CVE-2009-4796

glFusion <= 1.1.2 - SQL Injection via Order and Direction Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-4796. PoCs published by Nine:Situations:Group.

AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in glFusion <= 1.1.2 via the 'order' and 'direction' parameters. It extracts user hashes from the database and can be used to authenticate as admin by setting cookies.

Description

Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in glFusion 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) order and (2) direction parameters to search.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Nine:Situations:Group · phpwebappsphp
https://www.exploit-db.com/exploits/8302

This exploit targets a SQL injection vulnerability in glFusion <= 1.1.2 via the 'order' and 'direction' parameters. It extracts user hashes from the database and can be used to authenticate as admin by setting cookies.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: glFusion <= 1.1.2
No auth needed
Prerequisites: Target must have at least 2 records in the same topic section · MySQL >= 4.1
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/502260/100/0/threaded
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/8302
Various Sources x_refsource_confirm
http://www.glfusion.org/article.php/security_20090329
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34519
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/52984
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/49498
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34281

Scores

EPSS 0.0234
EPSS Percentile 81.4%

Details

CWE
CWE-89
Status published
Products (5)
glfusion/glfusion 1.0.0 (3 CPE variants)
glfusion/glfusion 1.0.1
glfusion/glfusion 1.1.0 (2 CPE variants)
glfusion/glfusion 1.1.1
glfusion/glfusion < 1.1.2
Published Apr 22, 2010
Tracked Since Feb 18, 2026