Multiple SQL injection vulnerabilities in PHP-Fusion before 6.00.110 allow remote attackers to execute arbitrary SQL commands via (1) the activate parameter in register.php and (2) the cat_id parameter in faq.php.
References
Link | Resource |
---|---|
http://www.php-fusion.co.uk/news.php?readmore=261 | Patch Vendor Advisory |
http://secunia.com/secunia_research/2005-52/advisory/ | Vendor Advisory |
http://www.securityfocus.com/bid/15018 | Patch |
http://www.osvdb.org/19866 | |
http://www.osvdb.org/19867 | |
http://secunia.com/advisories/17055 | Patch Vendor Advisory |
http://securityreason.com/securityalert/54 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/22532 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-10-06 03:02
Updated : 2017-07-10 18:33
NVD link : CVE-2005-3161
Mitre link : CVE-2005-3161
JSON object : View
CWE
Products Affected
php_fusion
- php_fusion