Chcounter · Chcounter · CVE-2009-1347
**Name of the Vulnerable Software and Affected Versions**
chCounter version 3.1.3
**Description**
The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the `login name` parameter (also known as the username field) or the `login pw` parameter (also known as the password field) in the stats/index.php file.
**Recommendations**
For chCounter version 3.1.3, avoid using the `login name` and `login pw` parameters in the stats/index.php file until the issue is resolved. As a temporary workaround, consider restricting access to the stats/index.php file to minimize the risk of exploitation.