|
Family: CGI abuses --> Category: mixed
PHP-Fusion < 6.00.110 Multiple SQL Injection Vulnerabilities Vulnerability Scan
Vulnerability Scan Summary Checks for SQL injection in PHP-Fusion's register.php
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote host contains several PHP scripts that are vulnerable to
SQL injection flaws.
Description :
The remote version of this software is vulnerable to multiple SQL
injection attacks due to its failure to properly sanitize certain
parameters. Provided PHP's 'magic_quotes_gpc' setting is disabled,
these flaws allow a possible hacker to manipulate database queries, which
may result in the disclosure or modification of data.
See also :
http://securityfocus.org/archive/1/411909
http://archives.neohapsis.com/archives/secunia/2005-q4/0021.html
http://www.gnucitizen.org/writings/php-fusion-messages.php-sql-injection-vulnerability.xhtml
http://secunia.com/secunia_research/2005-52/advisory
Solution :
Update to at least version 6.00.110 of PHP-Fusion.
Threat Level:
Low / CVSS Base Score : 3
(AV:R/AC:H/Au:NR/C:P/A:N/I:N/B:C)
Click HERE for more information and discussions on this network vulnerability scan.
|