Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.20009
Kategorie:Web application abuses
Titel:PHP-Fusion < 6.00.110 Multiple SQL Injection Vulnerabilities
Zusammenfassung:The remote version of PHP-Fusion is vulnerable to multiple SQL; injection attacks due to its failure to properly sanitize certain parameters.
Beschreibung:Summary:
The remote version of PHP-Fusion is vulnerable to multiple SQL
injection attacks due to its failure to properly sanitize certain parameters.

Vulnerability Impact:
Provided PHP's 'magic_quotes_gpc' setting is disabled, these flaws
allow an attacker to manipulate database queries, which may result in the disclosure or modification of data.

Solution:
Update to at least version 6.00.110 of PHP-Fusion.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: BugTraq ID: 14964
BugTraq ID: 14992
BugTraq ID: 15005
BugTraq ID: 15018
Common Vulnerability Exposure (CVE) ID: CVE-2005-3157
Bugtraq: 20050928 PHP-Fusion v6.00.109 SQL Injection / admin|users credentials (Google Search)
http://marc.info/?l=bugtraq&m=112793982604963&w=2
http://rgod.altervista.org/phpfusion600109.html
http://secunia.com/advisories/16994
Common Vulnerability Exposure (CVE) ID: CVE-2005-3158
Bugtraq: 20050929 Re: PHP-Fusion v6.00.109 SQL Injection / admin|users credentials (Google Search)
http://marc.info/?l=bugtraq&m=112801702000944&w=2
http://www.gnucitizen.org/writings/php-fusion-messages.php-sql-injection-vulnerability.xhtml
Common Vulnerability Exposure (CVE) ID: CVE-2005-3160
http://www.osvdb.org/19841
http://secunia.com/advisories/17048
Common Vulnerability Exposure (CVE) ID: CVE-2005-3161
http://www.securityfocus.com/bid/15018
http://secunia.com/secunia_research/2005-52/advisory/
http://www.osvdb.org/19866
http://www.osvdb.org/19867
http://secunia.com/advisories/17055
http://securityreason.com/securityalert/54
XForce ISS Database: phpfusion-faq-register-sql-injection(22532)
https://exchange.xforce.ibmcloud.com/vulnerabilities/22532
CopyrightCopyright (C) 2005 Josh Zlatin-Amishav

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.