SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view parameter, a different vulnerability than CVE-2005-3157 and CVE-2005-3158.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/14489 | vdb entry exploit |
http://www.osvdb.org/18708 | vdb entry |
http://marc.info/?l=bugtraq&m=112811077320676&w=2 | mailing list |
http://www.s4a.cc/forum/archive/index.php/t-3585.html | url repurposed vendor advisory |