CVE Database
/

CVE-2006-4673

Back to search

CVE-2006-4673

Published: Sep 11, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Global variable overwrite vulnerability in maincore.php in PHP-Fusion 6.01.4 and earlier uses the extract function on the superglobals, which allows remote attackers to conduct SQL injection attacks via the _SERVER[REMOTE_ADDR] parameter to news.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

19908
vdb-entry
x_refsource_BID
ADV-2006-3523
vdb-entry
x_refsource_VUPEN
21830
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now