CVE-2009-1282 | glFusion 1.0.0/1.0.1/1.1.0/1.1.1/1.1.2 lib-session.php cookie sql injection (EDB-8347 / XFDB-49652)
A vulnerability classified as critical has been found in glFusion 1.0.0/1.0.1/1.1.0/1.1.1/1.1.2. This affects an unknown part in the library private/system/lib-session.php. The manipulation of the argument cookie leads to sql injection.
This vulnerability is uniquely identified as CVE-2009-1282. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.