PHP-Fusion 'messages.php' SQL Injection Vulnerability
BID:32388
Info
PHP-Fusion 'messages.php' SQL Injection Vulnerability
| Bugtraq ID: | 32388 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5335 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 20 2008 12:00AM |
| Updated: | May 07 2015 05:21PM |
| Credit: | irk4z[at]yahoo.pl |
| Vulnerable: |
PHP-Fusion PHP_Fusion 7.0.1 |
| Not Vulnerable: |
PHP-Fusion PHP_Fusion 7.0.2 |
Discussion
PHP-Fusion 'messages.php' SQL Injection Vulnerability
PHP-Fusion is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
PHP-Fusion 7.00.1 is vulnerable; other versions may also be affected.
PHP-Fusion is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
PHP-Fusion 7.00.1 is vulnerable; other versions may also be affected.
Exploit / POC
PHP-Fusion 'messages.php' SQL Injection Vulnerability
An attacker can exploit this issue via a browser.
The following exploit is available:
An attacker can exploit this issue via a browser.
The following exploit is available:
Solution / Fix
PHP-Fusion 'messages.php' SQL Injection Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for details.
Solution:
Vendor updates are available. Please contact the vendor for details.