SQL injection vulnerability in PHPFox before 3.6.0 (build6) allows remote attackers to execute arbitrary SQL commands via the search[sort_by] parameter to user/browse/view_/.
References
Configurations
Information
Published : 2013-08-14 08:55
Updated : 2013-08-14 10:52
NVD link : CVE-2013-5121
Mitre link : CVE-2013-5121
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
phpfox
- phpfox