Global variable overwrite vulnerability in maincore.php in PHP-Fusion 6.01.4 and earlier uses the extract function on the superglobals, which allows remote attackers to conduct SQL injection attacks via the _SERVER[REMOTE_ADDR] parameter to news.php.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2006-09-11 09:04
Updated : 2017-07-19 18:33
NVD link : CVE-2006-4673
Mitre link : CVE-2006-4673
JSON object : View
CWE
Products Affected
php_fusion
- php_fusion