Multiple SQL injection vulnerabilities in PHP-Fusion 6.00.206 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the forum_id parameter to options.php or (2) lastvisited parameter to viewforum.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php_fusion | Php_fusion | * | 6.00.206 (including) |