Global variable overwrite vulnerability in maincore.php in PHP-Fusion 6.01.4 and earlier uses the extract function on the superglobals, which allows remote attackers to conduct SQL injection attacks via the _SERVER[REMOTE_ADDR] parameter to news.php.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2006-09-11 16:04
Updated : 2017-07-20 01:33
NVD link : CVE-2006-4673
Mitre link : CVE-2006-4673
CVE.ORG link : CVE-2006-4673
JSON object : View
Products Affected
php_fusion
- php_fusion
CWE