6
CVSSv2

CVE-2009-0831

Published: 05/03/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the sortby parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

php-fusion members_cv_module 1.0

Exploits

##################################################################################### #### PHP-Fusion Mod Members Bewerb Sql Injection #### ##################################################################################### # # #AUTHO ...