Various Sources x_refsource_confirm
http://www.familycms.com/blog/2009/03/fcms-182-released/
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/8319
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/502272/100/0/threaded
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34297
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34503

Scores

EPSS 0.0128
EPSS Percentile 66.3%

Details

CWE
CWE-89
Status published
Products (32)
ryan_haudenschilt/family_connections 0.1.1
ryan_haudenschilt/family_connections 0.1.2
ryan_haudenschilt/family_connections 0.5
ryan_haudenschilt/family_connections 0.6
ryan_haudenschilt/family_connections 0.8
ryan_haudenschilt/family_connections 0.9
ryan_haudenschilt/family_connections 0.9.1
ryan_haudenschilt/family_connections 0.9.2
ryan_haudenschilt/family_connections 0.9.5
ryan_haudenschilt/family_connections 0.9.8
... and 22 more
Published Apr 22, 2010
Tracked Since Feb 18, 2026