filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable parameter, in conjunction with a Password value for the dbfield parameter. NOTE: this has been reported as a SQL injection vulnerability by some sources, but the provenance of that information is unknown.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.osvdb.org/51102 | vdb entry |
http://secunia.com/advisories/33367 | third party advisory vendor advisory |
https://www.exploit-db.com/exploits/7636 | exploit |