CVE-2009-4796
glFusion <= 1.1.2 - SQL Injection via Order and Direction Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4796. PoCs published by Nine:Situations:Group.
AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in glFusion <= 1.1.2 via the 'order' and 'direction' parameters. It extracts user hashes from the database and can be used to authenticate as admin by setting cookies.
Description
Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in glFusion 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) order and (2) direction parameters to search.php.
Exploits (1)
This exploit targets a SQL injection vulnerability in glFusion <= 1.1.2 via the 'order' and 'direction' parameters. It extracts user hashes from the database and can be used to authenticate as admin by setting cookies.