SQL injection vulnerability in PHPFox before 3.6.0 (build4) allows remote attackers to execute arbitrary SQL commands via the search[gender] parameter to user/browse/view_/.
References
Configurations
Information
Published : 2013-08-14 08:55
Updated : 2013-08-14 10:31
NVD link : CVE-2013-5120
Mitre link : CVE-2013-5120
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
phpfox
- phpfox