PHP-Fusion Multiple SQL and HTML Injection Vulnerabilities
BID:11296
Info
PHP-Fusion Multiple SQL and HTML Injection Vulnerabilities
| Bugtraq ID: | 11296 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2004 12:00AM |
| Updated: | Sep 30 2004 12:00AM |
| Credit: | r0ut3r is credited for the discovery of these vulnerabilities. |
| Vulnerable: |
PHP-Fusion PHP-Fusion 4.0 1 |
| Not Vulnerable: | |
Discussion
PHP-Fusion Multiple SQL and HTML Injection Vulnerabilities
It is reported that PHP-Fusion is susceptible to HTML and SQL injection vulnerabilities. These vulnerabilities are due to a failure of the application to properly sanitize user-supplied input data.
An attacker may leverage the SQL injection issues to manipulate SQL queries to the underlying database. This may allow the attacker access to sensitive information, such as the administrator password, to corrupt data, and to carry out other attacks.
The HTML injection vulnerabilities may allow an attacker to inject malicious HTML and script code into the vulnerable application. An unsuspecting user viewing the resulting pages will have the attacker-supplied script code executed within their browser in the context of the vulnerable web site.
These vulnerabilities are reported to exist in version 4.01 of PHP-Fusion. Other versions may also be affected.
It is reported that PHP-Fusion is susceptible to HTML and SQL injection vulnerabilities. These vulnerabilities are due to a failure of the application to properly sanitize user-supplied input data.
An attacker may leverage the SQL injection issues to manipulate SQL queries to the underlying database. This may allow the attacker access to sensitive information, such as the administrator password, to corrupt data, and to carry out other attacks.
The HTML injection vulnerabilities may allow an attacker to inject malicious HTML and script code into the vulnerable application. An unsuspecting user viewing the resulting pages will have the attacker-supplied script code executed within their browser in the context of the vulnerable web site.
These vulnerabilities are reported to exist in version 4.01 of PHP-Fusion. Other versions may also be affected.
Exploit / POC
PHP-Fusion Multiple SQL and HTML Injection Vulnerabilities
An exploit is not required for these vulnerabilities.
An exploit is not required for these vulnerabilities.
Solution / Fix
PHP-Fusion Multiple SQL and HTML Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP-Fusion Multiple SQL and HTML Injection Vulnerabilities
References:
References:
- PHP-Fusion Homepage (PHP-Fusion)
- PHP-Fusion SQL Injection and Script Insertion Vulnerabilities (Secunia)