Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2009-4796
Description:Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in glFusion 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) order and (2) direction parameters to search.php.
Test IDs: 1.3.6.1.4.1.25623.1.0.901111  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2009-4796
BugTraq ID: 34281
http://www.securityfocus.com/bid/34281
Bugtraq: 20090329 glFusion <= 1.1.2 COM_applyFilter()/order sql injection exploit (Google Search)
http://www.securityfocus.com/archive/1/502260/100/0/threaded
http://www.exploit-db.com/exploits/8302
http://osvdb.org/52984
http://secunia.com/advisories/34519
XForce ISS Database: glfusion-class-sql-injection(49498)
https://exchange.xforce.ibmcloud.com/vulnerabilities/49498




© 1998-2025 E-Soft Inc. All rights reserved.