Secunia Logo
 
CVE Reference: CVE-2005-4005
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-4005

Description:
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to obtain path information and possibly execute arbitrary SQL commands via the srch_text parameter in a Search and Sort option to messages.php.

CVE Status:
Candidate

References:

SREASON
  http://securityreason.com/securityalert/31

SAID
  Secunia Advisory: SA17871

OSVDB
  21415

BUGTRAQ
  http://www.securityfocus.com/archive/1/418512

BID
  15698


Return to the previous page.