Vulnerability Description
Multiple SQL injection vulnerabilities in PHP-Fusion before 6.00.110 allow remote attackers to execute arbitrary SQL commands via (1) the activate parameter in register.php and (2) the cat_id parameter in faq.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Php Fusion | Php Fusion | 6.00.100 |
References
- http://secunia.com/advisories/17055PatchVendor Advisory
- http://secunia.com/secunia_research/2005-52/advisory/Vendor Advisory
- http://securityreason.com/securityalert/54
- http://www.osvdb.org/19866
- http://www.osvdb.org/19867
- http://www.php-fusion.co.uk/news.php?readmore=261PatchVendor Advisory
- http://www.securityfocus.com/bid/15018Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22532
- http://secunia.com/advisories/17055PatchVendor Advisory
- http://secunia.com/secunia_research/2005-52/advisory/Vendor Advisory
- http://securityreason.com/securityalert/54
- http://www.osvdb.org/19866
- http://www.osvdb.org/19867
- http://www.php-fusion.co.uk/news.php?readmore=261PatchVendor Advisory
- http://www.securityfocus.com/bid/15018Patch
FAQ
What is CVE-2005-3161?
CVE-2005-3161 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple SQL injection vulnerabilities in PHP-Fusion before 6.00.110 allow remote attackers to execute arbitrary SQL commands via (1) the activate parameter in register.php and (2) the cat_id paramete...
How severe is CVE-2005-3161?
CVE-2005-3161 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-3161?
Check the references section above for vendor advisories and patch information. Affected products include: Php Fusion Php Fusion.