vendor:
PHP-Fusion
by:
Manuel García Cárdenas
N/A
CVSS
N/A
Blind SQL Injection in admin panel PHP-Fusion
89
CWE
Product Name: PHP-Fusion
Affected Version From: PHP-Fusion <= v7.02.07
Affected Version To: PHP-Fusion <= v7.02.07
Patch Exists: YES
Related CWE: N/A
CPE: a:php-fusion:php-fusion
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
MGC ALERT 2015-002
This bug was found using the portal with authentication as administrator. To exploit the vulnerability only is needed use the version 1.0 of the HTTP protocol to interact with the application. It is possible to inject SQL code in the variable 'status' on the page 'members.php'.
Mitigation:
All data received by the application and can be modified by the user, before making any kind of transaction with them must be validated.