Multiple SQL injection vulnerabilities in PHP-Fusion before 6.00.110 allow remote attackers to execute arbitrary SQL commands via (1) the activate parameter in register.php and (2) the cat_id parameter in faq.php.
Link | Tags |
---|---|
http://www.osvdb.org/19867 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/22532 | vdb entry |
http://www.osvdb.org/19866 | vdb entry |
http://www.securityfocus.com/bid/15018 | vdb entry patch |
http://secunia.com/secunia_research/2005-52/advisory/ | vendor advisory |
http://www.php-fusion.co.uk/news.php?readmore=261 | patch vendor advisory |
http://securityreason.com/securityalert/54 | third party advisory |
http://secunia.com/advisories/17055 | third party advisory patch vendor advisory |