CVE-2009-4796 | glFusion 1.0.0/1.0.1/1.1.0/1.1.1/1.1.2 listfactory.class.php ExecuteQueries sql injection (EDB-8302 / XFDB-49498)
A vulnerability was found in glFusion 1.0.0/1.0.1/1.1.0/1.1.1/1.1.2. It has been classified as critical. Affected is the function ExecuteQueries of the file private/system/classes/listfactory.class.php. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2009-4796. It is possible to launch the attack remotely. Furthermore, there is an exploit available.