vendor:
PHP-Fusion
by:
Mauricio Correa
8,8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: PHP-Fusion
Affected Version From: 7.02.07
Affected Version To: 7.02.07
Patch Exists: YES
Related CWE: CVE-2014-8596
CPE: a:php-fusion:php-fusion:7.02.07
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux OS (Debian)
2014
PHP-Fusion 7.02.07 SQL Injection
The vulnerability exists due to insufficient filtration of user-supplied data passed via the 'aid' and 'submit_id' parameters to '/PHP-Fusion/files/administration/submissions.php' script and 'aid' parameter to '/PHP-Fusion/files/administration/members.php' script. A remote attacker can execute arbitrary SQL commands in application's database and gain access to sensitive data.
Mitigation:
The vendor has released an update to address this vulnerability. Users are advised to upgrade to the latest version.