Global variable overwrite vulnerability in maincore.php in PHP-Fusion 6.01.4 and earlier uses the extract function on the superglobals, which allows remote attackers to conduct SQL injection attacks via the _SERVER[REMOTE_ADDR] parameter to news.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php_fusion | Php_fusion | * | 6.01.4 (including) |
Php_fusion | Php_fusion | 6.0.105 (including) | 6.0.105 (including) |
Php_fusion | Php_fusion | 6.0.106 (including) | 6.0.106 (including) |
Php_fusion | Php_fusion | 6.0.107 (including) | 6.0.107 (including) |
Php_fusion | Php_fusion | 6.0.109 (including) | 6.0.109 (including) |
Php_fusion | Php_fusion | 6.0.110 (including) | 6.0.110 (including) |
Php_fusion | Php_fusion | 6.0.204 (including) | 6.0.204 (including) |
Php_fusion | Php_fusion | 6.0.206 (including) | 6.0.206 (including) |
Php_fusion | Php_fusion | 6.0.303 (including) | 6.0.303 (including) |
Php_fusion | Php_fusion | 6.0.304 (including) | 6.0.304 (including) |
Php_fusion | Php_fusion | 6.0.306 (including) | 6.0.306 (including) |
Php_fusion | Php_fusion | 6.0.307 (including) | 6.0.307 (including) |